<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD Subinterfaces change to Physical in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674366#M1092898</link>
    <description>&lt;P&gt;If you are managing this via FMC you can remove the configuration from the subinterface and then configure the physical interface with that configuration from the subinterface.&amp;nbsp; The good thing with FTD is that the interfaces are associated with zones and then those zones are used in the access rules.&amp;nbsp; this means that ACP rules and NAT rules will be updated automatically with the new interface.&amp;nbsp; Routing and VPN would need to be updated manually as these reference the physical interface.&lt;/P&gt;
&lt;P&gt;Also, none of these changes will take effect until you deploy the configuration.&amp;nbsp; That means that you can configure everything, veryify that all is changed, and then deploy.&lt;/P&gt;
&lt;P&gt;I did this just last week, though I chose to create a new interface name as it was so quick and easy to change the configuration.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2022 06:52:27 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2022-08-24T06:52:27Z</dc:date>
    <item>
      <title>Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674154#M1092881</link>
      <description>&lt;P&gt;I am running into issues with a sub-interface so I need to change it to a physical. I'm nervous about making the change. Is there an easy way to change a sub-interface into a physical without renaming? I currently can't ping anything from the sub-interface but don't have any issues with physical interfaces. I'm assuming that running dhcp-relay on a sub-interface is a no no on the FTD's which is why I can't get it up and running. Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 16:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674154#M1092881</guid>
      <dc:creator>agilliup</dc:creator>
      <dc:date>2022-08-23T16:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674160#M1092883</link>
      <description>&lt;P&gt;I do not see any sub interface issue, when you do port-channel. that give you high availability. if one of the Physical interface go down, or switch port go down, or switch in stack or SVL part go down.&lt;/P&gt;
&lt;P&gt;i still prefer to do port-channel. rather single sub interface, that is best advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 16:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674160#M1092883</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-23T16:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674163#M1092884</link>
      <description>&lt;P&gt;I really just want to make it a physical interface. We have high availability with two FTD's already.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 17:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674163#M1092884</guid>
      <dc:creator>agilliup</dc:creator>
      <dc:date>2022-08-23T17:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674170#M1092885</link>
      <description>&lt;P&gt;how many sub-interface do you have enough physical interfaces ?&lt;/P&gt;
&lt;P&gt;if so you need to make changes on the Physical interface configuration, same config need to apply on switch to match the VLAN, you need to move 1 sub-interface at a time and test it...shutdown sub-interface and bring up physical interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note : i have not done myself this practice, so test 1 interface before you move to next interfaces for good safe approach, make sure you have config backup out of the box.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 17:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674170#M1092885</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-23T17:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674174#M1092886</link>
      <description>&lt;P&gt;You have to remove and recretae if you want to keep the same interface name (nameif).&lt;/P&gt;
&lt;P&gt;You can potentially use interface groups as an alternative to avoid renaming but then any NAT and ACP rules would likewise have to reference those as applicable.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 17:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674174#M1092886</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-08-23T17:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674323#M1092897</link>
      <description>&lt;P&gt;if you are planing to move with same name, you need to remove sub interface first and apply those settings in to physical interface. you cannot have same name simultaneously. so plana down time and move interface to physical. also when you moving interfaces, you may need to re add routings related to that interface. so keep them in track. also make sure you have enough physical interfaces to move your sub interfaces. after moving sub interfaces, you need to configure connected switch with correct VLAN which previously configured in sub interface.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 02:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674323#M1092897</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-08-24T02:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Subinterfaces change to Physical</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674366#M1092898</link>
      <description>&lt;P&gt;If you are managing this via FMC you can remove the configuration from the subinterface and then configure the physical interface with that configuration from the subinterface.&amp;nbsp; The good thing with FTD is that the interfaces are associated with zones and then those zones are used in the access rules.&amp;nbsp; this means that ACP rules and NAT rules will be updated automatically with the new interface.&amp;nbsp; Routing and VPN would need to be updated manually as these reference the physical interface.&lt;/P&gt;
&lt;P&gt;Also, none of these changes will take effect until you deploy the configuration.&amp;nbsp; That means that you can configure everything, veryify that all is changed, and then deploy.&lt;/P&gt;
&lt;P&gt;I did this just last week, though I chose to create a new interface name as it was so quick and easy to change the configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2022 06:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-subinterfaces-change-to-physical/m-p/4674366#M1092898</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-08-24T06:52:27Z</dc:date>
    </item>
  </channel>
</rss>

