Resolved! Recover policies from ftd
Hello, Would anyone know if you can retrieve policies from an ASA/FTD box into FMC? I needed to restore my FMC server and I would like to retrieve the policies that are currently on the ASA. Thanks,Dan.
Hello, Would anyone know if you can retrieve policies from an ASA/FTD box into FMC? I needed to restore my FMC server and I would like to retrieve the policies that are currently on the ASA. Thanks,Dan.
I still don't understand the logic:mandatories rules are checked like and ACL, but default rules are in oposite direction?Are their any best practices in which categories to keep which rules?
Hi, I have a confusion when it comes to configuring Interfaces on the FP4110.as i understood, here two types for Interfaces in FP41101- Data-type: used for the Data plane2- Management-type: use for Management. now if I wanted to run ASA on the applia...
Dear All, I tried to create a config backup on FMC, but it consumes around 160MB.How do people rancid and manage configuration versions on FMC with such monstrous files? I didn't find a way how to backup FTD config.
Hello, I am looking for advice in regards to logging our edge firewall connections. We are running an ASA 5520 and Kiwi Syslog 9.5 on a windows server. I have been running kiwi syslog server 9.5 for a few months and it keeps crashing. I opened a tick...
Hi, How can I block all ports from inside to outside and allow only specific traffic towards outside. What is the best practice to do that? Should I use ACL or global_policy?
Hi all , how can i nat the outside address to make it reach internet .NB: the ouside interface has a private ip address Thanks
I've got an old PIX running 6.3 code. Finally upgrading to an ASA 5515 running 9.2 code. I can't keep up with all the NAT changes that have taken place through the years. I have several of basically no nat statements on the PIX, like below: static (i...
Is there a way to override a manual shun with an object group (or otherwise)?I have found that we can override an "automatic shun" using:threat-detection scanning-threat shun except object-group no-shunBut, we are needing a way to override a priviled...
As mentioned, this is an ASA 5506 running 9.8(1) They both "claim" to be in use if I try to remove either via command line. The object-group is a service, has nothing underneath it (I was able to remove the ports), and does not show up anywhere else...
I have a few ASA5506-Xs, an ASA5508-X, and vFMC. Looking at upgrading from 6.2.0.2 to 6.2.2.0. I browsed the release notes, but I was wondering if anyone has actually done the deed yet?Any "gotchas"?Wanting to get this deployed ASAP, but decades in ...
Recently updated FMC to 6.2.0.1. Estreamer client now only sends 5 or so events and then the estreamer client fails, both on Splunk and host-based client testing. Also, the server does not seem to respond to changes in the event type delivery opti...
Hi Experts,I've been deploying RAVPN multiple times using 2 zone approach (outside and inside) and now I saw this design and I don't know if it will work.Currently, the design has one zone only which is outside zone. Will this work?Thanks
Hello Guys,I was going thrugh documentation for Inline deployment in v6.2.0 and found something about TAP Mode (even though this option is available in previous versions as well). In Inline sets, there is an option called TAP Mode which says that the...
I tried to generate a rather simple report on a DC1500 for the previous calender month.The report should contain a summary of the connection events based on the action, Trust, Allow, Block. The connection event database contains that information, how...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Subject | Author | Posted |
---|---|---|
07-16-2025 04:21 AM | ||
07-06-2025 01:40 PM | ||
07-04-2025 01:59 AM | ||
06-19-2025 07:32 AM | ||
06-17-2025 01:07 PM |
User | Count |
---|---|
10 | |
7 | |
5 | |
2 | |
1 |