<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC FTD HA Cluster in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162638#M1115183</link>
    <description>&lt;P&gt;FTD HA active/standby or cluster ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2024 13:25:26 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-08-19T13:25:26Z</dc:date>
    <item>
      <title>FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162599#M1115179</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;currently we are facing a challenge to build FTD HA cluster using FMC while using the same interface for DATA and MANAGEMENT traffic processing.&lt;/P&gt;&lt;P&gt;However it turned out that on FTD models 1150 such setup is not supported. When building up a cluster we get message: "High availability not supported on this model for devices enabled for Management access through data interfaces".&lt;/P&gt;&lt;P&gt;In case we use our available public IPs for management interfaces to separate DATA and MANAGEMENT traffic there will be no left for outside interface to build VPN tunnel. In case we use private IPs for management interfaces we will not be able to publish any changes from FMC in case VPN tunnel will be down.&lt;/P&gt;&lt;P&gt;I would like to ask you what is the best practice to follow in such scenario.&lt;/P&gt;&lt;P&gt;Also I would like to ask you, in case we use public IPs for management interface, is there a way to secure this interface which will be facing public internet? (like limit access only from certain IPs, or deny ICMP, etc...)&lt;/P&gt;&lt;P&gt;Thanks a lot for any valuable information on these topics!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 12:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162599#M1115179</guid>
      <dc:creator>kamensky@kronovision.sk</dc:creator>
      <dc:date>2024-08-19T12:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162638#M1115183</link>
      <description>&lt;P&gt;FTD HA active/standby or cluster ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 13:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162638#M1115183</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-19T13:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162640#M1115184</link>
      <description>&lt;P&gt;HA active/ standby&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 13:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162640#M1115184</guid>
      <dc:creator>kamensky@kronovision.sk</dc:creator>
      <dc:date>2024-08-19T13:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162659#M1115186</link>
      <description>&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 18:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162659#M1115186</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-19T18:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162667#M1115187</link>
      <description>&lt;P&gt;FYI version 7.4 added support for this feature.&lt;/P&gt;
&lt;TABLE class="table frame-topbot table--pgwide-1" border="1" width="100%"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD colspan="4" class="entry align-left colsep-1 rowsep-1"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;High Availability/Scalability&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry align-left colsep-1 rowsep-1"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph"&gt;Manage threat defense high availability pairs using a data interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry align-left colsep-1 rowsep-1"&gt;
&lt;P class="p"&gt;7.4.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry align-left colsep-1 rowsep-1"&gt;
&lt;P class="p"&gt;7.4.0&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry align-left colsep-1 rowsep-1"&gt;
&lt;DIV id="Cisco_Concept.dita_f1d9dce2-d61d-4aaa-ba45-c419ab2d3d39__74_ha_data_interface" class="div"&gt;
&lt;P class="p"&gt;Threat defense high availability now supports using a regular data interface for communication with the management center. Previously, only standalone devices supported this feature.&lt;/P&gt;
&lt;P class="p"&gt;See: &lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/get-started-device-management.html" target="_blank" rel="noopener"&gt;Using the Threat Defense Data Interface for Management&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 19 Aug 2024 14:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162667#M1115187</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-19T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: FMC FTD HA Cluster</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162782#M1115194</link>
      <description>&lt;P&gt;Thanks a lot for info, tested, working.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 18:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-ha-cluster/m-p/5162782#M1115194</guid>
      <dc:creator>kamensky@kronovision.sk</dc:creator>
      <dc:date>2024-08-19T18:36:26Z</dc:date>
    </item>
  </channel>
</rss>

