11-08-2022 08:07 AM - edited 11-08-2022 08:10 AM
Security analysts told us that a network security scan shows that the HTTPS service may be running on the management interfaces our FTD nodes. Trying to access it via browser, it returned the following message:
The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.
...when trying to access a secure webpage using https://FQDN of the FTD 2130 (Firepower Threat Defense) nodes. We have a 2-node cluster they scanned and it seems https service is enabled somewhere but I'm not sure how to disable it if it is enabled. The browser tab message shows "503 service unavailable", so I'm not even sure it's actually enabled. Can anyone confirm? Can this be disabled using the FMC or must this be done in the FTD CLI? If so, how? Thanks in advance.
11-17-2022 02:42 AM - edited 11-17-2022 02:44 AM
Hi Andrewjinks,
When you are using FMC to Manage FTD. Then you cannot access FTD via GUI using Management IP. FTD device Management settings you can configure in FMC by navigating to
FMC --> Device --> Platform settings
Now you can disable HTTP Access for FTD by navigating through
FMC --> Device --> Platform settings --> HTTP Access and uncheck Enable HTTP Server check box
Kindly apply the above steps and let us know if you have more queries
-----------------------------------------
If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.
You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.
-----------------------------------------
Regards
Arunkumar
11-17-2022 04:28 AM
Unfortunately the service cannot be disabled, even when following the steps suggest by @Arunkumar Sathasivam .
There is an unresolved ENH bug (enhancement request) pending against this behavior.
11-07-2023 09:23 AM
@Arunkumar Sathasivamwas this ever resolved? It seems to have been a bug as the other user pointed out. The HTTP option is disabled (unchecked) for the FTD nodes in the Device Management settings as described, but the 503 message still appears when you try to access the management interface of the nodes. Our security scans are picking it up and we'll either need to disable it completely somehow, or apply a SSL/TLS certificate. I don't see how to add a certificate for that interface, either, and I imagine that is because when using the FMC to manage the nodes, HTTP/S is supposed to be disabled on the nodes since the FMC is using HTTPS and there's a certificate for that.
Is there a way to apply a cert or disable HTTP/S completely via CLI or through FMC?
11-07-2023 09:38 PM
I advise my customers to cite the vendor ENH defect as a response to any security scans. If you try to manually disable it under the covers, you will be potentially be making your system unusable.
I have had some success at limiting the ciphers presented. Reference these threads:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide