<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sub-interface configuration limit on FTD managed via FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193330#M1115691</link>
    <description>&lt;P&gt;Thanks for the response. Responding to your question about chassis manager, yes, after I couldn't get the sub-interface configured, I went to the chassis manager and was able to configure the 17th interface from there and then associated it with the instance and then synced it to the FMC, but my doubt is that I couldn't create the sub-interface via FMC and I was wondering if there's was a limit to creating sub interfaces via FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 16:04:35 GMT</pubDate>
    <dc:creator>adebola</dc:creator>
    <dc:date>2024-09-11T16:04:35Z</dc:date>
    <item>
      <title>Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193235#M1115688</link>
      <description>&lt;DIV id="content" class="style-scope ytd-expander"&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;I need to ask a question. We've got an FTD managed by an FMC with interfaces configured as follows:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;INSIDE - 1 sub-interface&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;OUTSIDE - 16 sub-interfaces&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;All sub interfaces on the OUTSIDE side were configured via the chassis manager. Sub-interface on the INSIDE was configured via FMC.&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;We need to configure a 17th sub-interface on the OUTSIDE interface and the OUSIDE interface is grayed out and only the INSIDE interface is available.&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;Creating sub interfaces on an FMC managed FTD that already has 16 sub interfaces on the OUTSIDE interface, the FMC wouldn't allow it. I could create on the INSIDE interface that's got just one sub interface, but I couldn't on the OUTSIDE interface that already has 16.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="style-scope ytd-expander"&gt;&lt;SPAN class="yt-core-attributed-string yt-core-attributed-string--white-space-pre-wrap"&gt;Can anyone tell me if there's a limitation to 16 sub interfaces on the FMC? If i create it on the chassis, I'm able to sync and use it on the FMC, just couldn't create it from there after 16 sub interfaces.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV id="toolbar" class="style-scope ytd-comment-engagement-bar"&gt;
&lt;DIV class="yt-spec-button-shape-next__icon" aria-hidden="true"&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="yt-spec-touch-feedback-shape yt-spec-touch-feedback-shape--touch-response" aria-hidden="true"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228953i9CAF35ED7010CF9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="imagem.png" alt="imagem.png" /&gt;&lt;/span&gt;
&lt;P&gt; &lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Sep 2024 13:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193235#M1115688</guid>
      <dc:creator>adebola</dc:creator>
      <dc:date>2024-09-11T13:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193320#M1115690</link>
      <description>&lt;P&gt;I don't believe there is any limitation with FMC to create more than 16 subinterfaces, actually the limitation of how many subinterface you can create on an FTD is bound to the FTD hardware not to the FMC. Not sure if there is anything you should do to kinda handover the OUTSIDE interface management from the chassis manager to the FMC, I'm not so familiar with the chassis manager. Did you try to create the subinterface from the chassis manager?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 15:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193320#M1115690</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-09-11T15:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193330#M1115691</link>
      <description>&lt;P&gt;Thanks for the response. Responding to your question about chassis manager, yes, after I couldn't get the sub-interface configured, I went to the chassis manager and was able to configure the 17th interface from there and then associated it with the instance and then synced it to the FMC, but my doubt is that I couldn't create the sub-interface via FMC and I was wondering if there's was a limit to creating sub interfaces via FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 16:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193330#M1115691</guid>
      <dc:creator>adebola</dc:creator>
      <dc:date>2024-09-11T16:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193340#M1115692</link>
      <description>&lt;P&gt;You did not mention your platform or software version, but there are some important distinctions explained here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/2120/web-guide/b_GUI_FXOS_ConfigGuide_2120/interface_management.html#id_90184" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/2120/web-guide/b_GUI_FXOS_ConfigGuide_2120/interface_management.html#id_90184&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 16:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193340#M1115692</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-09-11T16:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193397#M1115695</link>
      <description>&lt;P&gt;Thanks Marvin for sharing the link. I have looked at this information before. Here is the information about version and platform as requested.&lt;/P&gt;
&lt;P&gt;Cisco Firepower 4115 running FXOS 2.12&lt;BR /&gt;FMC/FTD version: 7.2.8.&lt;/P&gt;
&lt;P&gt;Thanks once again.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 18:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193397#M1115695</guid>
      <dc:creator>adebola</dc:creator>
      <dc:date>2024-09-11T18:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193426#M1115696</link>
      <description>&lt;P&gt;Are you by chance running the FTD in multi-instance?&amp;nbsp; It could be that you need to add the subinterface at the chassis level before you can configure it in the FMC.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 20:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193426#M1115696</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-09-11T20:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193815#M1115718</link>
      <description>&lt;P&gt;Yes mate! It's a multi-instance FTD. I figured out we needed to do the configuration via chassis manager which we did and it worked. What I didn't get was that I could create sub interfaces on the INSIDE interface using the FMC without having to do that through the chassis manager, but OUTSIDE interface wouldn't let me do it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Information I forgot to add is that both INSIDE and OUTSIDE interfaces are Port channels.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 13:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5193815#M1115718</guid>
      <dc:creator>adebola</dc:creator>
      <dc:date>2024-09-12T13:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194017#M1115727</link>
      <description>&lt;P&gt;What I believe has happened is that when the FTD was set up, the "whole" inside interface or Port-channel was provisioned to the FTD instance, while the outside Port-channel only the sub-interface was provisioned.&amp;nbsp; This might be because the different instances are sharing that interface for access outside the network.&amp;nbsp; So that would mean that you have full access to the inside interface and will be able to define sub-interfaces while the outside interface you would need to create the sub-interface on the chassis and then provision it to the instance before you can make use of it.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 21:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194017#M1115727</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-09-12T21:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194328#M1115765</link>
      <description>&lt;P&gt;Hello Marius!&lt;/P&gt;
&lt;P&gt;i went back to the chassis manager just to be verify what you pointed out. I can confirm that both port-channels were configured the same way and associated the same way to the FTD instance. I'm sharing some screenshots of the chassis configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm grateful to everyone who has contributed to this. i would like to understand this FMC behaviour so I can avoid having this problem in future configurations as a Field Engineer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-13 100218.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/229096i7439FB292915E832/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-09-13 100218.png" alt="Screenshot 2024-09-13 100218.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-13 100551.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/229097i31AF3F8F4E8707E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-09-13 100551.png" alt="Screenshot 2024-09-13 100551.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 13:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194328#M1115765</guid>
      <dc:creator>adebola</dc:creator>
      <dc:date>2024-09-13T13:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface configuration limit on FTD managed via FMC</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194842#M1115798</link>
      <description>&lt;P&gt;I do not believe you are sharing the "parent interface" or parent port-channel 6 with the instance.&amp;nbsp; This because you are not able to select it in the FMC / application configuration.&amp;nbsp; So as mentioned earlier, port-channel 5 is being shared completely with the instance you are configuring, while port-channel 6 is only sharing the sub-interfaces.&amp;nbsp; The below is taken from a Cisco document also linked to below.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;H4 class="title sectiontitle"&gt;VLAN Subinterfaces&lt;/H4&gt;
&lt;P class="p"&gt;For all logical devices, you can create VLAN subinterfaces within the application.&lt;/P&gt;
&lt;P class="p"&gt;For container instances&lt;SPAN class="ph"&gt; in standalone mode&lt;/SPAN&gt; only, you can &lt;EM class="ph i"&gt;also&lt;/EM&gt; create VLAN subinterfaces in FXOS.&lt;SPAN class="ph"&gt; Multi-instance clusters do not support subinterfaces in FXOS except on the Cluster-type interface. &lt;/SPAN&gt; Application-defined subinterfaces are not subject to the FXOS limit. Choosing in which operating system to create subinterfaces depends on your network deployment and personal preference. For example, to share a subinterface, you must create the subinterface in FXOS. Another scenario that favors FXOS subinterfaces comprises allocating separate subinterface groups on a single interface to multiple instances. For example, you want to use Port-channel1 with VLAN 2–11 on instance A, VLAN 12–21 on instance B, and VLAN 22–31 on instance C. If you create these subinterfaces within the application, then you would have to share the parent interface in FXOS, which may not be desirable. See the following illustration that shows the three ways you can accomplish this scenario:&lt;/P&gt;
&lt;P class="p"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html#id_20107" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html#id_20107&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 07:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-configuration-limit-on-ftd-managed-via-fmc/m-p/5194842#M1115798</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-09-16T07:32:00Z</dc:date>
    </item>
  </channel>
</rss>

