cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
406
Views
2
Helpful
3
Replies

2 FTD Interfaces in the same FMC security zone

Rene Mueller
Level 5
Level 5

I have a FTD HA-Pair configured in FMC and it's inernal and external Interface is assigned to a Internal-Security Zone and an External-Security zone. So far so good. Now I added another FTD HA-pair (branch office) to the FMC and asking myself if it is possible to add its Interfaces to the same Security Zones, so that I don't need to add "duplicate" zones. Question is, can I add Interfaces from different HA-pairs to the same Security Zone or is it better to have every FTD-pair use it's own logic and Security Zones.

2 Accepted Solutions

Accepted Solutions

@Rene Mueller yes you can configure the interfaces of another FTD with the same security zone.

View solution in original post

Yes, I have 6 FTDs where I have standardized the interface names and zones so that all my remote office firewall configurations can be streamlined.  So, for example, all my LAN interfaces are a member of INT-ZONE-A and all my Outside interfaces are a member of OUT-ZONE-A.  I have also done the same with VTIs.  I like doing things this way as it makes management  and setup of interface rules much easier and efficient.

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

3 Replies 3

@Rene Mueller yes you can configure the interfaces of another FTD with the same security zone.

Thanks

MHM

Yes, I have 6 FTDs where I have standardized the interface names and zones so that all my remote office firewall configurations can be streamlined.  So, for example, all my LAN interfaces are a member of INT-ZONE-A and all my Outside interfaces are a member of OUT-ZONE-A.  I have also done the same with VTIs.  I like doing things this way as it makes management  and setup of interface rules much easier and efficient.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card