<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interface &amp;amp; Security Zone in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4897011#M1103144</link>
    <description>&lt;P&gt;I setup my diagnostic interface as management and gave it an IP address that falls under the management subnet. Flexconfig took the commands, so I believe I'm all set. How can I confirm flows are being sent, though, as I'm not seeing anything at the collector yet? I tried setting up a packet capture on the FTD CLI to the management interface using any command, but nothing is being sent.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 14:34:44 GMT</pubDate>
    <dc:creator>dcanady55</dc:creator>
    <dc:date>2023-08-01T14:34:44Z</dc:date>
    <item>
      <title>Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893698#M1103010</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;FTD &amp;amp; FMC 7.3&lt;/P&gt;&lt;P&gt;I am setting up Netflow and decided to use a physical interface for this process. The help section says an interface can belong to only one security zone. However, can multiple interfaces belong to the same zone Inside in my case? I'm getting an error to many interfaces in security zone / interface group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893698#M1103010</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-07-27T12:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893953#M1103027</link>
      <description>&lt;P&gt;&lt;A href="https://support.auvik.com/hc/en-us/articles/360025288852-How-to-configure-NetFlow-on-Cisco-devices-with-Firepower-Management-Center" target="_blank"&gt;https://support.auvik.com/hc/en-us/articles/360025288852-How-to-configure-NetFlow-on-Cisco-devices-with-Firepower-Management-Center&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893953#M1103027</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-27T17:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893969#M1103029</link>
      <description>&lt;P&gt;As noted in the linked article, we generally setup Netflow records to be exported from the management interface.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893969#M1103029</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-07-27T17:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893972#M1103031</link>
      <description>&lt;P&gt;Yes as share link, I think his issue is he is using INside not Mgmt.&amp;nbsp;&lt;BR /&gt;hope this link help him&amp;nbsp;&lt;BR /&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893972#M1103031</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-27T17:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893977#M1103034</link>
      <description>&lt;P&gt;To confirm&amp;nbsp; you are referring to the management IP address that I have configured under the device tab of said FTD, I tried that address and wasn't successful for some reason. Under interfaces themselves, there's a box for enabled and management, but management is grayed out, so I wanted to make sure you're not talking about enabling that under a physical interface. I will review the article, as maybe I missed something.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4893977#M1103034</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-07-27T17:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4897011#M1103144</link>
      <description>&lt;P&gt;I setup my diagnostic interface as management and gave it an IP address that falls under the management subnet. Flexconfig took the commands, so I believe I'm all set. How can I confirm flows are being sent, though, as I'm not seeing anything at the collector yet? I tried setting up a packet capture on the FTD CLI to the management interface using any command, but nothing is being sent.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4897011#M1103144</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-08-01T14:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4901824#M1103316</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;, or&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run the command "show flow-export counters," this number does increase, yet when I use wireshark on the collector, nothing from this FTD appears. I have setup ASP drop captures, and nothing was found there as well. Is there a way to validate that flows are being sent outside of this counter? Like I previously mentioned, when I setup a packet capture on the MGT interface, there were no packets. I can ping the collector from FTD CLI, so I'm not sure what else I can look at.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 17:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4901824#M1103316</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-08-08T17:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903175#M1103351</link>
      <description>&lt;P&gt;When you ping the collector from the FTD cli did you use "ping system"?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 17:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903175#M1103351</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-08-10T17:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903208#M1103358</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion, as I did not know about this command. I ran the ping this way, and it was successful. However, on the collector, I was running wireshark and noticed that the source was the MGT IP found under the device tab of that FTD. Per that document, MHM posted I took my diagnostic interface and labeled it management and gave it an IP address inside the same subnet found under my device tab's management's space. If I go into the diagnostic CLI on the FTD and try to source my pings from the management interface that I setup under the diagnostic interface to the collector, it fails. I assume that I must create a rule for this traffic but wasn't sure as there's no mention of it in that document nor Cisco's official documentation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 18:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903208#M1103358</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-08-10T18:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Interface &amp; Security Zone</title>
      <link>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903215#M1103359</link>
      <description>&lt;P&gt;I ran a packet capture looking for ASP drops and ran a ping inside the diagnostic CLI sourcing from my new management IP to my collector and the asp output is the following. I don't know what that is yet but assuming something with routing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1: 18:15:29.120187 10.80.5.10 &amp;gt; 10.93.200.36 icmp: echo request Drop-reason: (no-adjacency) No valid adjacency, Drop-location: frame 0x000000aaacd9bccc flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 18:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interface-amp-security-zone/m-p/4903215#M1103359</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2023-08-10T18:19:19Z</dc:date>
    </item>
  </channel>
</rss>

