<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default FlexConfig Policy? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636516#M1091161</link>
    <description>&lt;P&gt;So, it would be sufficient to compare "show run all" before and after new FlexConfig policy, assuming there are no other changes in the same deployment?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 12:00:48 GMT</pubDate>
    <dc:creator>sasha</dc:creator>
    <dc:date>2022-06-22T12:00:48Z</dc:date>
    <item>
      <title>Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4635854#M1091124</link>
      <description>&lt;P&gt;Hello. I'm creating my FIRST FlexConfig policy. But when I try to assign it to a device, I'm getting the following message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Following devices already have assignments listed below. These devices will be reassigned to the current policy&lt;BR /&gt;device: impftd - policy: (device setting)&lt;/P&gt;
&lt;P&gt;Do you want to continue with above changes?"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will I loose some settings if I answer "yes"?&amp;nbsp;Is there any way to see the mentioned "(device setting)" policy, and/or FlexConfigs already set on the device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're using FMC 7.0.1 and a HA pair of 2110s with FTD 7.0.1. We recently upgraded from 6.4, but we didn't use FlexConfig before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 13:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4635854#M1091124</guid>
      <dc:creator>sasha</dc:creator>
      <dc:date>2022-06-21T13:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636017#M1091139</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You navigate to the listed flexconfig policy, you can see what flex objects&lt;BR /&gt;are assigned and what is configured.&lt;BR /&gt;&lt;BR /&gt;Keep in mind that if you remove a flex policy from an FTD, it won't revoke&lt;BR /&gt;the changes. This is how flex works. You will need another flex policy to&lt;BR /&gt;remove the changes. So don't be concerned about revoking existing config&lt;BR /&gt;but its good to know what that policy does before any changes.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636017#M1091139</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-21T16:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636353#M1091152</link>
      <description>&lt;P&gt;Hello Mohammed, there ISN'T ANY policies in the list! The policy I'm creating is the FIRST one. But the FMC warns me that the device is assigned to "&lt;SPAN&gt;policy: (device setting)". My question is how to see THAT policy. And is&amp;nbsp;&lt;/SPAN&gt;there any other way to see FlexConfig commands which are in effect. As you said, it's good to know that before any changes. Thanks and best regards.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 07:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636353#M1091152</guid>
      <dc:creator>sasha</dc:creator>
      <dc:date>2022-06-22T07:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636395#M1091157</link>
      <description>&lt;P&gt;I do not believe that this is possible.&amp;nbsp; If the policy is not present in the FMC GUI then the only place you can check is the running configuration on the FTD it self, but there you would need to know what you are looking for.&amp;nbsp; Flexconfig is only a tool that you can use to send ASA CLI configuration to the FTD device, so you would only see the configurations them selves on the FTD and not the actual policy.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636395#M1091157</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-22T08:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636516#M1091161</link>
      <description>&lt;P&gt;So, it would be sufficient to compare "show run all" before and after new FlexConfig policy, assuming there are no other changes in the same deployment?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 12:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636516#M1091161</guid>
      <dc:creator>sasha</dc:creator>
      <dc:date>2022-06-22T12:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636608#M1091164</link>
      <description>&lt;P&gt;Yes that would be the only way to know what was included in the previous policy&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 13:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4636608#M1091164</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-22T13:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Default FlexConfig Policy?</title>
      <link>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4637599#M1091216</link>
      <description>&lt;P&gt;So folks, thank you both for help. The first policy went fine. Here's the outcome:&lt;/P&gt;
&lt;P&gt;- Before I assigned the first flexconfig policy to our FTD HA pair, Preview Config button was grayed out.&lt;/P&gt;
&lt;P&gt;- But after I assigned the policy and before I saved the changes, the button became active!?! As the only available device, it didn't offer our FTD HA pair but just our primary FTD device!?! And it displayed the old (before-save) flexconfig.&lt;/P&gt;
&lt;P&gt;- After I saved the changes, the button offered our FTD HA as the only available device, and displayed the new flexconfig. All of the old commands were still there, and a couple of new commands produced by the new policy were added.&lt;/P&gt;
&lt;P&gt;- I compared show run all before and after, and the only difference were the commands added by the new policy.&lt;/P&gt;
&lt;P&gt;Thanks again and best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-flexconfig-policy/m-p/4637599#M1091216</guid>
      <dc:creator>sasha</dc:creator>
      <dc:date>2022-06-23T14:25:57Z</dc:date>
    </item>
  </channel>
</rss>

