cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1394
Views
5
Helpful
2
Replies

FTD 1120 Remote Deployment to Branch Office Managed by FMCv

Alan Inman
Level 1
Level 1
  • The FTD 1120 is currently paired to the FMCv using the diagnostic/management port, both FTD and FMCv are in HQ at the moment.
  • However, the branch office that the FTD 1120 will be deployed to only has Outside Internet. No tie-back to HQ
  • If I check "Enable management on this interface for the Firepower Management Center" will it convert from the management port to the Outside (see screenshot) Interface allowing the FTD to be managed by the FMCv via the Internet?
  • The FTD and FMCv are both running 7.0.1
  • Once deployed to the branch office. I will build an S2S VPN tunnel back to HQ
  • The FTD will replace a CradlePoint we have at the branch office. The CradlePoint is managed through the cloud and has an S2S VPN tunnel coming back to HQ

The "Enable management on this..." is fairly new and documentation is light. I did look through the admin guide and it mentions it but is vague about switching from management to the Outside interface. 

 

Thank you, 

 

Alan

1 Accepted Solution

Accepted Solutions

@Alan Inman there is a bit more involved, refer to this link it has all the steps involved to manage over the data interface. You will need to ensure you have a NAT setup on the firewall in front of the FMC, to translate from the public IP address to the real IP address of the FMC on tcp/8305.

View solution in original post

2 Replies 2

Alan Inman
Level 1
Level 1

Better shot of the screenshot I mentioned in the original post

 

2022-01-31-11-21-21.png

@Alan Inman there is a bit more involved, refer to this link it has all the steps involved to manage over the data interface. You will need to ensure you have a NAT setup on the firewall in front of the FMC, to translate from the public IP address to the real IP address of the FMC on tcp/8305.

Review Cisco Networking for a $25 gift card