cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
367
Views
2
Helpful
6
Replies

Can't ping from FTD managemnt to FMC

emurray
Level 1
Level 1

I am traying to add two FED'S to FMC but one of them was giving me an error on FMC thay the connection was timeout.  I connected to the FTD using SSH and I can't do a regular ping to the FMC. It says there is no route to gateway, but they are on the same subnet. The thing is that if I do a ping system, it does ping.

 

I have tried removing the manager, configuring the ip address again with no luck. Any suggestions are welcome 

1 Accepted Solution

Accepted Solutions

Normal ping without the "system" keyword will send the traffic out of the data interfaces, not the management interface. To use the management interface you have to use "ping system ...". Could you please elaborate more about the error you see on the FMC and possibly share some screenshots?

View solution in original post

6 Replies 6

Normal ping without the "system" keyword will send the traffic out of the data interfaces, not the management interface. To use the management interface you have to use "ping system ...". Could you please elaborate more about the error you see on the FMC and possibly share some screenshots?

The error in the FMC says connection timeout when adding the ftd. I mention the regular ping because the second FTD was added without any issues and that one could ping without adding the system to the ping command. Also the second one did not have any IP on the data interfaces, so how it is able to ping?

Did you check on the switch where this FTD management port is connected? maybe the swich port has a wrong VLAN assigned? or maybe the port is not configured in access mode? if you try (still with ping system ...) to ping the management port default gateway do you get any response?

The thing was that I was always able to ping from the FMC to the FTD and from the gateway to the FTD. Very wierd thing

Do you have any SVI of the VLAN where the management ports are connected on the switch? if so, I would try to ping the SVI from the FTD and see if there will be any response.

Review Cisco Networking for a $25 gift card