02-27-2018 07:16 AM - edited 02-21-2020 07:27 AM
Hello,
I have a very weird problem with firepower device. Just got it out of the box, went through the management interface configuration, the web got stuck on loading 10 minutes so I refreshed. :)
After that I will not let me go through the https://192.168.45.45 or the inside interface gi1/2 1.1
I went through a console cable and I saw the it got the below configuration.
interface GigabitEthernet1/2
nameif inside
cts manual
propagate sgt preserve-untag
policy static sgt disabled trusted
security-level 0
ip address 192.168.1.1 255.255.255.0
interface Management1/1
management-only
nameif diagnostic
cts manual
propagate sgt preserve-untag
policy static sgt disabled trusted
security-level 0
no ip address
Now correct me if I am wrong but since it has Security Level 0, it will never let me in through the Web.
I tried looking for commands to change the interface through CLI but I couldn't find any!!!
Model : Cisco ASA5516-X Threat Defense (75) Version 6.2.0 (Build 363)
Please Help! Whats wrong with it and why did it set the intrerfaces to Sec Level 0???
Solved! Go to Solution.
02-28-2018 01:36 AM
It looks like somehow your unit got an improper or partial configuration on it.
To get back to factory default, try the following from your console connection:
> configure manager delete > configure firewall transparent > configure firewall routed
02-28-2018 06:59 AM
If your FMC is remotely located on the outside network then it is difficult to setup management with a gateway on the inside data interface.
For instance, how would your outside interface know its address?
You have to either put management interface on the outside network or else pre-deploy the appliance at there site where your FMC is and then send it to the remote location with all the addressing, routing and any NAT etc. already having been pushed to it.
03-05-2018 03:44 AM
I'm not sure about your specific detailed design. That's probably a bit more than is best handled in a simple support forum thread.
Generally speaking FTD does support portchannel interfaces.
Email Security Appliance (ESA) licenses are completely separate from anything FTD- and FMC-related. There's generally no direct interaction between ESA and FTD.
02-27-2018 11:18 AM
The ASA looks to be running the Firepower Threat Defense OS.
Model : Cisco ASA5516-X Threat Defense (75) Version 6.2.0 (Build 363)
FTD no longer uses security levels but zones to create access policies between. Also, there is no CLI configuration on the FTD, this has to be configured using the on-box Firepower device manager (FDM) or centralized Firepower management center (FMC).
This is a quick start guide to set up FTD using the FDM.
https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5506X/ftd-fmc-5506x-qsg.html
If you want to get to the ASA image, use the guide below:
https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/reimage/asa-ftd-reimage.html
02-28-2018 12:10 AM
02-28-2018 01:36 AM
It looks like somehow your unit got an improper or partial configuration on it.
To get back to factory default, try the following from your console connection:
> configure manager delete > configure firewall transparent > configure firewall routed
02-28-2018 06:52 AM
02-28-2018 06:59 AM
If your FMC is remotely located on the outside network then it is difficult to setup management with a gateway on the inside data interface.
For instance, how would your outside interface know its address?
You have to either put management interface on the outside network or else pre-deploy the appliance at there site where your FMC is and then send it to the remote location with all the addressing, routing and any NAT etc. already having been pushed to it.
03-02-2018 07:00 AM
03-05-2018 03:44 AM
I'm not sure about your specific detailed design. That's probably a bit more than is best handled in a simple support forum thread.
Generally speaking FTD does support portchannel interfaces.
Email Security Appliance (ESA) licenses are completely separate from anything FTD- and FMC-related. There's generally no direct interaction between ESA and FTD.
03-05-2018 05:23 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide