08-20-2023 02:11 PM
If the ip address of an FMCv manager changes in FTD, can I re-enroll the same manager without losing configuration artifacts by adding another manager with the same parms other than the ip address?
To say it differently, is there ANY PROCEDURE that allows me to change Managers in FTD without losing key configuration artifacts?
My situation is I have an external, off prem FMCv temporarily managing FTD1010 on prem and my manager ip address changed due to an ISP not honoring static ip. The FRP1010 is in production and essential orphaned until I can re-establish a manager.
Solved! Go to Solution.
08-21-2023 04:14 AM
Hi @lcaruso,
This looks to me like change of FMC. I've done one recently, and small difference is that you don't actually change FMC, so no policy export/import or FMC backup/restore is required in your case. However, you'll still need to re-register FTD to "new" FMC (although it is not new, it actually is, as FTD sees it from different IP).
In that case, you'll need to reconfigure your device configuration (I haven't tried backup/restore of FTD device) as that part was not retained for me (e.g. interfaces, routing, etc.). After that, you just need to attach proper polices (all of them - Access control, SSL, Platform, etc.). We had a service interruption for that time, so I would advise to execute change in MW.
Kind regards,
Milos
08-21-2023 04:18 AM
You can do the backup / restore in addition to the other policies @Milos_Jovanovic mentioned. That feature is available in FMC 7.1+.
08-21-2023 04:14 AM
Hi @lcaruso,
This looks to me like change of FMC. I've done one recently, and small difference is that you don't actually change FMC, so no policy export/import or FMC backup/restore is required in your case. However, you'll still need to re-register FTD to "new" FMC (although it is not new, it actually is, as FTD sees it from different IP).
In that case, you'll need to reconfigure your device configuration (I haven't tried backup/restore of FTD device) as that part was not retained for me (e.g. interfaces, routing, etc.). After that, you just need to attach proper polices (all of them - Access control, SSL, Platform, etc.). We had a service interruption for that time, so I would advise to execute change in MW.
Kind regards,
Milos
08-21-2023 04:18 AM
You can do the backup / restore in addition to the other policies @Milos_Jovanovic mentioned. That feature is available in FMC 7.1+.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide