<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco FTD in one arm mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4986857#M1107369</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I've thought of this too. In the context of doing PBR to divert traffic towards the FW for analysis, it would make sense to have just one interface to/from the distribution switch without worrying about routing entries. I'm not sure if this has a performance penalty or known limitations for features other than FW/IPS.&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;GG&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2023 14:09:57 GMT</pubDate>
    <dc:creator>ggalteroo</dc:creator>
    <dc:date>2023-12-29T14:09:57Z</dc:date>
    <item>
      <title>cisco FTD in one arm mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184167#M1075787</link>
      <description>&lt;P&gt;Hello Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to deploy&amp;nbsp; cisco FTD in one arm mode.&lt;/P&gt;&lt;P&gt;Can you please help with that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ing OZ&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 18:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184167#M1075787</guid>
      <dc:creator>O.Zang</dc:creator>
      <dc:date>2020-11-15T18:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: cisco FTD in one arm mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184169#M1075788</link>
      <description>&lt;P&gt;FTD in one-arm mode, you want only 1 interface (subinterface)&amp;nbsp; zone?&amp;nbsp; - what is the reason, due to port availability?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the high level, you can do sub interface in the different zone - switch configured as a trunk with different VLAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 18:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184169#M1075788</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-15T18:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: cisco FTD in one arm mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184264#M1075799</link>
      <description>&lt;P&gt;Technically speaking you can, however, it would not be recommended, and it would add complexity to your design. I have seen it once (or maybe twice) with an ASA device where it was behind an edge firewall, and it was only used to terminate AnyConnect VPN connections. Post VPN connections, all the traffic from the ASA was routed back to the edge firewall that was doing all the routing and security policies. Is that something similar to what you would like to do?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 06:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4184264#M1075799</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-11-16T06:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: cisco FTD in one arm mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4986857#M1107369</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I've thought of this too. In the context of doing PBR to divert traffic towards the FW for analysis, it would make sense to have just one interface to/from the distribution switch without worrying about routing entries. I'm not sure if this has a performance penalty or known limitations for features other than FW/IPS.&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;GG&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 14:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-in-one-arm-mode/m-p/4986857#M1107369</guid>
      <dc:creator>ggalteroo</dc:creator>
      <dc:date>2023-12-29T14:09:57Z</dc:date>
    </item>
  </channel>
</rss>

