<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI changes occurring directly on managed devices without using the FMC? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380739#M923895</link>
    <description>&lt;P&gt;With the exception of the configuration of the management port, all config is applied&amp;nbsp;one-way from the FMC to the managed device. At least&amp;nbsp;for the next time, there is no configuration on the device that is pushed to the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to have best of both worlds (locally and centrally managed), you could achieve that with the FTD-API. Local changes could be done by FDM,&amp;nbsp;and also a central management-server (which is &lt;STRONG&gt;not&lt;/STRONG&gt; FMC) can fetch all config from FTD, alter it and push it back to the device.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 May 2018 14:45:49 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2018-05-09T14:45:49Z</dc:date>
    <item>
      <title>CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380628#M923892</link>
      <description>&lt;P&gt;Just curious if I could make any sort of CLI changes on my managed devices w/o using the FMC, and if I did would those changes be synced with the FMC or is it the case that once I set up a device to be managed by the FMC that all my configuration changes such as access control policies would need to be done via the FMC GUI in order to stay synced?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380628#M923892</guid>
      <dc:creator>tayon.kendrick</dc:creator>
      <dc:date>2020-02-21T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380631#M923893</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ideally, no config changes are permitted on the device vis CLI apart from basic network settings for the device itself to connect to FMC /internet.&lt;/P&gt;
&lt;P&gt;Can you elaborate more on what kind of device you are using and what changes you want to make on that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 12:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380631#M923893</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-05-09T12:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380737#M923894</link>
      <description>Thank Yogesh for your reply.&lt;BR /&gt;&lt;BR /&gt;My FMC is currently managing a Cisco Firepower 4140, and 3 ASA 5545's, with&lt;BR /&gt;all of these devices being HA.&lt;BR /&gt;&lt;BR /&gt;I have a client who prefers to make ASA ACL policy changes via the ASA's&lt;BR /&gt;still, if allowed. My question was still more general and hypothetical in&lt;BR /&gt;nature.&lt;BR /&gt;&lt;BR /&gt;I understand the purpose of the FMC and that's what makes using it ideal,&lt;BR /&gt;however, if he does make changes on his end on the ASA, how would it affect&lt;BR /&gt;the sync process, deploy process, etc....&lt;BR /&gt;</description>
      <pubDate>Wed, 09 May 2018 14:45:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380737#M923894</guid>
      <dc:creator>tayon.kendrick</dc:creator>
      <dc:date>2018-05-09T14:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380739#M923895</link>
      <description>&lt;P&gt;With the exception of the configuration of the management port, all config is applied&amp;nbsp;one-way from the FMC to the managed device. At least&amp;nbsp;for the next time, there is no configuration on the device that is pushed to the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to have best of both worlds (locally and centrally managed), you could achieve that with the FTD-API. Local changes could be done by FDM,&amp;nbsp;and also a central management-server (which is &lt;STRONG&gt;not&lt;/STRONG&gt; FMC) can fetch all config from FTD, alter it and push it back to the device.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 14:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380739#M923895</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-05-09T14:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380814#M923896</link>
      <description>&lt;P&gt;Thanks for your answer Karsten.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not familiar with that scenario. With whom could I speak to in order to obtain more information on this being a possibility.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380814#M923896</guid>
      <dc:creator>tayon.kendrick</dc:creator>
      <dc:date>2018-05-09T15:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: CLI changes occurring directly on managed devices without using the FMC?</title>
      <link>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380823#M923897</link>
      <description>&lt;P&gt;For now, it's likely that you have to make yourself comfortable with both the API and&amp;nbsp;write your own scripts to implement the API.&amp;nbsp;The API on FTD is quite new, but I assume that&amp;nbsp;some vendors of management-solutions will have software for this in quite some time.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 16:03:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-changes-occurring-directly-on-managed-devices-without-using/m-p/3380823#M923897</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-05-09T16:03:06Z</dc:date>
    </item>
  </channel>
</rss>

