<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD1120 diagnostic port IP configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590228#M1089098</link>
    <description>&lt;P&gt;I am currently managing an FTD from FMC using an IP address that is linked to the FTD's management port.&amp;nbsp; This is confirmed because if I physically remove the network cable from the port I lose connectivity to the FTD.&amp;nbsp; However, on the FMC device management screen the port does not show as having an IP and is configured for DHCP?&amp;nbsp; Should I add the management IP in there or leave things alone?&amp;nbsp; Is this an expected behavior/configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2022 14:24:54 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2022-04-11T14:24:54Z</dc:date>
    <item>
      <title>FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590228#M1089098</link>
      <description>&lt;P&gt;I am currently managing an FTD from FMC using an IP address that is linked to the FTD's management port.&amp;nbsp; This is confirmed because if I physically remove the network cable from the port I lose connectivity to the FTD.&amp;nbsp; However, on the FMC device management screen the port does not show as having an IP and is configured for DHCP?&amp;nbsp; Should I add the management IP in there or leave things alone?&amp;nbsp; Is this an expected behavior/configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 14:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590228#M1089098</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2022-04-11T14:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590237#M1089101</link>
      <description>&lt;P&gt;we are not sure, is this FMC Virtual or Physical ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as Long as FTD able to reach FMC that means working...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the question is , if the Manangment port not configured, how are these commnunicating ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 14:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590237#M1089101</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-04-11T14:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590252#M1089105</link>
      <description>&lt;P&gt;Hello BB,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FTD is physical and yes, all is working.&amp;nbsp; I am running traffic thru it, I have NAT and ACP rules, I can see connection events, push policies, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But according to the FMC device management you would think it should not be because the diag int does not have an IP and is not enabled for management.&amp;nbsp; See attached pics&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 15:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590252#M1089105</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2022-04-11T15:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590258#M1089108</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317180"&gt;@tato386&lt;/a&gt; Leave things alone unless you need to use the diagnostics interface, it's optional.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;ARTICLE id="concept_8628A651D0AF4F59B7021A67FADCD513" class="topic concept nested2" lang="en-US" aria-labelledby="ariaid-title4"&gt;
&lt;SECTION class="body conbody"&gt;
&lt;SECTION id="concept_8628A651D0AF4F59B7021A67FADCD513__section_8107E8D3C73F4A50B3CDD3A2F6A049DC" class="section"&gt;
&lt;P class="p"&gt;The &lt;STRONG&gt;Diagnostic&lt;/STRONG&gt; logical interface can be configured along with the rest of the data interfaces on the &lt;STRONG&gt;&lt;U&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Devices&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;Device Management&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;Interfaces&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/U&gt; screen.&lt;/STRONG&gt; Using &lt;U&gt;&lt;STRONG&gt;the Diagnostic interface is optional&lt;/STRONG&gt;&lt;/U&gt; (see the routed and transparent mode deployments for scenarios). The Diagnostic interface only allows management traffic, and does not allow through traffic. &lt;SPAN class="ph"&gt;It does not support SSH; you can SSH to data interfaces or to the Management interface only. &lt;/SPAN&gt;The &lt;STRONG&gt;Diagnostic interface is useful for SNMP or syslog monitoring.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;The Management interface is separate from the other interfaces on the device. If &lt;STRONG&gt;you change the IP address at the CLI after you add it to the &lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;,&lt;/STRONG&gt; you can match the IP address in the &lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt; in the&lt;STRONG&gt; &lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Devices&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;Device Management&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;Devices&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="ph uicontrol"&gt;Management&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/STRONG&gt;area.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/interface_overview_for_firepower_threat_defense.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/interface_overview_for_firepower_threat_defense.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/SECTION&gt;
&lt;/SECTION&gt;
&lt;/ARTICLE&gt;</description>
      <pubDate>Mon, 11 Apr 2022 15:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590258#M1089108</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-11T15:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590280#M1089113</link>
      <description>&lt;P&gt;that is diag interface, there is nothing to worry - leave it as it is..you are good now.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 15:46:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4590280#M1089113</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-04-11T15:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD1120 diagnostic port IP configuration</title>
      <link>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4591165#M1089172</link>
      <description>&lt;P&gt;I guess the name "diagnostic" threw me off.&amp;nbsp; Now I realize this is same as ASA/SFR whereby the ASA's management interface is shared with SFR but configured separately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 18:55:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd1120-diagnostic-port-ip-configuration/m-p/4591165#M1089172</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2022-04-12T18:55:28Z</dc:date>
    </item>
  </channel>
</rss>

