<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD sourcing from 169.254.1.3 address for LDAP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237853#M1118290</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320506"&gt;@carl_townshend&lt;/a&gt;, as shown in &lt;A href="https://community.cisco.com/t5/network-security/ftp-creating-ad-realm-in-cdfmc/m-p/5237532#M1118270" target="_self"&gt;this&lt;/A&gt; other post, your firewall seems not to have the data interfaces configured yet, this would explain why is showing nothing when you click on the interfaces drop down menu.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2024 10:00:09 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2024-12-17T10:00:09Z</dc:date>
    <item>
      <title>FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237833#M1118284</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;I am trying to troubleshoot an issue with LDAP from my FTD, I have the ftd onboarded to the cloud cdFMC for management.&lt;/P&gt;&lt;P&gt;I have done a packet capture and I can see the requests are coming from 169.254.1.3 rather than the inside interface IP.&lt;/P&gt;&lt;P&gt;How do we change / fix this behaviour?&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 08:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237833#M1118284</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2024-12-17T08:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237848#M1118287</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320506"&gt;@carl_townshend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This IP address means some interface is configured for DHCP and is not receiving IP address and It using APIPA address&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237848#M1118287</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-17T09:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237853#M1118290</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320506"&gt;@carl_townshend&lt;/a&gt;, as shown in &lt;A href="https://community.cisco.com/t5/network-security/ftp-creating-ad-realm-in-cdfmc/m-p/5237532#M1118270" target="_self"&gt;this&lt;/A&gt; other post, your firewall seems not to have the data interfaces configured yet, this would explain why is showing nothing when you click on the interfaces drop down menu.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 10:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237853#M1118290</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-12-17T10:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237901#M1118294</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The inside and outside interfaces are both configured with IP addresses and zones, I can also ping them both fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237901#M1118294</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2024-12-17T12:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237909#M1118296</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when you integration LDAP with FTD try select interface that reachable from LDAP&lt;BR /&gt;I think OUTside is Good&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.1.-Cisco-FMC-Realm-Types-.png" style="width: 667px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236067i699C8DD89AEB1B94/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.1.-Cisco-FMC-Realm-Types-.png" alt="1.1.-Cisco-FMC-Realm-Types-.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237909#M1118296</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-17T12:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237913#M1118297</link>
      <description>&lt;P&gt;It's weird then why it's showing empty in the interfaces drop down menu. Have you managed to configure the management interface with the right IP as well?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 12:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5237913#M1118297</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-12-17T12:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238040#M1118301</link>
      <description>&lt;P&gt;The behavior you're observing—LDAP requests originating from 169.254.1.3 on your Cisco Firepower Threat Defense (FTD) device—is due to the diagnostic interface being used as the source for system-generated traffic, including LDAP queries. This is common for scenarios where the source interface for such traffic is not explicitly defined.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 16:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238040#M1118301</guid>
      <dc:creator>vishalbhandari</dc:creator>
      <dc:date>2024-12-17T16:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238067#M1118303</link>
      <description>&lt;P&gt;Hi, is there some sort of bug then?&lt;/P&gt;&lt;P&gt;I managed to get around it by creating a Nat rule for from the 169 address to the inside interface ip.&lt;/P&gt;&lt;P&gt;also, the other issue was the firewall not doing dns lookups when testing the ldap connection, even though I had internal dns servers configured on my platform settings and I could ping when using the ftd cli, when I did an ldap test I never saw any dns lookups coming from the ftd, to fix this I had to go onto the ftd itself and configure the network dns to an internal server, &amp;nbsp;the ldap then worked, the only issue I have now is that it won’t apply the LDAP configuration to the ftd, the deployment fails validation and days contact Cisco TAC, something to do with not accepting the ldap username.&lt;/P&gt;&lt;P&gt;maybe I need flexconfig for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 17:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238067#M1118303</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2024-12-17T17:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238378#M1118312</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;For ref, please see the below from the CDO instructions, you can see it does create a NAT for (outside) by default for the internal management interface traffic, I had to add a rule manually for the (inside) interface&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.defenseorchestrator.com/cdfmc/r_troubleshoot-management-connectivity.html" target="_blank"&gt;Troubleshoot Management Connectivity on a Data Interface&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="carltownshend_0-1734522344189.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236163i3848B18CA1D598CD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="carltownshend_0-1734522344189.png" alt="carltownshend_0-1734522344189.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 11:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238378#M1118312</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2024-12-18T11:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238393#M1118317</link>
      <description>&lt;P&gt;Thanks for sharing this.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 12:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238393#M1118317</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-12-18T12:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238396#M1118318</link>
      <description>&lt;P&gt;Why make long steps&lt;/P&gt;
&lt;P&gt;Instead use outside as interface connect to ldap instead of using inside and NAT to outside.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 12:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238396#M1118318</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-18T12:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238407#M1118320</link>
      <description>&lt;P&gt;Hi, my LDAP servers are on the inside not outside, so they need to point this way&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 12:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238407#M1118320</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2024-12-18T12:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTD sourcing from 169.254.1.3 address for LDAP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238416#M1118321</link>
      <description>&lt;P&gt;If that SO why you NAT to outside?.?&lt;/P&gt;
&lt;P&gt;Anyway goodluck&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 12:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-sourcing-from-169-254-1-3-address-for-ldap/m-p/5238416#M1118321</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-18T12:59:54Z</dc:date>
    </item>
  </channel>
</rss>

