06-07-2023 05:59 AM
I have an on-prem FMC that manages a handful of FTD devices. All of these devices use private IPs and are not NATed or exposed to the Internet in any way. The problem is some of the FTD devices are reachable only via IPSec VPN which sometimes gives me a bit of grief and I lose connectivity to the FTDs. Is it possible to register the FTDs on CDO without removing them from the FMC and sort of co-manage them with both platforms?
TIA,
Diego
Solved! Go to Solution.
06-07-2023 12:10 PM
So would I want to assign a public routed IP to the physical management interface or simply enable management access for a data interface that already has a public IP ie, "outside Interface"? I'm a bit reluctant to have the management interface exposed...
06-07-2023 12:17 PM - edited 06-07-2023 12:19 PM
@tato386 well if you enable management on the data interface which has been configured with a public IP address you have exposed the management functionality on the internet. You are essentially combining the data/management functionality on one interface, rather than having a dedicated mgmt and data interfaces. Communication between the FTD and FMC is secured.
It's up to you wish option to take, if you have a spare public IP address for each site, then go with that.
06-07-2023 12:56 PM
@Rob Ingram When I edit a data interface I see I have options for allowed management networks but the management interface does not show in FMC. The FMC does show the diagnostic interface and that guy has allowed management nets option just like the data interface. Do the management networks configured on the diag interface apply to the management interface? How do I secure the management interface?
06-07-2023 01:06 PM
@tato386 the management and diagnostics interfaces are separate interfaces. The management interface IP address and routing is configured via the CLI using the configure network command.
For the Management interface, to configure an SSH access list, see the configure ssh-access-list command.
06-07-2023 01:42 PM
excellent. thank you very much sir, I appreciate it!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: