cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4763
Views
10
Helpful
6
Replies

Manage remote FTD with FMC

Hi! We just install a FMC server on our corporate office. A new branch was open on a different city and they got a FTD-2110...

How do I add this remote device to my FMC? I've already did

>configure manager add <my.corporate.network.ip> <reg_key>

the FTD says "Pending"

the FMC never registered the FTD

 

I've also noticed that if I do:

>configure manager delete

>configure manager local

All my interfaces are shutdown....

 

6 Replies 6

Muhammad Awais Khan
Cisco Employee
Cisco Employee

HI,

 

Whenever you change the management mode, it is going wipe out the config and thats the reason your interface shut down when you make config manager delete and conf manager local.

 

What are the steps you are following ? Please see the attached example if required.

 

FMC management and FTD Management are reachable to each other ?

balaji.bandi
Hall of Fame
Hall of Fame

here is blog covers registering FTD with FMC

 

http://www.balajibandi.com/2017/04/02/adding-cisco-firepower-threat-defense-vftd-to-firepower-management-center-fmc/

 

make sure FMC and FTD has reachability.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you, but I don't have FMC, just 2 FTDs
I need a guide to setup a site to site VPN between 2 FTDs on separated networks
Or
A guide to register remote FTDs on a local FDM, from where I can follow the guide you sent me.
Thank you again....

Hi,

 

You cannot register remote FTD's to local one FDM. FDM is local device manager and each device will be having unique management interface.

 

If you want centralize management then you can go with either FMC ( virtual/physical appliance) or CDO ( Cloud based orchestration tool). It seems currently you don't have any other management option so you have to configure your devices from their local FDM Page.

 

First thing, setup your Box and make your FDM page up and running. You can get the instruction from below link. Steps are same for firepower 1000 and 2000 series but I am posting links for both. With below guides, you will be able to make your device up and running.

 

Firepower 2100: https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp2100/firepower-2100-gsg/ftd-fdm.html

Firepower 1000: https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp1010/firepower-1010-gsg/ftd-fdm.html

 

Once above is done, you need to configure IPSEC by following simple wizards. Follow below guide for it:

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-s2svpn.html

 

 

Keep us posted if you encounter any issue.

 

once both devices are 

But your original post was different than what you described now.

 

anyway, you would like to Manage Local FTD with FDM, depends on how you have done your initial setup if you choose that this device managed FMC or Locally?

 

FDM has Limited Features unlike Full Blown FMC Management kit like any other vendor.

 

here is onbox management  :

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-2100-series/213519-configure-fdm-firepower-device-manageme.html

 

VPN Site to Site For reference :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_threat_defense_site_to_site_vpns.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

amadoriale
Level 1
Level 1

Hello,

 

we are also going to deploy 3 FTD clusters (v 6.4), respectively 2 1140s, 2 1120s, 2 1010s. We are going to deploy the virtual FMC on the main site with 1140s and the remote sites connected via IPSEC S2S.

 

Could you kindly share information on how to best deploy this solution?

 

Thank you very much.

Review Cisco Networking for a $25 gift card