07-08-2024 07:34 AM
I have a FTD HA-Pair configured in FMC and it's inernal and external Interface is assigned to a Internal-Security Zone and an External-Security zone. So far so good. Now I added another FTD HA-pair (branch office) to the FMC and asking myself if it is possible to add its Interfaces to the same Security Zones, so that I don't need to add "duplicate" zones. Question is, can I add Interfaces from different HA-pairs to the same Security Zone or is it better to have every FTD-pair use it's own logic and Security Zones.
Solved! Go to Solution.
07-08-2024 07:42 AM
@Rene Mueller yes you can configure the interfaces of another FTD with the same security zone.
07-08-2024 09:14 AM
Yes, I have 6 FTDs where I have standardized the interface names and zones so that all my remote office firewall configurations can be streamlined. So, for example, all my LAN interfaces are a member of INT-ZONE-A and all my Outside interfaces are a member of OUT-ZONE-A. I have also done the same with VTIs. I like doing things this way as it makes management and setup of interface rules much easier and efficient.
07-08-2024 07:42 AM
@Rene Mueller yes you can configure the interfaces of another FTD with the same security zone.
07-08-2024 08:19 AM - edited 07-10-2024 02:58 AM
Thanks
MHM
07-08-2024 09:14 AM
Yes, I have 6 FTDs where I have standardized the interface names and zones so that all my remote office firewall configurations can be streamlined. So, for example, all my LAN interfaces are a member of INT-ZONE-A and all my Outside interfaces are a member of OUT-ZONE-A. I have also done the same with VTIs. I like doing things this way as it makes management and setup of interface rules much easier and efficient.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide