<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower FMC and FTD Deployment Issues: in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057366#M431294</link>
    <description>&lt;P&gt;Dear Experts;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I Installed and configured the FMC with FTD, I just have some issues regarding this deployment.&lt;/P&gt;
&lt;P&gt;Deployment Senario:&lt;/P&gt;
&lt;P&gt;I configured the two passive interfaces (eth1, eth2) on the FTD server and Span the Email traffic on eth1 and Web traffic on eth2. FTD analyze the web traffic in eth2 but i need to verified email traffic coming in or not. As my knowledge the FTD has customized Linux OS. how I can verified that.?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the FMC health status, It shows that the URL filtering download failure error. How can i fix it and how can i check the direct connectivity in FTD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;your support required.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:03:43 GMT</pubDate>
    <dc:creator>Qamar Islam</dc:creator>
    <dc:date>2020-02-21T14:03:43Z</dc:date>
    <item>
      <title>Firepower FMC and FTD Deployment Issues:</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057366#M431294</link>
      <description>&lt;P&gt;Dear Experts;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I Installed and configured the FMC with FTD, I just have some issues regarding this deployment.&lt;/P&gt;
&lt;P&gt;Deployment Senario:&lt;/P&gt;
&lt;P&gt;I configured the two passive interfaces (eth1, eth2) on the FTD server and Span the Email traffic on eth1 and Web traffic on eth2. FTD analyze the web traffic in eth2 but i need to verified email traffic coming in or not. As my knowledge the FTD has customized Linux OS. how I can verified that.?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the FMC health status, It shows that the URL filtering download failure error. How can i fix it and how can i check the direct connectivity in FTD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;your support required.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057366#M431294</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2020-02-21T14:03:43Z</dc:date>
    </item>
    <item>
      <title>You can go into the OS and</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057367#M431299</link>
      <description>&lt;P&gt;You can go into the OS and use tcpdump to see the incoming packets on a given interface. That program requires root privilege so be sure to "sudo tcpdump".&lt;/P&gt;
&lt;P&gt;Regarding the health status, verify the FMC can reach the Internet and resolve addresses. You can also do this from the command line - telnet to an external host on port 80, nslookup etc. are all things you can do to verify.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 08:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057367#M431299</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-20T08:48:03Z</dc:date>
    </item>
    <item>
      <title>Thanks for your support</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057368#M431302</link>
      <description>&lt;P&gt;Thanks for your support Marvin&lt;/P&gt;
&lt;P&gt;On the CLI of FTD, I just have the limited commands. I tried to figure it out but nothings works following are the commands:&lt;/P&gt;
&lt;P&gt;configure&lt;/P&gt;
&lt;P&gt;exit&lt;/P&gt;
&lt;P&gt;expert&lt;/P&gt;
&lt;P&gt;history&lt;/P&gt;
&lt;P&gt;logout&lt;/P&gt;
&lt;P&gt;show&lt;/P&gt;
&lt;P&gt;systems&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The above are the commands.&lt;/P&gt;
&lt;P&gt;Kindly more elaborate the commands so can i fix the issues.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 09:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057368#M431302</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-04-20T09:27:17Z</dc:date>
    </item>
    <item>
      <title>You need to switch to "expert</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057369#M431303</link>
      <description>&lt;P&gt;You need to switch to "expert" mode. Then you will be in the Linux bash shell environment.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 10:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057369#M431303</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-20T10:48:05Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin;</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057370#M431304</link>
      <description>&lt;P&gt;Hi Marvin;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I just have a question:&lt;/P&gt;
&lt;P&gt;Can I add multiple FTD's in FMC.?&lt;/P&gt;
&lt;P&gt;I recently add FTD for the analysis of Web Traffic Now the client need to analysis for Email Traffic.&lt;/P&gt;
&lt;P&gt;The Email traffic coming from the regional sites too far from the existing site so I need to&amp;nbsp;deploy another FTD and add this to FMC and Span the email traffic on it.&lt;/P&gt;
&lt;P&gt;Can I add multiple FTD;s in FMC?&lt;/P&gt;
&lt;P&gt;I just deployed it but when registering in FMC I just get an error. Kindly find an attached error snap-shot&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Your kind support is needed.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 07:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057370#M431304</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-04-27T07:22:30Z</dc:date>
