07-27-2020 10:31 AM
Hi,
We have a project where we need to configure many FTDs who's configurations will be almost identical other than MGMT IP, interface IPs and hostnames. The LAN subnets to be used in NAT and ACP policies will differ slightly too.
The FTDs will be FMC managed.
I was hoping I would be able to create a template/seed FTD configuration, then clone this configuration and apply it to a new FTD and make the minor changes to hostname, IPs and objects.
I don't think import/export will include interface IPs, VRFs, and routing? Or am I wrong?
We can't backup the seed config and restore to the 'clone' as the backup includes unique UUID information.
Anybody got any bright ideas?
Thank in advance,
Matt.
07-27-2020 11:22 PM
It sounds like a great use case for an API-driven orchestration project.
Or you could reconsider the use of FMC for management and use CDO for management instead. It excels at this sort of thing.
07-27-2020 11:35 PM
Hi Marvin,
Yes, I was thinking this morning that a Python script and some API magic is probably the way to go here. Take the /21 site subnet as input and output the entire config to the FMC via API.
Challenge accepted! 😁
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide