<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FMC 2600 - implementing IPv6 and hardening the FTDs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348702#M1123592</link>
    <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;My FMC is a 2600, running version 7.7.1.10.&amp;nbsp; Do you have any documents that I can reference and compare my current settings against future IPv6 development in our enterprise?&lt;/P&gt;&lt;P&gt;My IPS models are 2130, 4120, 4125 devices with various FTD software versions.&amp;nbsp; Each 41XX device chassis is running the highest FXOS version Cisco has released.&amp;nbsp; Do you have any thing specific to these devices regarding IPv6?&lt;/P&gt;&lt;P&gt;The Cisco Secure Firewall Threat Defense Hardening guide you mention, we have reviewed and applied that prior to adding IPv6 to our environment, but I did not see anything specific guide related to IPv6.&amp;nbsp; If you have the most current version please provide it.&lt;/P&gt;&lt;P&gt;Defense in Depth is what we have here, and I agree.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Nov 2025 13:03:04 GMT</pubDate>
    <dc:creator>robert-l-swafford2-ctr</dc:creator>
    <dc:date>2025-11-20T13:03:04Z</dc:date>
    <item>
      <title>Cisco FMC 2600 - implementing IPv6 and hardening the FTDs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348377#M1123584</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;We are in the process of implementing IPv6 addresses in an established IPv4 enterprise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for anyone that has go through this process in the past and could offer some lessons learned.&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Does anyone know of any recommended FMC hardening configurations specifically for the FMC and IPv6?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Has anyone discovered any IPv6 hardening configuration guides that might offered a how to?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Has anyone developed and dashboard widgets with in the FMC to display IPv6 events separate of IPv4 events?&lt;/P&gt;&lt;P&gt;If anyone has any other lesson learn topics I failed to ask, please offer them.&lt;/P&gt;&lt;P&gt;Version 7.7.10 (build 3089)&lt;BR /&gt;Model Cisco Secure Firewall Management Center 2600&lt;BR /&gt;Serial Number XXXXXXXXXX&lt;BR /&gt;Snort Version 2.9.24 (Build 99)&lt;BR /&gt;Snort3 Version 3.3.5.1000 (Build 57)&lt;BR /&gt;Rule Pack Version 3178&lt;BR /&gt;Module Pack Version 3568&lt;BR /&gt;LSP Version lsp-rel-20251117-1954&lt;BR /&gt;VDB Version build 418 (2025-11-04 09:21:45)&lt;BR /&gt;Rule Update Version 2025-11-17-001-vrt&lt;BR /&gt;Geolocation Version 2025-11-08-029&lt;BR /&gt;OS Cisco Firepower Extensible Operating System (FX-OS) 82.17.26 (build 14)&lt;BR /&gt;Hostname XXXXXXXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 12:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348377#M1123584</guid>
      <dc:creator>robert-l-swafford2-ctr</dc:creator>
      <dc:date>2025-11-19T12:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC 2600 - implementing IPv6 and hardening the FTDs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348685#M1123591</link>
      <description>&lt;P&gt;Hardening FMC for IPv6 involves both general FMC security and steps specific to FXOS and IPv6 traffic,&amp;nbsp;Limit access to management interfaces and regularly audit user privileges.&lt;/P&gt;&lt;P&gt;Harden FXOS (Firepower Extensible OS) itself,&amp;nbsp;Restrict FMC management access to trusted networks/subnets (using Platform Settings) for both IPv4 and IPv6.&lt;/P&gt;&lt;P&gt;Monitor and apply Cisco security advisories for your specific FMC version, as IPv6 support and vulnerabilities frequently evolve.&lt;/P&gt;&lt;P&gt;Available IPv6 Hardening Guides,&amp;nbsp;The "Cisco Secure Firewall Threat Defense Hardening Guide" (see v7.2 or greater) provides hardening recommendations that address both IPv4 and IPv6, including device policies and access control for mixed environments.&lt;BR /&gt;&lt;BR /&gt;I think you just need to take approach of First, second and third layer of Defence.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 12:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348685#M1123591</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-11-20T12:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC 2600 - implementing IPv6 and hardening the FTDs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348702#M1123592</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;My FMC is a 2600, running version 7.7.1.10.&amp;nbsp; Do you have any documents that I can reference and compare my current settings against future IPv6 development in our enterprise?&lt;/P&gt;&lt;P&gt;My IPS models are 2130, 4120, 4125 devices with various FTD software versions.&amp;nbsp; Each 41XX device chassis is running the highest FXOS version Cisco has released.&amp;nbsp; Do you have any thing specific to these devices regarding IPv6?&lt;/P&gt;&lt;P&gt;The Cisco Secure Firewall Threat Defense Hardening guide you mention, we have reviewed and applied that prior to adding IPv6 to our environment, but I did not see anything specific guide related to IPv6.&amp;nbsp; If you have the most current version please provide it.&lt;/P&gt;&lt;P&gt;Defense in Depth is what we have here, and I agree.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 13:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348702#M1123592</guid>
      <dc:creator>robert-l-swafford2-ctr</dc:creator>
      <dc:date>2025-11-20T13:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FMC 2600 - implementing IPv6 and hardening the FTDs</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348972#M1123600</link>
      <description>&lt;P&gt;IPv6 provides a significantly more secure and scalable addressing architecture compared to its predecessor, IPv4. When your security appliances—such as Cisco FMC-FTD are properly configured, continuously monitored, and maintained, the overall security posture remains strong.&lt;/P&gt;&lt;P&gt;Ensure that all systems are updated with the latest patches and that known vulnerabilities are remediated promptly. Apply the principles of least privilege and need-to-know to limit unnecessary access. In addition, enable comprehensive auditing and logging to support monitoring, incident detection, and forensic analysis.&lt;/P&gt;&lt;P&gt;Information specific to IPv6 security can sometimes be limited, but following these fundamental security practices provides a solid foundation for operating securely in an IPv6 environment.&lt;/P&gt;&lt;P&gt;Just a side note FTD2100,FTD4100 are now End Of Life (EOL)&lt;BR /&gt;&lt;BR /&gt;Check this link might find useful for you&lt;BR /&gt;&lt;A href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3270451/nsa-publishes-internet-protocol-version-6-ipv6-security-guidance/" target="_blank"&gt;https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3270451/nsa-publishes-internet-protocol-version-6-ipv6-security-guidance/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 09:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fmc-2600-implementing-ipv6-and-hardening-the-ftds/m-p/5348972#M1123600</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-11-21T09:37:43Z</dc:date>
    </item>
  </channel>
</rss>