    </item>
    <item>
      <title>Yes - you can add multiple</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057371#M431305</link>
      <description>&lt;P&gt;Yes - you can add multiple FTD sensors in a given FMC (subject to your FMC license of 2- 10- or 25-device limit).&lt;/P&gt;
&lt;P&gt;The error you are getting is most commonly due to one of two reasons:&lt;/P&gt;
&lt;P&gt;1. Necessary network connectivity is not in place (tcp/8305 bidirectional is required between the FMC and all sensors)&lt;/P&gt;
&lt;P&gt;2. There is a NAT between the FMC and the sensor. In that case you need to use the "DONTRESOLVE" option as described here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118596-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;Also, the sensor version must not be higher than the FMC. (i.e cannot register a 6.2 sensor to a 6.1 FMC).&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 07:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057371#M431305</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T07:34:25Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057372#M431306</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;Yaa I just checked the tcp/8305 bidirectional port and following are the syslogs I just received.&lt;/P&gt;
&lt;P&gt;the FTD sensor ip address is 10.50.62.209&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE class="full-width horizontal-table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:12 FMC sudo: pam_unix(sudo:session): session closed for user root&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:12 FMC sudo: pam_unix(sudo:session): session opened for user root by (uid=0)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:12 FMC sudo: www : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/bin/chown www:www /var/log/CSMAgent.log&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] reconnect to peer '10.50.62.209' in 14 seconds&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] Unable to connect to peer '10.50.62.209'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] VerifyConnect:Failed to authenticate or to be authenticated by peer '10.50.62.209'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] Could not receive Message: Closed&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Successfully connected using SSL to: '10.50.62.209'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Connected to 10.50.62.209:8305 (IPv4)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Wait to connect to 8305 (IPv6): 10.50.62.209&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to 10.50.62.209:8305/tcp&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to 10.50.62.209 (via eth0)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] Connect to 10.50.62.209 on port 8305 - eth0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_peers [INFO] Peer 10.50.62.209 needs a single connection&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [4180] sftunneld:sf_connections [INFO] Start connection to : 10.50.62.209 (wait 0 seconds is up)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;what was the issue am just little confused in below logs:&lt;/P&gt;
&lt;TABLE class="full-width horizontal-table"&gt;
&lt;TBODY&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [INFO] reconnect to peer '10.50.62.209' in 14 seconds&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] Unable to connect to peer '10.50.62.209'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=" alternate"&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] VerifyConnect:Failed to authenticate or to be authenticated by peer '10.50.62.209'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Apr 27 2017 13:45:08 FMC SF-IMS[4134]: [652] sftunneld:sf_ssl [WARN] Could not receive Message: Closed&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;both are on the same versions 6.1&lt;/P&gt;
&lt;P&gt;find attached snap-shot for adding another FTD&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 09:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057372#M431306</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-04-27T09:39:21Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057373#M431308</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I just registered the FTD thanks for your support.you are right that, we just have the port issue on both FMC and FTD. THanks&lt;/P&gt;
&lt;P&gt;Now i just have an issue for the licenses. How can i generate the licenses for that FTD.?&lt;/P&gt;
&lt;P&gt;I just assign the same policy for the previous FTD. I just need the steps to generate the licenses.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kindly find the below snapshot.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 12:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057373#M431308</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-04-27T12:32:04Z</dc:date>
    </item>
    <item>
      <title>FTD uses Smart Licenses. You</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057374#M431310</link>
      <description>&lt;P&gt;FTD uses Smart Licenses. You need to allocate them to your registered FMC in the Cisco portal:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;https://software.cisco.com/&lt;/P&gt;
&lt;P&gt;..and then apply them to the new sensor within FMC.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 12:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057374#M431310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T12:41:42Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057375#M431313</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I just registered another FTD and transferred the SMTP traffic through span port.&lt;/P&gt;
&lt;P&gt;I just have some quries:&lt;/P&gt;
&lt;P&gt;How I can check and analysis of SMTP traffic?&lt;/P&gt;
&lt;P&gt;How can I check that the traffic is coming or not?&lt;/P&gt;
&lt;P&gt;what are the commands in FMC and FTD to find the SMTP or port 25 traffic?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 12:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057375#M431313</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-04-28T12:57:40Z</dc:date>
    </item>
    <item>
      <title>You can simply query the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057376#M431316</link>
      <description>&lt;P&gt;You can simply query the connection events and filter for smtp application.&lt;/P&gt;
&lt;P&gt;Analysis &amp;gt; Connections &amp;gt; Events. Then "Edit Search" and include only smtp.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 15:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057376#M431316</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-28T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin;</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057377#M431318</link>
      <description>&lt;P&gt;Hi Marvin;&lt;/P&gt;
&lt;P&gt;I analyzed all the events but there is not any sign of smtp or 25.&lt;/P&gt;
&lt;P&gt;How i can further checked the traffic. In FTD console i typed the command system support firewall engine debug, also type the filters on port 25 but nothing shown on it also.&lt;/P&gt;
&lt;P&gt;Your support needed.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 18:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057377#M431318</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-02T18:37:47Z</dc:date>
    </item>
    <item>
      <title>First off I'd confirm your</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057378#M431324</link>
      <description>&lt;P&gt;First off I'd confirm your span port is sending the smtp traffic. If it's physically nearby I'd just put a laptop with Wireshark on the port and grab a sample of the traffic.&lt;/P&gt;
&lt;P&gt;If you're running 6.2 you can do advanced troubleshooting - do a trace and/or pull a packet capture from the GUI.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/troubleshooting_the_system.html#id_41600&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 18:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057378#M431324</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-02T18:42:15Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin;</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057379#M431327</link>
      <description>&lt;P&gt;Hi Marvin;&lt;/P&gt;
&lt;P&gt;Good Day!&lt;/P&gt;
&lt;P&gt;As per the attack Ransomeware in globe WANNACRY. The client need to move this APT solution in INLINE mode.&lt;/P&gt;
&lt;P&gt;I just need little help for doing this activity.&lt;/P&gt;
&lt;P&gt;Yes the Email traffic now analysed. Now the POC is completed.&lt;/P&gt;
&lt;P&gt;Next Step:&lt;/P&gt;
&lt;P&gt;Now client need to move FMC and FTD in Inline mode.&lt;/P&gt;
&lt;P&gt;We will place FTD behind the web gateway. How many interfaces i need in FMC?&lt;/P&gt;
&lt;P&gt;I just have some quires regarding moving passive mode to inline mode, Now what are the requirements for inline deployment. How many ports i need in FTD&amp;nbsp; to take action on both email and the web traffic.?&lt;/P&gt;
&lt;P&gt;How web gateway push the traffic in FTD?&lt;/P&gt;
&lt;P&gt;How email gatemay push Email traffic in FTD?&lt;/P&gt;
&lt;P&gt;If you have any document for inline deployment of the FTD Kindly share it.&lt;/P&gt;
&lt;P&gt;I just have one night for this activity. Your kind support needed.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Qamar&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 14:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057379#M431327</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-15T14:37:14Z</dc:date>
    </item>
    <item>
      <title>Qamar,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057380#M431331</link>
      <description>&lt;P&gt;Qamar,&lt;/P&gt;
&lt;P&gt;What you are asking is more of a professional services request. Which Cisco or a partner could handle as a paid service.&lt;/P&gt;
&lt;P&gt;In general terms, FMC has a single interface for connecting to the managed devices as well as for administrative access to the server.&lt;/P&gt;
&lt;P&gt;FTD interface design is not unlike firewall interface design - it varies widely according to the client's requirements, both current and planned. A very simple deployment is shown in the Quick Start Guide here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5500X/ftd-fdm-5500x-qsg.html#pgfId-129862&lt;/P&gt;
