<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD to remote FMC register problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998832#M1108073</link>
    <description>&lt;P&gt;I have configured as you have write but fails, i have added FTD without IP address but with register and nat id&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2024 20:02:58 GMT</pubDate>
    <dc:creator>sherali mamatkarimov</dc:creator>
    <dc:date>2024-01-17T20:02:58Z</dc:date>
    <item>
      <title>FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998773#M1108057</link>
      <description>&lt;P&gt;i am trying to register my FTD to my remote FMC by this guide with manual method&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp2100/firepower-2100-gsg/ftd-fmc-remote.html#task_imq_yw3_b3b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp2100/firepower-2100-gsg/ftd-fmc-remote.html#task_imq_yw3_b3b&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but when i am adding my FTD to FMC i got error&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Registration timed out. Please check connectivity and registration id&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have configured outside static ip address in FTD as managment interface and also registration id and nat id. FMC is behind the nat and I can ping FTD outside ip.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;On FTD i configured manager with command "configure manager add DONTRESOLVE secret123 natid123" as i dont have directly access to FMC. I tried to registrer FTD with IP and NAT ID both, without IP only with NAT ID and also without NAT ID only with static IP but everytime fails. Can you help me?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998773#M1108057</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998776#M1108058</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt; check the logs from the f&lt;SPAN&gt;rom the CLI of the FTD enter expert mode and e&lt;/SPAN&gt;&lt;SPAN&gt;nter the command &lt;STRONG&gt;&lt;EM&gt;sudo tail -f /ngfw/var/logs/messages&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;tcp/8305 is allowed inbound/outbound to/from the FMC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998776#M1108058</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-17T19:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998784#M1108059</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;Jan 17 19:06:01 fpr-02 sudo: pam_ldap: ldap_simple_bind Can't contact LDAP server&lt;BR /&gt;Jan 17 19:06:01 fpr-02 sudo: pam_ldap: reconnecting to LDAP server...&lt;BR /&gt;Jan 17 19:06:01 fpr-02 sudo: pam_ldap: ldap_simple_bind Can't contact LDAP server&lt;BR /&gt;Jan 17 19:06:04 fpr-02 sudo: pam_radius_auth: Could not open configuration file /etc/raddb/server: No such file or directory&lt;BR /&gt;Jan 17 19:06:04 fpr-02 sudo: pam_ldap: ldap_simple_bind Can't contact LDAP server&lt;BR /&gt;Jan 17 19:06:04 fpr-02 sudo: pam_ldap: reconnecting to LDAP server...&lt;BR /&gt;Jan 17 19:06:04 fpr-02 sudo: pam_ldap: ldap_simple_bind Can't contact LDAP server&lt;BR /&gt;Jan 17 19:06:05 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x snort&lt;BR /&gt;Jan 17 19:06:05 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x sfhassd&lt;BR /&gt;Jan 17 19:06:07 fpr-02 sudo: admin : TTY=ttyS0 ; PWD=/ ; USER=root ; COMMAND=/usr/bin/tail -f /ngfw/var/log/messages&lt;/P&gt;&lt;P&gt;Jan 17 19:06:09 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:06:18 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jan 17 19:06:29 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jan 17 19:06:38 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jan 17 19:06:49 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:00 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:09 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:11 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x snort&lt;BR /&gt;Jan 17 19:07:11 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x sfhassd&lt;BR /&gt;Jan 17 19:07:21 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:33 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:44 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:07:55 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:05 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:07 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x snort&lt;BR /&gt;Jan 17 19:08:07 fpr-02 sudo: root : PWD=/opt/cisco/csp/applications ; USER=root ; COMMAND=/usr/bin/pgrep -x sfhassd&lt;BR /&gt;Jan 17 19:08:13 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:23 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:34 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:46 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;BR /&gt;Jan 17 19:08:55 fpr-02 SF-IMS[8503]: [8730] SFDataCorrelator:adi.subscriber [INFO] GRPC-Client Session Directory connects to host unix:///tmp/vdi.socket&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;Here is log&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should i add from any to any allow to port 8305 is it unsafe? And should i close 8305 after registring?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998784#M1108059</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998787#M1108060</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt; you have to leave tcp/8305 that is how the FMC and FTD communicate to deploy policy and send event logs etc. You could limit the communication on the FTD in front of the FMC to restrict communication to the FMC from known networks. The communication over tcp/8305 is encrypted.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998787#M1108060</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-17T19:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998793#M1108061</link>
      <description>&lt;P&gt;i have opened 8305 port from anywhere to anywhere but still fails here is my netstat from FMC&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sheralimamatkarimov_0-1705518885123.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207681i0C4CCB1B50C7CAE5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sheralimamatkarimov_0-1705518885123.png" alt="sheralimamatkarimov_0-1705518885123.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And here from FTD&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sheralimamatkarimov_1-1705518920749.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207682i8364DF27DBA6CB59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sheralimamatkarimov_1-1705518920749.png" alt="sheralimamatkarimov_1-1705518920749.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998793#M1108061</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998797#M1108062</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt; you need to check the firewall logs of the FTD protecting the FMC and confirm traffic is or is not permitted. You can use the &lt;SPAN&gt; &lt;STRONG&gt;&lt;EM&gt;capture-traffic&lt;/EM&gt; &lt;/STRONG&gt;command and filter on tcp/8305 to confirm the communication.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998797#M1108062</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-17T19:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998806#M1108063</link>
