cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
941
Views
0
Helpful
2
Replies

cdFMC, which FTD interface for management?

Jack G
Level 4
Level 4

I'm new to using cdFMC and planning to add two FTDs configured for high availability. What are the recommended interfaces for management? Should I use a data interface for management purposes on both firewalls (two public IP addresses)? Additionally, is it possible to switch to the dedicated management interface while still maintaining connectivity between the FTDs and cdFMC? Ideally, I'd like to retain SSH access to the firewalls from the LAN and not have SSH open on the WAN.

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

If you have out-of-band management to connect to the Internet, then I use the Management interface to connect to CFMCA 

good presentation helps you :

https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2023/pdf/BRKSEC-2318.pdf

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

The devices dedicated management interfaces would still need to be configured and you can access the devices from your local LAN just as normal. When the FTDs try to register to the cdFMC they use their outside interface because that traffic will flow securely over the internet. So you don't really have to open up anything from the WAN in terms of management of the devices and for any change that will be deployed from the cdFMC it will be delivered to the devices over the secure management channel between the cdFMC and the FTDs. So, also for that you don't have to open up anything externally.

Review Cisco Networking for a $25 gift card