<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTDv-HA different setttings in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376869#M1124747</link>
    <description>&lt;P&gt;Yes, for mgmg if not accessable for some reason as I have read.&lt;BR /&gt;So. FTDv2 cannot resolve&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; ping cisco.com
Please use 'CTRL+C' to cancel/abort...

 ping cisco.com
      ^
ERROR: % Invalid Hostname&lt;/LI-CODE&gt;&lt;P&gt;but DNS is configured...&lt;/P&gt;&lt;P&gt;also no ping working&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; ping 8.8.8.8
Please use 'CTRL+C' to cancel/abort...

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
?????
Success rate is 0 percent (0/5)
&amp;gt; &lt;/LI-CODE&gt;&lt;P&gt;I think this due to FTDv2 does not has IPs configured...no OUTSIDE, no INSIDE ip addresses.&lt;BR /&gt;I have read that it is not neccesary as after Pri dies, config migrates to second node, with same IP interfaces setting&lt;/P&gt;</description>
    <pubDate>Mon, 16 Mar 2026 13:55:53 GMT</pubDate>
    <dc:creator>s_SiD_s</dc:creator>
    <dc:date>2026-03-16T13:55:53Z</dc:date>
    <item>
      <title>FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376837#M1124740</link>
      <description>&lt;P&gt;Good day!&lt;BR /&gt;I have set up FTDv-HA and everything work like a charm.&lt;/P&gt;&lt;P&gt;One thing I have noticed. it is output of &lt;EM&gt;show network&lt;/EM&gt; command on CLI of both FTDv&lt;BR /&gt;PRI\Active shows&lt;/P&gt;&lt;PRE&gt;&amp;gt; show network
===============[ System Information ]===============
Hostname : firepower&lt;/PRE&gt;&lt;P&gt;---&lt;BR /&gt;And Secondary\Standby&lt;/P&gt;&lt;PRE&gt;&amp;gt; show network

===============[ System Information ]===============
Hostname : FTDv
Domains : netcompz.org&lt;/PRE&gt;&lt;P&gt;different hostnames and...for the Standby...show Domains, but Primary does not show up...&lt;/P&gt;&lt;P&gt;all the rest output is OK.&lt;/P&gt;&lt;P&gt;how to change hostnames and Domains settings?&lt;/P&gt;&lt;P&gt;On GUI, see attached, names are OK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261091i255CAE37F4FE7684/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 12:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376837#M1124740</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T12:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376846#M1124741</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750984"&gt;@s_SiD_s&lt;/a&gt; from the CLI of each FTD use the "configure network" command to change the settings.&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/c_3.html#wp3524022327" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/c_3.html#wp3524022327&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 11:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376846#M1124741</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-16T11:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376852#M1124742</link>
      <description>&lt;P&gt;Great! Thanks!&lt;BR /&gt;If you don't mind, I will ask more couple of quiestions)&lt;/P&gt;&lt;P&gt;1. does hostname will be resolved to ftdv1.netcompz.org&lt;BR /&gt;and ftdv2.netcompz.org&lt;/P&gt;&lt;P&gt;if we add A and reverse records ro internal DNS server? Or better take names form GUI?&lt;/P&gt;&lt;P&gt;or better to make same names in GUI and CLI?&lt;/P&gt;&lt;P&gt;2. Cannot find information about this string in&lt;EM&gt; show network&amp;nbsp;&lt;/EM&gt;comand. FTDv-Pri has it disabled and FTDv-Sec - enabled.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DNS from router           : disabled&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 12:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376852#M1124742</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T12:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376854#M1124743</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750984"&gt;@s_SiD_s&lt;/a&gt;&amp;nbsp;if you add the approprirate entries in your DNS servers, then yes the hostname would be resolved. You just need a friendly/memorable name to resolve in DNS, whether thats the hostname in the CLI or GUI. The names don't necessarily need to be the same name in the CLI and GUI.&lt;/P&gt;
&lt;P&gt;Is DNS statically configured on one FTD and not the other?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 12:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376854#M1124743</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-16T12:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376863#M1124744</link>
      <description>&lt;P&gt;As I remember, both configured statically, as an ip addresses&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;configure network dns servers&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;i also notied that there is no static route on FTDv2&lt;BR /&gt;like on FTDv1. Interesting, what did I miss... during deploy&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTDv1.png" style="width: 560px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261092i562E60F9B213EEB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTDv1.png" alt="FTDv1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTDv2.png" style="width: 562px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261093i29EBD40723CEB0A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTDv2.png" alt="FTDv2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 13:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376863#M1124744</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T13:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376864#M1124745</link>
      <description>&lt;PRE&gt;&lt;STRONG&gt;configure network static-routes ipv4 add management1 10.201.0.0&amp;nbsp;255.255.0.0&amp;nbsp;10.201.213.254&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;by this command I can add static route to FTDv2&lt;/P&gt;&lt;P&gt;as FTDv1&lt;BR /&gt;&amp;gt; ping cisco.com&lt;BR /&gt;Please use 'CTRL+C' to cancel/abort...&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 72.163.4.185, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 150/154/160 ms&lt;BR /&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and FTDv2&lt;/P&gt;&lt;P&gt;&amp;gt; ping cisco.com&lt;BR /&gt;Please use 'CTRL+C' to cancel/abort...&lt;/P&gt;&lt;P&gt;ping cisco.com&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 13:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376864#M1124745</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T13:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376866#M1124746</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750984"&gt;@s_SiD_s&lt;/a&gt;&amp;nbsp;yes, you shouldn't need a static if you have the default route configured. That static route applies to the mgmt interface not data interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 13:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376866#M1124746</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-16T13:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376869#M1124747</link>
      <description>&lt;P&gt;Yes, for mgmg if not accessable for some reason as I have read.&lt;BR /&gt;So. FTDv2 cannot resolve&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; ping cisco.com
Please use 'CTRL+C' to cancel/abort...

 ping cisco.com
      ^
ERROR: % Invalid Hostname&lt;/LI-CODE&gt;&lt;P&gt;but DNS is configured...&lt;/P&gt;&lt;P&gt;also no ping working&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; ping 8.8.8.8
Please use 'CTRL+C' to cancel/abort...

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
?????
Success rate is 0 percent (0/5)
&amp;gt; &lt;/LI-CODE&gt;&lt;P&gt;I think this due to FTDv2 does not has IPs configured...no OUTSIDE, no INSIDE ip addresses.&lt;BR /&gt;I have read that it is not neccesary as after Pri dies, config migrates to second node, with same IP interfaces setting&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 13:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376869#M1124747</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T13:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376870#M1124748</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1750984"&gt;@s_SiD_s&lt;/a&gt;&amp;nbsp;use "ping &lt;STRONG&gt;system&lt;/STRONG&gt; cisco.com" which will ping from the mgmt interface.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 13:56:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376870#M1124748</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-16T13:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376872#M1124749</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; ping system cisco.com
PING cisco.com (72.163.4.185) 56(84) bytes of data.
64 bytes from redirect-ns.cisco.com (72.163.4.185): icmp_seq=1 ttl=49 time=154 ms
64 bytes from redirect-ns.cisco.com (72.163.4.185): icmp_seq=2 ttl=49 time=153 ms
64 bytes from redirect-ns.cisco.com (72.163.4.185): icmp_seq=3 ttl=49 time=153 ms
^C
--- cisco.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2001ms
rtt min/avg/max/mdev = 153.314/153.583/154.024/0.314 ms&lt;/LI-CODE&gt;&lt;P&gt;good)&lt;/P&gt;&lt;P&gt;1 question\setting still remains....&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DNS from router           : enabled&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;where this has been be configured... O_o&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 14:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5376872#M1124749</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-16T14:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377108#M1124763</link>
      <description>&lt;P&gt;I have tested HA by disconnecting OUTSIDE interface on ESXI vm properties.&lt;BR /&gt;Failover failed...we forgot to add FTDV2 inside interface to allowed vlan on cisco switch...&lt;BR /&gt;but now no errors I see before test HA again and found errors.&lt;/P&gt;&lt;P&gt;So before testing HA need to resolve this issue.&lt;/P&gt;&lt;P&gt;ip addresess PING-able&amp;nbsp;&lt;BR /&gt;NAT is working. no health issues.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="FTDv1_failover2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261148i6F2637A7A19424C0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FTDv1_failover2.png" alt="FTDv1_failover2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="FTDv2_failover2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261149i082C27E01FE1FF79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FTDv2_failover2.png" alt="FTDv2_failover2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may be reboot both FTDv? in which order if so?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="FTDv1_failover2_GUI.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261150i3D8040B6B0C8B1B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FTDv1_failover2_GUI.png" alt="FTDv1_failover2_GUI.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="FTDv2_failover2_GUI.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261151iFC4BB57EDF2030B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FTDv2_failover2_GUI.png" alt="FTDv2_failover2_GUI.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 11:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377108#M1124763</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-17T11:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377119#M1124765</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="graylog.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/261152iC91312B045D99F27/image-size/large?v=v2&amp;amp;px=999" role="button" title="graylog.png" alt="graylog.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;logs on Graylog...&amp;nbsp;&lt;BR /&gt;all interfaces UP and connected.&lt;BR /&gt;Checked everywhere.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 12:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377119#M1124765</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-17T12:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv-HA different setttings</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377188#M1124766</link>
      <description>&lt;P&gt;I have rebooted both FTDv and all seems to be OK.&lt;/P&gt;&lt;P&gt;test HA was as Pro server went to reload, monitoring intefaces not good as they are ALWAYS in UP state in dSwitch ESXi&lt;BR /&gt;one thing to sort out....how auto switch back to Primary FTDv...&lt;BR /&gt;i see everything is "green" on dashboard...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 10:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ha-different-setttings/m-p/5377188#M1124766</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2026-03-18T10:11:16Z</dc:date>
    </item>
  </channel>
</rss>

