01-26-2021 12:09 PM
Hello,
I am doing the system settings on a FTD 2130.
When I did a copy/paste the token to registrate the license, I got this message "cannot connect to smart licensing server".
I followed the quick start guide to do my settings :
e.g. outside (dhcp mode), inside is 192.168.1.1/24, mngt is 192.168.45.45
FW is dhcp server enabled, NAT is configured by default, policy is default also.
But I cannot ping 8.8.8.8 from inside to outside. Do I need to add permit icmp rule?
Do you have any idea?
Thank you.
01-27-2021 12:22 AM
Your management interfaces needs to have Internet connectivity. Does the 192.168.45.0 subnet have a gateway with connectivity to the Internet and a reachable DNS server? Use "ping system" and not simply "ping" to make sure your ping tests use traffic from the management interface.
01-27-2021 02:44 AM
Hello Marvin,
I am using the FTD deployment w/ FDM document.
From the included picture, it shows that I only need to connect a laptop to the mngt interface and then using FDM to configure the settings, license,etc.
In my understanding the outside e1/1 will be connected to internet (correct me if I'm wrong). Actually, this interface is connecting to a box which is dhcp server and gw ip is 192.168.1.1. This box goes out to internet.
So my mngt IP is 192.168.45.45 (default) with data-interface as gw.
DNS servers are default, they are Cisco servers.
I think I should change my inside network to someting else other than 192.168.1.1 which makes conflit to the box's gw.
Could you please explain:
"192.168.45.0 subnet have a gateway with connectivity to the Internet and a reachable DNS server?"
Should I connect the mngt interface to internet instead of using outside interface?
Thank you.
01-27-2021 04:41 AM
Do I understand correctly that your outside data interface is DHCP-addressed and the upstream gateway is 192.168.1.1? Obviously that won't work when your inside data interface is 192.168.1.1.
Normally the management interface is where smart licensing communications take place from. If it is 192.168.45.45 then it needs to be able to reach addresses via some gateway on the same subnet - that's basic routing. It also needs to be able to resolve FQDNs via a DNS server. Those are all things you setup when the appliance is new out of the box.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide