<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't change Management Interface FPR 2130 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756239#M1096893</link>
    <description>&lt;P&gt;I am running 7.0.4 FMC and FTD - i can see we can setup Management only as below : (right now i am using outside interface - this is example screenshot) - or am i missing something here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_0-1673990710339.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/173613i6E3449157B9065C5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_0-1673990710339.png" alt="balajibandi_0-1673990710339.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_1-1673990750311.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/173614i179D59BD8C622C27/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_1-1673990750311.png" alt="balajibandi_1-1673990750311.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 21:25:59 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-01-17T21:25:59Z</dc:date>
    <item>
      <title>Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756225#M1096891</link>
      <description>&lt;P&gt;We have a couple FPR-2130s and FPR-2110s. We would like to change our default/dedicated management port to be one of our inside/data ports for simplicity's sake (&lt;SPAN&gt;Management1/1 -&amp;gt; Gig1/2)&lt;/SPAN&gt;. According to Cisco, you can do this via the CLI or FMC gui, but through both methods, the option is missing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/device_management_basics.html#Cisco_Task.dita_d359bb35-78d5-4bb7-8d29-91612da7eb01" target="_self"&gt;Here's the documentation I'm following.&lt;/A&gt;&amp;nbsp;Note: This is the FMC 6.7 guide but the same directions for changing MGMT to Data interface is present in the 7.3 guide, albeit the GUI directions are missing (or I can't find them).&lt;/P&gt;&lt;P&gt;Via CLI: Login and use command "&lt;SPAN&gt;&lt;STRONG&gt;configure network management-data-interface"&lt;/STRONG&gt;. This command is completely missing from our CLI&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Via GUI: Navigate to&amp;nbsp;&lt;STRONG&gt;Device&amp;nbsp;&lt;/STRONG&gt;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Management&amp;nbsp;&lt;/STRONG&gt;&amp;gt; click the link for&amp;nbsp;&lt;STRONG&gt;FMC Access Interface&lt;/STRONG&gt;. This "FMC Access Interface" link is missing from our GUI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are running the most recent versions, I believe it is 7.3 on FMC and 7.0.4 for our FPRs (I will have to verify this, we downloaded whatever Cisco gave us via FMC update manager). We have disabled local management when connecting to our FPRs to FMC.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If anyone can give me insight, if I'm missing some sort of software version or license, it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 20:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756225#M1096891</guid>
      <dc:creator>korkomando</dc:creator>
      <dc:date>2023-01-17T20:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756234#M1096892</link>
      <description>&lt;P&gt;Could it be that you run your FTDs in HA? In this scenario it’s not possible to use the data interface.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 21:19:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756234#M1096892</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-01-17T21:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756239#M1096893</link>
      <description>&lt;P&gt;I am running 7.0.4 FMC and FTD - i can see we can setup Management only as below : (right now i am using outside interface - this is example screenshot) - or am i missing something here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_0-1673990710339.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/173613i6E3449157B9065C5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_0-1673990710339.png" alt="balajibandi_0-1673990710339.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="balajibandi_1-1673990750311.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/173614i179D59BD8C622C27/image-size/medium?v=v2&amp;amp;px=400" role="button" title="balajibandi_1-1673990750311.png" alt="balajibandi_1-1673990750311.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 21:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756239#M1096893</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-17T21:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756250#M1096895</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;No, we have plans on using HA in the future but at the moment it is not configured on any devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;On our end, the "Management Only" checkbox is greyed out on our 2110s and 2130s. Additionally, we don't see the "FMC Access" tab.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 22:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756250#M1096895</guid>
      <dc:creator>korkomando</dc:creator>
      <dc:date>2023-01-17T22:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756270#M1096896</link>
      <description>&lt;P&gt;My Setup is Virtual since you are using Physical tin, check&amp;nbsp; Firepower chassis (FXOS)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/intro.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/intro.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 22:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4756270#M1096896</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-17T22:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4757962#M1096985</link>
      <description>&lt;P&gt;To clarify, we have FMC running on a virtual machine and our Firewalls are physical. If I understand this documentation correctly, I can choose to run the Firewalls with an ASA operating system or run them with our current Threat Defense operating system. Considering that we spent a lot of money on FMC and Threat Defense licenses, I would like to find a solution where I can continue to use Threat Defense. Please correct me if I'm wrong.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 16:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4757962#M1096985</guid>
      <dc:creator>korkomando</dc:creator>
      <dc:date>2023-01-19T16:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4757993#M1096988</link>
      <description>&lt;P&gt;You can make this change as long as your Firepower release is 6.7 or higher. Can you verify your version of FMC and FTD, preferably with screen shot to confirm.&lt;/P&gt;
&lt;P&gt;You need to make changes in the Interface, Manager access tab and well as in the Device (Management widget), both in FMC.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 17:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4757993#M1096988</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-01-19T17:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4776203#M1097821</link>
      <description>&lt;P&gt;Sorry for the late response; this was our solution. I was under the incorrect assumption that FMC will update FPRs to the most recent version release. However, from what I read on your replies on other threads, it doesn't update past a major version release (we were stuck on 6.5) and that it would need to be manually staged.&lt;/P&gt;&lt;P&gt;To add to my confusion, I couldn't track down any cisco documentation stating that you needed 6.7 or above to make this change, I could only find documentation stating how to perform the configuration change on the 6.7 version documentation.&lt;/P&gt;&lt;P&gt;Thanks for the expedient responses. The issue is fixed and I learned a valuable lesson in making assumptions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 19:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4776203#M1097821</guid>
      <dc:creator>korkomando</dc:creator>
      <dc:date>2023-02-15T19:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can't change Management Interface FPR 2130</title>
      <link>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4799489#M1098901</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;&lt;P&gt;Not sure if this should be a new post but I'll write it here:&lt;BR /&gt;&lt;BR /&gt;I'm facing a new issue where only one of the 2130s is using the it's newly assigned data-interface for management traffic. After switching everything over I kept the management port connection plugged in as it was a hassle to physically reach them. Later on when I was configuring a site-to-site VPN I was encountering a problem where traffic couldn't get across despite packet tracer and the 2130's CLI output both stating that the tunnel was up/active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This led me to finally unplugging the management port connection during troubleshooting and I noticed that 3 out of the 4 (two separate tunnels, not HA) become unreachable when the management port is unplugged despite seeing link lights active.&lt;/P&gt;&lt;P&gt;After combing through the troubleshooting files I noticed a difference between the one working and the 3 that don't:&lt;/P&gt;&lt;P&gt;Working 2130 output:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Output of /usr/local/sf/bin/sfcli.pl show network:

===============[ System Information ]===============
Hostname                  : SiteA-FTD1
DNS Servers               : 192.168.1.100
                            192.169.1.100
DNS from router           : disabled
Management port           : 8305
IPv4 Default route
  Gateway                 : 192.168.200.1
  Netmask                 : 0.0.0.0


==================[ management0 ]===================
State                     : Enabled
Link                      : Up
Channels                  : Management &amp;amp; Events
Mode                      : Non-Autonegotiation 
MDI/MDIX                  : Auto/MDIX 
MTU                       : 1500
MAC Address               :  x:A5:00
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.168.200.3
Netmask                   : 255.255.255.0
Gateway                   : 192.168.200.1
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

===============[ Proxy Information ]================
State                     : Disabled
Authentication            : Disabled

======[ System Information - Data Interfaces ]======
DNS Servers               : 
Interfaces                : Ethernet1/2

==================[ Ethernet1/2 ]===================
State                     : Enabled
Link                      : Up
Name                      : Internal1
MTU                       : 1500
MAC Address               : x:A5:25
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.168.200.5
Netmask                   : 255.255.255.0
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

&lt;/LI-CODE&gt;&lt;P&gt;Non working 2130s:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Output of /usr/local/sf/bin/sfcli.pl show network:

===============[ System Information ]===============
Hostname                  : SiteA-FTD2
DNS Servers               : 192.168.1.100
                            192.169.1.100
DNS from router           : disabled
Management port           : 8305
IPv4 Default route
  Gateway                 : 192.168.200.1
  Netmask                 : 0.0.0.0


