<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: default gateway for FTD with two management interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/default-gateway-for-ftd-with-two-management-interfaces/m-p/5370120#M1124465</link>
    <description>&lt;P&gt;When you configure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="Yjhzub" data-complete="true"&gt;Manager Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;on a data interface, the FTD often defaults to using the existing system default gateway for that interface in its "management" context. Since you cannot change this gateway directly via the "show network" CLI or the basic interface settings, you must use&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="Yjhzub" data-complete="true"&gt;Static Routes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;within the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-complete="true"&gt;Cisco Secure Firewall Management Center (FMC)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to override this behaviour.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;check this guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222145-configure-manager-access-on-ftd-from-man.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222145-configure-manager-access-on-ftd-from-man.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Avoid configuring via the CLI, since the FMC overrides some configurations.&lt;/P&gt;
&lt;P&gt;You can deploy static content as an example; make changes as needed based on the setup.&lt;/P&gt;
&lt;P&gt;To fix the gateway for your secondary management interface (Ethernet1/4):&lt;BR /&gt;Configure a Static Route in FMC: Navigate to Devices &amp;gt; Device Management, select your FTD, and go to the Routing tab.&lt;BR /&gt;Target the FMC IP: Add a Static Route specifically for the IP address of your FMC.&lt;BR /&gt;Interface: Select inf_MySite-inside (Ethernet1/4).&lt;BR /&gt;Network: Enter the specific IP of your FMC (or its subnet).&lt;BR /&gt;Gateway: Enter the internal gateway IP you want to use for the VPN path.&amp;nbsp; and deploy the configure to FTD and test it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 15 Feb 2026 10:20:53 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2026-02-15T10:20:53Z</dc:date>
    <item>
      <title>default gateway for FTD with two management interfaces</title>
      <link>https://community.cisco.com/t5/network-security/default-gateway-for-ftd-with-two-management-interfaces/m-p/5370113#M1124464</link>
      <description>&lt;P&gt;I am using an Internet connected data interfaces to manage an FTD from FMC.&amp;nbsp; This is working as expected.&amp;nbsp; Now I want to add a 2nd interface as a backup management interface using a data interface connected to to my internal network.&amp;nbsp; &amp;nbsp;The 2nd interface needs to use a different gateway than what the primary interface is using to route over a VPN.&amp;nbsp; &amp;nbsp;When I do a "show network" it shows up as using the same gateway as my Internet connected interface.&amp;nbsp; I added it using the GUI and didn't see any option for setting a gateway. I can't find a way to change it from the management CLI either. There does seem to be a way to setup static routes using the CLI which might help here.&amp;nbsp; I have attached the output of the "show network" command for reference.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2026 04:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-gateway-for-ftd-with-two-management-interfaces/m-p/5370113#M1124464</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2026-02-15T04:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: default gateway for FTD with two management interfaces</title>
      <link>https://community.cisco.com/t5/network-security/default-gateway-for-ftd-with-two-management-interfaces/m-p/5370120#M1124465</link>
      <description>&lt;P&gt;When you configure&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="Yjhzub" data-complete="true"&gt;Manager Access&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;on a data interface, the FTD often defaults to using the existing system default gateway for that interface in its "management" context. Since you cannot change this gateway directly via the "show network" CLI or the basic interface settings, you must use&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="Yjhzub" data-complete="true"&gt;Static Routes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;within the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-complete="true"&gt;Cisco Secure Firewall Management Center (FMC)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to override this behaviour.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;check this guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222145-configure-manager-access-on-ftd-from-man.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222145-configure-manager-access-on-ftd-from-man.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Avoid configuring via the CLI, since the FMC overrides some configurations.&lt;/P&gt;
&lt;P&gt;You can deploy static content as an example; make changes as needed based on the setup.&lt;/P&gt;
&lt;P&gt;To fix the gateway for your secondary management interface (Ethernet1/4):&lt;BR /&gt;Configure a Static Route in FMC: Navigate to Devices &amp;gt; Device Management, select your FTD, and go to the Routing tab.&lt;BR /&gt;Target the FMC IP: Add a Static Route specifically for the IP address of your FMC.&lt;BR /&gt;Interface: Select inf_MySite-inside (Ethernet1/4).&lt;BR /&gt;Network: Enter the specific IP of your FMC (or its subnet).&lt;BR /&gt;Gateway: Enter the internal gateway IP you want to use for the VPN path.&amp;nbsp; and deploy the configure to FTD and test it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2026 10:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-gateway-for-ftd-with-two-management-interfaces/m-p/5370120#M1124465</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-15T10:20:53Z</dc:date>
    </item>
  </channel>
</rss>

