cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
457
Views
0
Helpful
4
Replies

How to access cisco firepower chassis

Herman2022
Level 1
Level 1

Hi, can someone please advise how to access firepower 2120? can ping the mgmt ip, but when run https://firepower-mgmt-ip, then failed, can someone pls advise? thanks in advance! 

4 Replies 4

Mark Elsen
Hall of Fame
Hall of Fame

 

  - Review this guide : https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp2100/firepower-2100-gsg.pdf

  M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Network Diver
Level 3
Level 3

You mean the FXOS chassis manager? It may have IP restrictions for HTTP and SSH access. Use serial console. Not sure if this applies only if Firepower 2100 is running ASA or also FTD software image:

firepower2100# scope system
firepower2100 /system # scope services
firepower2100 /system/services # show ip-block

Permitted IP Block:
    IP Address      Prefix Length Protocol
    --------------- ------------- --------
    10.0.0.0                 8 https
    10.0.0.0                 8 snmp
    10.0.0.0                 8 ssh
    192.168.0.0             16 https
    192.168.0.0             16 snmp
    192.168.0.0             16 ssh

https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html#task_ax3_lyf_ndb

If the Firepower 2100 is running FTD and managed by Firewall Management Center (FMC), then there is nothing on HTTPS anymore. Without Management Center the Device Manager web UI should be running there. On FTD CLI when FTD is managed by two FMC in failover mode:

> show managers
Type                      : Manager
Host                      : fmc1.example.com
Display name              : fmc1.example.com
Version                   : 7.4.2.2 (Build 28)
Identifier                : XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXX
Registration              : Completed
Management type           : Configuration and analytics

Type                      : Manager
Host                      : fmc2.example.com
Display name              : fmc2.example.com
Version                   : 7.4.2.2 (Build 28)
Identifier                : XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXX
Registration              : Completed
Management type           : Configuration and analytics

 

Are you running this in platform mode or appliance mode? If platform mode why? 

Marvin Rhoads
Hall of Fame
Hall of Fame

As noted by others, a 2100 series running FTD and managed by FMC will not have a Web UI (i.e., no user interface via https).

Only when locally managed (i.e., "show managers" indicates local) will there be a Firepower Device Manager Web GUI. When running ASA image, the chassis manager UI should be available via https to the management IP.

Review Cisco Networking for a $25 gift card