cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
672
Views
0
Helpful
3
Replies

Firepower Management center register remote ips

seckka21
Level 1
Level 1

Hi 

I have two site linked by vpn ipsec site to site.I have in each site an ASA 5525-X with ips module.I have installed my FMC in the site A in a vlan with ip 172.16.30.12/28.The ASA management interface and ips module have ip too in the same vlan.all VLAN are created on the backbone switch.and i have a default route in my backbone with gateway the ASA inside interface. I have the same configuration in site B.My problem is that  the ips module in site B is in a different network with my FMC in site A.I have done the configuration but ips module can't ping FMC .I need your help to verify if this configuration can work.

2 Accepted Solutions

Accepted Solutions

management-access mgmt_if <- you need this command to all management traffic through vpn.

View solution in original post

I think that since the IPS is consider as management traffic so you need this command to allow it pass through tunnel.

below link how config the management traffic through vpn.

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html

 

 

View solution in original post

3 Replies 3

management-access mgmt_if <- you need this command to all management traffic through vpn.

HI

If I understand correctly, this command must be executed so that the traffic from the management interfaces goes through the tunnel. And for the ips module, there will be no routing problems.

I think that since the IPS is consider as management traffic so you need this command to allow it pass through tunnel.

below link how config the management traffic through vpn.

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/118092-configure-asa-00.html

 

 

Review Cisco Networking for a $25 gift card