<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTDv/NGFWv in AWS BVI issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3824015#M925754</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've deployed an FTDv/NGFWv in an AWS VPC, changed the firewall mode to transparent, and registered it to an FMCv.&amp;nbsp; I've attached two additional network interfaces to the FTDv in the same subnet "192.168.1.0/24".&amp;nbsp; Now when I try to create a BVI interface and enter 192.168.1.0/24 into the IPv4 configuration I get an error "&lt;SPAN&gt;Invalid value of IPv4 address or subnet or network overlap".&amp;nbsp; No matter what network range I try to put in 192.168.1.0/32 or 192.168.0.0/24 (the management interface network) I get the same error and cannot create the BVI interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: Per instructional videos I have disabled AWS's Source and Destination check on the attached network interfaces and the EC2 instnaces of FTDv and FMCv.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here's the current IPv4 network config and interface statistics.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : mgt-rts-ftdv1&lt;BR /&gt;DNS Servers : 8.8.8.8&lt;BR /&gt;8.8.4.4&lt;BR /&gt;Management port : 8305&lt;BR /&gt;IPv4 Default route&lt;BR /&gt;Gateway : 192.168.0.1&lt;/P&gt;
&lt;P&gt;======================[ eth0 ]======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 0E:D4:6A:88:83:DE&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.0.12&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Broadcast : 192.168.0.255&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;
&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show interface&lt;BR /&gt;Interface GigabitEthernet0/0 "", is administratively down, line protocol is up&lt;BR /&gt;Hardware is ixgbevf, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;Available but not configured via nameif&lt;BR /&gt;MAC address 0ee7.7b8d.7c4a, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Interface GigabitEthernet0/1 "", is administratively down, line protocol is up&lt;BR /&gt;Hardware is ixgbevf, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;Available but not configured via nameif&lt;BR /&gt;MAC address 0e02.3d4e.d6fa, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Interface Management0/0 "diagnostic", is up, line protocol is up&lt;BR /&gt;Hardware is en_vtun rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;MAC address 0eb1.f241.99e4, MTU 1500&lt;BR /&gt;IP address unassigned&lt;BR /&gt;211 packets input, 12216 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Traffic Statistics for "diagnostic":&lt;BR /&gt;211 packets input, 9262 bytes&lt;BR /&gt;0 packets output, 0 bytes&lt;BR /&gt;16 packets dropped&lt;BR /&gt;1 minute input rate 0 pkts/sec, 2 bytes/sec&lt;BR /&gt;1 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt;1 minute drop rate, 0 pkts/sec&lt;BR /&gt;5 minute input rate 0 pkts/sec, 2 bytes/sec&lt;BR /&gt;5 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt;5 minute drop rate, 0 pkts/sec&lt;BR /&gt;Management-only interface. Blocked 0 through-the-device packets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Scott Owen&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:58:22 GMT</pubDate>
    <dc:creator>scott.owen@zii.aero</dc:creator>
    <dc:date>2020-02-21T16:58:22Z</dc:date>
    <item>
      <title>FTDv/NGFWv in AWS BVI issue</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3824015#M925754</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've deployed an FTDv/NGFWv in an AWS VPC, changed the firewall mode to transparent, and registered it to an FMCv.&amp;nbsp; I've attached two additional network interfaces to the FTDv in the same subnet "192.168.1.0/24".&amp;nbsp; Now when I try to create a BVI interface and enter 192.168.1.0/24 into the IPv4 configuration I get an error "&lt;SPAN&gt;Invalid value of IPv4 address or subnet or network overlap".&amp;nbsp; No matter what network range I try to put in 192.168.1.0/32 or 192.168.0.0/24 (the management interface network) I get the same error and cannot create the BVI interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: Per instructional videos I have disabled AWS's Source and Destination check on the attached network interfaces and the EC2 instnaces of FTDv and FMCv.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here's the current IPv4 network config and interface statistics.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : mgt-rts-ftdv1&lt;BR /&gt;DNS Servers : 8.8.8.8&lt;BR /&gt;8.8.4.4&lt;BR /&gt;Management port : 8305&lt;BR /&gt;IPv4 Default route&lt;BR /&gt;Gateway : 192.168.0.1&lt;/P&gt;
&lt;P&gt;======================[ eth0 ]======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 0E:D4:6A:88:83:DE&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.0.12&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Broadcast : 192.168.0.255&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;
&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show interface&lt;BR /&gt;Interface GigabitEthernet0/0 "", is administratively down, line protocol is up&lt;BR /&gt;Hardware is ixgbevf, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;Available but not configured via nameif&lt;BR /&gt;MAC address 0ee7.7b8d.7c4a, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Interface GigabitEthernet0/1 "", is administratively down, line protocol is up&lt;BR /&gt;Hardware is ixgbevf, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;Available but not configured via nameif&lt;BR /&gt;MAC address 0e02.3d4e.d6fa, MTU not set&lt;BR /&gt;IP address unassigned&lt;BR /&gt;0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Interface Management0/0 "diagnostic", is up, line protocol is up&lt;BR /&gt;Hardware is en_vtun rev00, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;BR /&gt;Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt;MAC address 0eb1.f241.99e4, MTU 1500&lt;BR /&gt;IP address unassigned&lt;BR /&gt;211 packets input, 12216 bytes, 0 no buffer&lt;BR /&gt;Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;0 pause input, 0 resume input&lt;BR /&gt;0 L2 decode drops&lt;BR /&gt;0 packets output, 0 bytes, 0 underruns&lt;BR /&gt;0 pause output, 0 resume output&lt;BR /&gt;0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt;0 late collisions, 0 deferred&lt;BR /&gt;0 input reset drops, 0 output reset drops&lt;BR /&gt;input queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;output queue (blocks free curr/low): hardware (0/0)&lt;BR /&gt;Traffic Statistics for "diagnostic":&lt;BR /&gt;211 packets input, 9262 bytes&lt;BR /&gt;0 packets output, 0 bytes&lt;BR /&gt;16 packets dropped&lt;BR /&gt;1 minute input rate 0 pkts/sec, 2 bytes/sec&lt;BR /&gt;1 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt;1 minute drop rate, 0 pkts/sec&lt;BR /&gt;5 minute input rate 0 pkts/sec, 2 bytes/sec&lt;BR /&gt;5 minute output rate 0 pkts/sec, 0 bytes/sec&lt;BR /&gt;5 minute drop rate, 0 pkts/sec&lt;BR /&gt;Management-only interface. Blocked 0 through-the-device packets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Scott Owen&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3824015#M925754</guid>
      <dc:creator>scott.owen@zii.aero</dc:creator>
      <dc:date>2020-02-21T16:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv/NGFWv in AWS BVI issue</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3824631#M925755</link>
      <description>&lt;P&gt;I found out from our vendor that FTDv/NGFWv in transparent mode is not supported in AWS.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3824631#M925755</guid>
      <dc:creator>scott.owen@zii.aero</dc:creator>
      <dc:date>2019-03-22T21:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTDv/NGFWv in AWS BVI issue</title>
      <link>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3825064#M925756</link>
      <description>&lt;P&gt;Thank you Scot!&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 12:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftdv-ngfwv-in-aws-bvi-issue/m-p/3825064#M925756</guid>
      <dc:creator>WilliamJacobson</dc:creator>
      <dc:date>2019-03-24T12:10:10Z</dc:date>
    </item>
  </channel>
</rss>