==================[ management0 ]===================
State                     : Enabled
Link                      : Up
Channels                  : Management &amp;amp; Events
Mode                      : Non-Autonegotiation 
MDI/MDIX                  : Auto/MDIX 
MTU                       : 1500
MAC Address               : x:17:80
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.168.200.4
Netmask                   : 255.255.255.0
Gateway                   : 192.168.200.1
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

===============[ Proxy Information ]================
State                     : Disabled
Authentication            : Disabled

======[ System Information - Data Interfaces ]======
DNS Servers               : 
Interfaces                : Ethernet1/2

==================[ Ethernet1/2 ]===================
State                     : Enabled
Link                      : Up
Name                      : Internal1
MTU                       : 1500
MAC Address               : x:17:A5
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.168.200.4
Netmask                   : 255.255.255.0
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Output of /usr/local/sf/bin/sfcli.pl show network:

===============[ System Information ]===============
Hostname                  : SiteB-FTD1
DNS Servers               : 192.168.1.100
                            192.169.1.100
DNS from router           : disabled
Management port           : 8305
IPv4 Default route
  Gateway                 : 192.169.200.1
  Netmask                 : 0.0.0.0


==================[ management0 ]===================
State                     : Enabled
Link                      : Up
Channels                  : Management &amp;amp; Events
Mode                      : Non-Autonegotiation 
MDI/MDIX                  : Auto/MDIX 
MTU                       : 1500
MAC Address               : x:41:80
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.169.200.5
Netmask                   : 255.255.255.0
Gateway                   : 192.169.200.1
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

===============[ Proxy Information ]================
State                     : Disabled
Authentication            : Disabled

======[ System Information - Data Interfaces ]======
DNS Servers               : 
Interfaces                : Ethernet1/2

==================[ Ethernet1/2 ]===================
State                     : Enabled
Link                      : Up
Name                      : Internal1
MTU                       : 1500
MAC Address               : x:41:A5
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.169.200.5
Netmask                   : 255.255.255.0
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Output of /usr/local/sf/bin/sfcli.pl show network:

===============[ System Information ]===============
Hostname                  : SiteB-FTD2
DNS Servers               : 192.168.1.100
                            192.169.1.100
DNS from router           : disabled
Management port           : 8305
IPv4 Default route
  Gateway                 : 192.169.1.1
  Netmask                 : 0.0.0.0


==================[ management0 ]===================
State                     : Enabled
Link                      : Up
Channels                  : Management &amp;amp; Events
Mode                      : Non-Autonegotiation 
MDI/MDIX                  : Auto/MDIX 
MTU                       : 1500
MAC Address               : x:FD:80
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.169.200.4
Netmask                   : 255.255.255.0
Gateway                   : 192.169.200.1
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

===============[ Proxy Information ]================
State                     : Disabled
Authentication            : Disabled

======[ System Information - Data Interfaces ]======
DNS Servers               : 
Interfaces                : Ethernet1/2

==================[ Ethernet1/2 ]===================
State                     : Enabled
Link                      : Up
Name                      : Internal1
MTU                       : 1500
MAC Address               : x:FD:A5
----------------------[ IPv4 ]----------------------
Configuration             : Manual
Address                   : 192.169.200.4
Netmask                   : 255.255.255.0
----------------------[ IPv6 ]----------------------
Configuration             : Disabled

&lt;/LI-CODE&gt;&lt;P&gt;The working one initially had the .3 address before we switched it over to a data-interface for management (after which we gave it the .5). The other 3 we kept the same address after switching from management to data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tomorrow I am going to attempt changing the address again to see if it will help it switch it over. My question is, 1) is that the correct thing to do and 2) Should I go out of my way to disable the management port? How would one do that? I assume disabling diagnostic0 from FMC isn't the same as disabling the management port.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 16:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-change-management-interface-fpr-2130/m-p/4799489#M1098901</guid>
      <dc:creator>korkomando</dc:creator>
      <dc:date>2023-03-22T16:28:56Z</dc:date>
    </item>
  </channel>
</rss>

