cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1262
Views
0
Helpful
6
Replies

Change Cisco Firepower Firewall (FTD) manager address on version 6.4.0

LewisGoulden
Level 1
Level 1

Hey,

Is it possible to change the manager address on a firepower firewall running 6.4.0 ?

I am aware on 6.7 onward you have the ability to issue the command 'configure manager edit [UUID] [newhostname]'

Is there a way to achieve this via another method on previous versions ?

I'm in a situation where i have migrated all devices running 7.x okay using the edit command above, there are some devices running older code 6.4, which I cannot currently upgrade. So I am a little stuck.

many thanks

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

de-register and register again.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

de-register and register again.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yep, I feared as much. I didn’t mention I have devices in a failover configuration. You have to disable HA to reregister, I have completed this for some none critical devices, but it’s not acceptable to disable HA and put environment at risk at for some some locations at the moment. I will have to schedule a window for this. I was hoping for a another method which wouldn’t require this. 

if the IP changes, there is no other method as I know, if you are more concerned, make sure do the backups all time FMC to out of the box. and make a note any config as granular as you can, so restoring is easy.

Note:  this is my suggestion based on the information we have, you have not mentioned models and HA before you need to provide some more information could have better suggestions all-time in the first instance.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

FTD running 6.4 if you disable the HA (break the HA pair) the primary active node will stay active and service in production network. here is the link https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/212699-configure-ftd-high-availability-on-firep.html#anc11

 

 

 

please do not forget to rate.

Are you switching to a new FMC?  I moved a bunch of FTDs from one FMC to another last year with zero downtime for those that were in HA setup. Had similar setup as you where the FTDs were in HA but the version was 6.6.5.

If you explain a bit more about what you are trying to achieve then we might be able to provide you with a better answer.

--
Please remember to select a correct answer and rate helpful posts

I basically need to move FTD HA pairs that were initially setup in a staging environment before shipping, to a production FMC once it arrived at the branch office without needing to de-register + re-register again (i.e. causing downtime)
sounds like you were on to the same thing as I am - would you mind elaborating how you achieved your zero downtime switch?

Review Cisco Networking for a $25 gift card