03-12-2021 10:27 AM
Hi,
I'll shortly have to deploy a physical firepower of the 4100 family "4115".
I know that the first MGMT interface showing up is for chassis FXOS purpuses. In Cisco videos I've seen that the management interface used for FTD "logical instance" is the ethernet1/1 .
1) I am right on saying that management interface for FTD can be any of the interfaces available on the fixed module?
2) On FTD can I use a subinterface as management (and FMC use that same subinterface), or management interface must be physical?
3) Management interface on FTD, can also work as data interface? (for example as mgmt interface i use the once facing as server in a DMZ)
Unfortunately on my virtual lab I couldn't test these things
Thank you in advanced
Solved! Go to Solution.
03-14-2021 03:15 AM
While we note that the documentation for Firepower 6.7 says that you can "manage the FTD using a data interface instead of the Management interface", I know that, at least through the latest FXOS for a 4100 or 9300 series, you cannot deploy an FTD logical device without first designating one of the network interfaces as exclusively management (not data). Note that the guide tells us explicitly:
"You can later enable management from a data interface; but you must assign a Management interface to the logical device even if you don't intend to use it after you enable data management. See the configure network management-data-interface command in the FTD command reference for more information."
03-13-2021 04:13 AM
Yes - you must use a separate dedicated physical interface for management. Firepower Chassis Manager will not allow you do deploy an FTD logical devices without having that configured and available.
03-13-2021 11:37 PM
Thanks Marvin,
so i must first define a management interface, for example eth1/1, then I can create the FTD logical device and apply eth1/1 to it, but can that eth1/1 interface be used for both data and management or does it have to be used exclusively for managemet?
thanks
David
03-14-2021 03:15 AM
While we note that the documentation for Firepower 6.7 says that you can "manage the FTD using a data interface instead of the Management interface", I know that, at least through the latest FXOS for a 4100 or 9300 series, you cannot deploy an FTD logical device without first designating one of the network interfaces as exclusively management (not data). Note that the guide tells us explicitly:
"You can later enable management from a data interface; but you must assign a Management interface to the logical device even if you don't intend to use it after you enable data management. See the configure network management-data-interface command in the FTD command reference for more information."
03-14-2021 12:32 PM
Fantastic thanks Marvin, you couldn't be clearer than this
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide