<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FP1010 topology in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735956#M1095799</link>
    <description>&lt;P&gt;Rob, the dns issue was seen with a critical health status for FTD not being able to connect like this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;FTD01:/home/ldap/abbac# &lt;STRONG&gt;curl -v -k &lt;A href="https://api-sse.cisco.com/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://api-sse.cisco.com&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;* Rebuilt URL to: &lt;A href="https://api-sse.cisco.com/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://api-sse.cisco.com/&lt;/A&gt;&lt;BR /&gt;* getaddrinfo(3) failed for api-sse.cisco.com:443&lt;BR /&gt;* Couldn't resolve host 'api-sse.cisco.com'&lt;BR /&gt;* Closing connection 0&lt;BR /&gt;curl: (6) &lt;STRONG&gt;Couldn't resolve host 'api-sse.cisco.com'&lt;/STRONG&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 09 Dec 2022 21:43:17 GMT</pubDate>
    <dc:creator>lcaruso</dc:creator>
    <dc:date>2022-12-09T21:43:17Z</dc:date>
    <item>
      <title>FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735917#M1095794</link>
      <description>&lt;P&gt;After mgmt connectivity issues, TAC provided that my FMCv had to be directly connected to the FP1010 as in the diagram below.&amp;nbsp;Since no examples given, guessing the configuration for each port.&amp;nbsp;From what I can tell, the FMC needs its own network separate from the Transit network which is connected to an internal router.&lt;/P&gt;&lt;P&gt;Here are my guesses. Advice and clarifications are appreciated.&lt;/P&gt;&lt;P&gt;Eth 1/1&lt;BR /&gt;Name Outside&lt;BR /&gt;Address DHCP&lt;BR /&gt;Routed&lt;BR /&gt;Zone Outside&lt;/P&gt;&lt;P&gt;Eth 1/2&lt;BR /&gt;Name Transit&lt;BR /&gt;Address Static 10.11.11.1&lt;BR /&gt;Routed&lt;BR /&gt;Zone Transit&lt;/P&gt;&lt;P&gt;Eth 1/4&lt;BR /&gt;Name FMCv&lt;BR /&gt;Address Static 10.22.22.1&lt;BR /&gt;Routed&lt;BR /&gt;No Zone&lt;/P&gt;&lt;P&gt;Eth 1/5&lt;BR /&gt;Name Mgmt&lt;BR /&gt;Address Static 192.168.45.2&lt;BR /&gt;Mgmt Only&lt;BR /&gt;Routed&lt;BR /&gt;No Zone&lt;/P&gt;&lt;P&gt;Managment 1/1&lt;BR /&gt;Name Mgmt&lt;BR /&gt;Address Static 192.168.45.1&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735917#M1095794</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T21:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735926#M1095795</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324624"&gt;@lcaruso&lt;/a&gt;&amp;nbsp;the FMC needs to be routable from the FTD, it doesn't need to be on the same network. It's easier to use the mgmt interface, change the IP address and gateway to match a vlan on your network. Establish ping connectivity and register the device to the FMC.&lt;/P&gt;
&lt;P&gt;Here is a guide to troubleshoot registration to the FMC.&lt;/P&gt;
&lt;P&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://integratingit.wordpress.com/2018/10/20/ftd-registration-w" target="_blank"&gt;https://integratingit.wordpress.com/2018/10/20/ftd-registration-with-fmc/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735926#M1095795</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-09T21:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735933#M1095796</link>
      <description>&lt;P&gt;Same document look for next diagram&amp;nbsp; -&amp;nbsp;&lt;SPAN class="fig--title-label"&gt;Figure 4.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Cabling the Firepower 1010&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This means FMCv can be anywhere not required to be in the same VLAN, as long IP has reachability (no FW between - can be FW but some ports are required to Open to connect).&lt;/P&gt;
&lt;P&gt;when you setup FTD, make sure you select managed FMC .&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=v_uZ9GbICBk" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=v_uZ9GbICBk&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=hbX4J2tZiyU" target="_blank"&gt;https://www.youtube.com/watch?v=hbX4J2tZiyU&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735933#M1095796</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-12-09T21:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735943#M1095797</link>
      <description>&lt;P&gt;Thanks, Rob for your input. I believe what you are describing is the same or close to what I had originally, but FTD could not resolve DNS even though DNS was configured. TAC spent three hours looking at this and concluded the FMCv had to be directly connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="first attempt.png" style="width: 509px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170382i3EFD659C82ADBB71/image-dimensions/509x425?v=v2" width="509" height="425" role="button" title="first attempt.png" alt="first attempt.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735943#M1095797</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T21:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735954#M1095798</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324624"&gt;@lcaruso&lt;/a&gt;&amp;nbsp;you don't need to use dns, you can just use IP.&lt;/P&gt;
&lt;P&gt;Can you ping the gateway from the FTD? Can you ping the FMC from the FTD?&lt;/P&gt;
&lt;P&gt;Did you take a tcpdump as per the link I provided?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735954#M1095798</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-09T21:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735956#M1095799</link>
      <description>&lt;P&gt;Rob, the dns issue was seen with a critical health status for FTD not being able to connect like this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;FTD01:/home/ldap/abbac# &lt;STRONG&gt;curl -v -k &lt;A href="https://api-sse.cisco.com/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://api-sse.cisco.com&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;* Rebuilt URL to: &lt;A href="https://api-sse.cisco.com/" target="_blank" rel="noopener nofollow noreferrer"&gt;https://api-sse.cisco.com/&lt;/A&gt;&lt;BR /&gt;* getaddrinfo(3) failed for api-sse.cisco.com:443&lt;BR /&gt;* Couldn't resolve host 'api-sse.cisco.com'&lt;BR /&gt;* Closing connection 0&lt;BR /&gt;curl: (6) &lt;STRONG&gt;Couldn't resolve host 'api-sse.cisco.com'&lt;/STRONG&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735956#M1095799</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T21:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735959#M1095800</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;thanks for your reply. I should have mentioned I had everything setup and working except FTD could not resolve DNS names and connect to the cloud. So FMCv was registered, inside traffic was passing fine, but FTD was critical status because of not being able to connect to the cloud. I did see that video you shared previously that is a good one, thanks.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lcaruso_1-1670622320943.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170391i762827BF52CB33F9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lcaruso_1-1670622320943.jpeg" alt="lcaruso_1-1670622320943.jpeg" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878" target="_self"&gt;&lt;SPAN class=""&gt;balaji.bandi&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735959#M1095800</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T21:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735960#M1095801</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324624"&gt;@lcaruso&lt;/a&gt;&amp;nbsp;I assumed your issue was registering the ftd to the fmc. That screenshot would indicate you mean the ftd is unable to resolve a dns entry in order to access the Internet?&lt;/P&gt;
&lt;P&gt;How does this relate to the fmc? Please provide more information on your issue.&lt;/P&gt;
&lt;P&gt;Is it just this fqdn that is not resolvable?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 21:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735960#M1095801</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-09T21:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735987#M1095808</link>
      <description>&lt;P&gt;is that still issue has this been resolved?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 22:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735987#M1095808</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-12-09T22:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735995#M1095809</link>
      <description>&lt;P&gt;Not resolved yet because I am now redesigning the network to match the diagram that Cisco says I have to implement. I swapped in my backup firewall and need to connect FMCv directly and cable Management1/1 to Eth1/5 as in the diagram.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cabling the FP1010.png" style="width: 546px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170398i16A7704000349CF9/image-dimensions/546x342?v=v2" width="546" height="342" role="button" title="cabling the FP1010.png" alt="cabling the FP1010.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 22:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4735995#M1095809</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T22:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4736001#M1095810</link>
      <description>&lt;P&gt;Rob, the connectivity issue was FTD could not ping ip addresses eg 8.8.8.8 so that is why a critical error raised regarding the reachability of the cloud. I was told by TAC there is a separate FTD "policy" that manages FTD's network that I had not configured. Somehow TAC jumped from configuring that as a possible solution to these required topology changes with Management1/1 connected directly to Eth1/5 and FMCv connected directly to Eth1/4 per the FP1010 cabling diagram.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 22:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4736001#M1095810</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-09T22:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: FP1010 topology</title>
      <link>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4736169#M1095819</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324624"&gt;@lcaruso&lt;/a&gt; isn't this 2 issues?&lt;/P&gt;
&lt;P&gt;Please provide the actual screenshot of the critical error regarding reachability of the cloud, I assume it's displayed on the FMC? The FMC does normally communicate with api-sse.cisco.com - therefore the FMC would need internet access, so NAT and an Access Control rule to permit the traffic.&lt;/P&gt;
&lt;P&gt;If you cannot even ping an IP address on the internet from the FTD itself, does this not indicate an actual fundamental network/routing issue? Can you ping the next hop IP address? Can devices behind the FTD access the internet?&lt;/P&gt;
&lt;P&gt;On the FTD what interface are you pinging from? The Outside interface (ping 8.8.8.8) or mgmt interface (ping &lt;STRONG&gt;system&lt;/STRONG&gt; 8.8.8.8). If your mgmt interface is connected to the internal LAN (with the switch as the next hop) then it is routed through the FTD, so you'd need NAT and an Access Control rule.&lt;/P&gt;
&lt;P&gt;To configure the FTD to ping hostnames you need to configure DNS in the Platform Settings policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 20:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp1010-topology/m-p/4736169#M1095819</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-10T20:12:08Z</dc:date>
    </item>
  </channel>
</rss>

