02-11-2023 08:06 AM
Hey,
Is it possible to change the manager address on a firepower firewall running 6.4.0 ?
I am aware on 6.7 onward you have the ability to issue the command 'configure manager edit [UUID] [newhostname]'
Is there a way to achieve this via another method on previous versions ?
I'm in a situation where i have migrated all devices running 7.x okay using the edit command above, there are some devices running older code 6.4, which I cannot currently upgrade. So I am a little stuck.
many thanks
Solved! Go to Solution.
02-11-2023 10:11 AM
de-register and register again.
02-11-2023 10:11 AM
de-register and register again.
02-11-2023 12:41 PM
Yep, I feared as much. I didn’t mention I have devices in a failover configuration. You have to disable HA to reregister, I have completed this for some none critical devices, but it’s not acceptable to disable HA and put environment at risk at for some some locations at the moment. I will have to schedule a window for this. I was hoping for a another method which wouldn’t require this.
02-12-2023 01:57 AM
if the IP changes, there is no other method as I know, if you are more concerned, make sure do the backups all time FMC to out of the box. and make a note any config as granular as you can, so restoring is easy.
Note: this is my suggestion based on the information we have, you have not mentioned models and HA before you need to provide some more information could have better suggestions all-time in the first instance.
02-12-2023 02:06 AM
FTD running 6.4 if you disable the HA (break the HA pair) the primary active node will stay active and service in production network. here is the link https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html#anc11
02-12-2023 05:15 AM
Are you switching to a new FMC? I moved a bunch of FTDs from one FMC to another last year with zero downtime for those that were in HA setup. Had similar setup as you where the FTDs were in HA but the version was 6.6.5.
If you explain a bit more about what you are trying to achieve then we might be able to provide you with a better answer.
09-26-2023 04:37 AM - edited 09-26-2023 04:38 AM
I basically need to move FTD HA pairs that were initially setup in a staging environment before shipping, to a production FMC once it arrived at the branch office without needing to de-register + re-register again (i.e. causing downtime)
sounds like you were on to the same thing as I am - would you mind elaborating how you achieved your zero downtime switch?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide