cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
111
Views
0
Helpful
3
Replies

ISP Migration - ISP/WAN/Gateway Utilizing Old Disabled Port

IWSup
Level 1
Level 1

We recently migrated to a new ISP and utilized a new port for setup on our Cisco FP 1150. Everything seems to have gone off without a hitch, the site is online and utilizing the new ISP, however, the ISP/WAN/Gateway is still trying to use the old port (which has since been disabled). While functionally, everything is good, visually it shows an issue that I would like to get corrected.

Firewall.png

The old port was 1/2, the new port everything is utilizing now is 1/3. The changes I made for the cutover are as follows. Is there something I missed?

  • Objects > Security Zones > Edit outside_zone > Add Eth1/3 to outside_zone Security Zones
  • Device > Routing > Static Routing > Modify Eth1/3 Networks to any-ipv4 and set Metric to 1
  • Device > Routing > Static Routing > Remove Eth1/2 Networks and set metric to 5
  • Policies > NAT > Modify all NAT policies using Eth1/2 to Eth1/3
  • Device > System Settings > DNS Server > Add Eth1/3 interface (remove old Eth1/2 interface)
  • Device > Interfaces > Disable Ethernet1/2

Thanks!

3 Replies 3

IWSup
Level 1
Level 1

Could this be due to the Management Gateway Interface Settings? On the old ISP, we had two ports active on the modem, so we had both the Outside Interface, and the MGMT Interface, with different IP addresses plugging directly into the ISPs modem.

Now, however, we have 1 Public IP and 1 active port on the modem. We have swapped the Management access to use the Data Port, but have not modified the Management Interface (Gateway) yet.

Should I change that to use the data interface gateway and set it as our new Public IP address (like so)?

Firewall2.png

You change only ISP so mgmt config not touch?

I see same issue before and the issue was dns server in ftd' after engineer add dns server IP the ISP gateway turn to green

MHM

IWSup
Level 1
Level 1

We changed the ISP, but the Management Interface config was and still is set up with the old ISP and its Public IP address. As of now, we have not migrated over the Management Interface to the new ISP.

We are utilizing the Cisco DNS Servers and have them attached to the new outside (Eth3) interface as mentioned in one of my migration steps.

Device > System Settings > DNS Server > Add Eth1/3 interface (remove old Eth1/2 interface)

Review Cisco Networking for a $25 gift card