&lt;P&gt;Of course if you have multiple interfaces and/or zones with varying secuirty levels, your deployment could vary quite a bit from a simple "inside, outside and management" setup.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 15:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057380#M431331</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-15T15:33:47Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057381#M431336</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Thanks for your support boss,&lt;/P&gt;
&lt;P&gt;Deployment scenario is on TRANSPARENT MODE.&lt;/P&gt;
&lt;P&gt;I just placed the FTD in between the WEB-Gateway and Core-Switch. The traffic coming from web-gateway to FTD and then goes to Core-switch and Vice versa.&lt;/P&gt;
&lt;P&gt;Web-gateway----FTD----Core-switch&lt;/P&gt;
&lt;P&gt;As the I just have the OVA file of FTD and i installed in ESXI and bind virtually 3 interfaces with it. I bind 1 management with the FTD management and other two used for inline traffic coming from one interface to the other.&lt;/P&gt;
&lt;P&gt;Inside to outside:&lt;/P&gt;
&lt;P&gt;One interface defined as INSIDE.&lt;/P&gt;
&lt;P&gt;Second Interface Defined as Outside.&lt;/P&gt;
&lt;P&gt;Now i just implemented the below configuration to get traffic from Inside interface and analyzed it and transferred it to the next hop.&lt;/P&gt;
&lt;P&gt;Kindly find an attached Snap-shots, I never get an ip-address of any interface inside or outside.&lt;/P&gt;
&lt;P&gt;Is my configuration is correct or any further changed kindly share please.&lt;/P&gt;
&lt;P&gt;I just transferred traffic in FTD but the traffic not coming out from the outside interface.&lt;/P&gt;
&lt;P&gt;Steps by steps snap-shots attached.&lt;/P&gt;
&lt;P&gt;Support needed boss.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 20:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057381#M431336</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-15T20:42:44Z</dc:date>
    </item>
    <item>
      <title>I recommend you open a TAC</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057382#M431338</link>
      <description>&lt;P&gt;I recommend you open a TAC case.&lt;/P&gt;
&lt;P&gt;It is most likely some aspect of your Access Control Policy that is blocking traffic - a default action is often the cuase for such behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 01:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057382#M431338</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-16T01:23:40Z</dc:date>
    </item>
    <item>
      <title>Thanks for your kind support.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057383#M431341</link>
      <description>&lt;P&gt;Thanks for your kind support.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards:&lt;/P&gt;
&lt;P&gt;Qamar&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 09:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057383#M431341</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-16T09:09:55Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057384#M431343</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I web traffic analysis topology is given below:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman'; color: black;"&gt;Firewall&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; &amp;lt;-&amp;gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; Web gateway(WCCP)&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; &amp;lt;-&amp;gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; FTD (inline Transparent mode)&amp;nbsp;&lt;WBR /&gt; &amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; &amp;lt;-&amp;gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; Core Switch&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; &amp;lt;-&amp;gt;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt;&amp;nbsp;&lt;WBR /&gt; users&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman'; color: black;"&gt;FMC and FTD virtualized.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman'; color: black;"&gt;Boss above is the topology of inline transparent mode deployment. Last night activity i just deployed the FTD virtual in between the web gateway and core switch. It worked fine and blocking and analysis works at all night but today morning at peak time when user connected to their network. After 3 hours the browsing is chocked. then i took back it to their production network.your suggestions required. Is their any limitations about the events connections with licenses or then above scenario any other possible troubleshooting required?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman'; color: black;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Times New Roman'; color: black;"&gt;Kindly suggest please.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 09:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057384#M431343</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-17T09:50:18Z</dc:date>
    </item>
    <item>
      <title>Connection events file</title>
      <link>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057385#M431344</link>
      <description>&lt;P&gt;Connection events file attached&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 09:55:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-fmc-and-ftd-deployment-issues/m-p/3057385#M431344</guid>
      <dc:creator>Qamar Islam</dc:creator>
      <dc:date>2017-05-17T09:55:04Z</dc:date>
    </item>
  </channel>
</rss>