      <description>&lt;P&gt;there is not connections with port 8305 how can i permit it from CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998806#M1108063</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998810#M1108064</link>
      <description>&lt;P&gt;what is interface you use to register FTD to FMC ?&lt;BR /&gt;Mgmt or OUTside data interface ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998810#M1108064</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T19:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998811#M1108065</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt; You do not permit from the CLI. You define the manager on the CLI (as you already appear to have done) and then from the FMC you register the device and communication is established. Example - &lt;A href="https://integratingit.wordpress.com/2018/10/20/ftd-registration-with-fmc/" target="_blank"&gt;https://integratingit.wordpress.com/2018/10/20/ftd-registration-with-fmc/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Have you checked the firewall logs of the FTD in front of the FMC to confirm the traffic is being permitted?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998811#M1108065</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-17T19:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998812#M1108066</link>
      <description>&lt;P&gt;Outside interface&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998812#M1108066</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998814#M1108067</link>
      <description>&lt;P&gt;Perfect&amp;nbsp;&lt;BR /&gt;are the FMC IP you use is behind NAT?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998814#M1108067</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T19:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998816#M1108068</link>
      <description>&lt;P&gt;Yes FMC IP is behind NAT&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998816#M1108068</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T19:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998818#M1108069</link>
      <description>&lt;PRE&gt;&amp;gt; &lt;STRONG&gt;configure manager add DONTRESOLVE Cisco-123 nat123&lt;/STRONG&gt;
&lt;/PRE&gt;
&lt;P&gt;then try this in FTD using key and NAT ID&amp;nbsp;&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998818#M1108069</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T19:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998820#M1108070</link>
      <description>&lt;PRE&gt;&amp;gt; &lt;STRONG&gt;configure manager add DONTRESOLVE Cisco-123 nat123&lt;/STRONG&gt;
&lt;/PRE&gt;
&lt;P&gt;use this in FTD and check&amp;nbsp;&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 19:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998820#M1108070</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T19:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998832#M1108073</link>
      <description>&lt;P&gt;I have configured as you have write but fails, i have added FTD without IP address but with register and nat id&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998832#M1108073</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T20:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998835#M1108074</link>
      <description>&lt;P&gt;One side must not use IP here fmc behind NAT so did you try above command ? Dis you use same key and NAT-ID in fmc side ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998835#M1108074</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T20:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998837#M1108075</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; написал (-а):&lt;BR /&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt;You do not permit from the CLI. You define the manager on the CLI (as you already appear to have done) and then from the FMC you register the device and communication is established. Example - &lt;A href="https://integratingit.wordpress.com/2018/10/20/ftd-registration-with-fmc/" target="_blank" rel="noopener"&gt;https://integratingit.wordpress.com/2018/10/20/ftd-registration-with-fmc/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Have you checked the firewall logs of the FTD in front of the FMC to confirm the traffic is being permitted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In that case FTD and FMC are in one subnet, but in my case FMC remote and i cant see capture traffic as i am going to connect to FMC not by managment0 interface&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998837#M1108075</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T20:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998838#M1108076</link>
      <description>&lt;P&gt;Of course using same key and NAT ID yes i tried do as you have written))&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998838#M1108076</guid>
      <dc:creator>sherali mamatkarimov</dc:creator>
      <dc:date>2024-01-17T20:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998841#M1108078</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1657874"&gt;@sherali mamatkarimov&lt;/a&gt; you can capture on the FTD traffic in front of the FMC (the firewall that is natting the traffic and permitting the connections), you can &lt;STRONG&gt;system support&lt;/STRONG&gt; &lt;STRONG&gt;firewall-engine-debug&lt;/STRONG&gt; as you would troubleshooting any other connection issue - &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or you can run tcpdump on the FMC, you can check the events in the FMC if you filter on the remote FTD. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998841#M1108078</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-17T20:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD to remote FMC register problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998843#M1108079</link>
      <description>&lt;P&gt;then did you use&amp;nbsp;&lt;BR /&gt;configure network management-data-interface&amp;lt;&amp;lt;- please read about this command before you apply it&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/device_management_basics.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/device_management_basics.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;again read about this command before apply&amp;nbsp;&lt;BR /&gt;thanks&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (88).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207686iB5B88FC8BD3AAB52/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (88).png" alt="Screenshot (88).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 20:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-to-remote-fmc-register-problem/m-p/4998843#M1108079</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-17T20:16:05Z</dc:date>
    </item>
  </channel>
</rss>

