cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
483
Views
2
Helpful
5
Replies

Changing FTD Platform Settings

jberrios
Level 1
Level 1

I currently have 2 sites, and each site has (2) FTDs in active/passive failover. When looking at the Platform Settings, they both share a single policy. I need to add another policy for each pair to change their syslog server settings to go to different syslog servers. When I create a "Threat Defense Settings" policy and add an HA to it, I am presented with the following message:

Following device have an existing platform setting or a DNS value configured by CLI. Do you want to replace the existing configuration?

How can I determine which setting(s) would be modified? Is there a potential for taking the pair offline?

 

5 Replies 5

@jberrios it is unlikely to impact transit traffic, as the Platform Settings policy applies setting applicable to the FTD itself. If your new Platform settings policy does not include DNS settings and the existing one does, you would probably want to ensure you define DNS servers and another other settings.

Why do you need to create a new policy, can you not amend the exist policy that is applied with the syslog servers?

@Rob Ingram , is it possible to specify multiple syslog servers within the same policy and direct each pair to specific syslog servers?

@jberrios not if they share the same policy.

there is config replication from active to standby and there some little config not replicate 
config different syslog is replication so what you try to do will not work 

MHM

Marvin Rhoads
Hall of Fame
Hall of Fame

In addition to what @Rob Ingram correctly mentioned, you can preview the deployment changes before clicking the final confirmation button.

MarvinRhoads_0-1734357836708.png

 

Review Cisco Networking for a $25 gift card