<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure Source Interface for AAA on FTD/FMC? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404610#M953474</link>
    <description>&lt;P&gt;Yes you're right the data routing will be checked if not able to reach it through management. Usually, at least i mean personally, i always do this using management RIB.&lt;/P&gt;
&lt;P&gt;Anyways, you can't modify the source interface. But i would recommend using the management interface to work with aaa.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jun 2018 23:22:01 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2018-06-24T23:22:01Z</dc:date>
    <item>
      <title>Configure Source Interface for AAA on FTD/FMC?</title>
      <link>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404278#M953471</link>
      <description>&lt;P&gt;Just wonder if this is another firmware limitation...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to specify the management interface of FTD as the source interface to reach AAA server. I think by default FTD is using the routing table to decide which interface to try to reach the AAA server. This is configurable on ASA but does not seem FTD supports it as of 6.2.3.2...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if FlexConfig can be used to accomplish this for FTD OR It is related to FXOS?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404278#M953471</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2020-02-21T15:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Source Interface for AAA on FTD/FMC?</title>
      <link>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404424#M953472</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default it should use management interface and you can't change it even using flexconfig.&lt;/P&gt;
&lt;P&gt;You can check in this link about all blacklisted commands over flexconfig and aaa is one of them:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/flexconfig_policies.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/flexconfig_policies.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 03:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404424#M953472</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-24T03:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Source Interface for AAA on FTD/FMC?</title>
      <link>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404508#M953473</link>
      <description>&lt;P class="p"&gt;Found this in the configuration guide:&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;For VPN authentication, the servers must be reachable over one of the regular interfaces: the Diagnostic interface or a data interface.&lt;/P&gt;
&lt;P class="p"&gt;For regular interfaces, two routing tables are used. A management-only routing table for the Diagnostic interface as well as any other interfaces configured for management-only, and a data routing table used for data interfaces. When a route-lookup is done, the management-only routing table is checked first, and then the data routing table. The first match is chosen to reach the AAA server.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 16:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404508#M953473</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2018-06-24T16:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Source Interface for AAA on FTD/FMC?</title>
      <link>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404610#M953474</link>
      <description>&lt;P&gt;Yes you're right the data routing will be checked if not able to reach it through management. Usually, at least i mean personally, i always do this using management RIB.&lt;/P&gt;
&lt;P&gt;Anyways, you can't modify the source interface. But i would recommend using the management interface to work with aaa.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 23:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-source-interface-for-aaa-on-ftd-fmc/m-p/3404610#M953474</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-06-24T23:22:01Z</dc:date>
    </item>
  </channel>
</rss>

