03-19-2021 11:07 AM
Hi,
I'm trying to create a lab with 2x 5506-X FWs and add them to the FMC. However initial configuration after FW reset doesn't allow me to choose 'Managed locally?' and set in to 'NO'. Therefore i can't use command 'Configure manager add xxx' - this command is not listed there.
What I'm doing wrongly? Please advise how to add FW to FMC?
Thanks in advance.
Solved! Go to Solution.
03-28-2021 08:15 AM
Since gi1/2 is on one subnet gi1/3 is on a different one the traffic from one to the other needs to go through the firewall. for that you need the command "same-security-traffic permit inter-interface".
03-28-2021 10:14 AM
03-29-2021 01:34 PM
Guys,
Please advise, as regardless what network I'm configuring on any interface (i.e. G1/2), the common error is that network overlaps with interface M1/1. Two interfaces cannot be in the same subnet.
Shall I bridge them somehow?
03-30-2021 06:14 AM
Don't assign any address to M1/1. Assign the sfr module an address in 192.168.1.0 network.
You wouldn't assign the default route on the outside interface using an address from the subnet associated with Gi1/3 which is an internal network.
04-03-2021 12:21 AM
Thanks very much. Now I can ping FirePower IP address. I tried to add it to the FMC (6.2.3), but it says that SW ver. I have on FW is lower than 6.1.0 and this is not supported. So I must upgrade it I think to 6.2.3 or close to it.
04-03-2021 12:27 AM - edited 04-03-2021 12:28 AM
Yes - FMC 6.2.3 can manage devices from 6.1.0 through 6.2.3.
Reference this guide:
If it's a new Firepower service module, it is by far easier to simply reimage it to the newer version rather than upgrade.
04-03-2021 12:48 AM
That will be a challenge as I have never done it before... Do you know maybe any link with some more details how to do it? I'm searching Internet now. My current version is 5.4.1 - pretty old...
04-03-2021 01:20 AM
Follow this procedure:
Use the 6.2.3 img and pkg files found here:
https://software.cisco.com/download/home/286283326/type/286277393/release/6.2.3
Then patch the FMC and Firepower service module to the latest 6.2.3 patch (6.2.3.16). You can go to a newer version on your FMC but the ASA 5506 is limited to 6.2.3.x.
04-03-2021 01:33 AM
Perfect thanks Marvin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide