04-29-2024 12:40 PM
Hi
I need to migrate multiple FTDs management to a newer FMC from current FMC. Current FMC IP is Over VPN to manage the FTD Devices at remote end. In the New plan we will use WAN IP as new Mgmt IP.
Please provide some reference link so I can review.
04-29-2024 02:32 PM
Hello! Let me know if this information would suffice- it sounds like you want to change the management interface to a data interface (WAN): https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/device_management_basics.html#Cisco_Task.dita_0cbd837e-6a80-4e05-8734-7a73bcb2c850 and https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/device_management_basics.html#Cisco_Concept.dita_a3adf1ee-a270-4ff4-8b7b-3f9a3f4f1636
04-29-2024 02:47 PM
Hi Blake
Thanks for your reply. Just to add I want to move the FTD Management from One FMC to another and while moving want to Change management of FTD using Data/WAN Interface.
Since I am looking for best practice suggestion , should I change the management of FTD through Data Interface before the move or after the move to new FMC.
Will be appreciated if you can provide any best practice suggestion/Blog/Forum Reference to move an FTD to another FMC.
04-30-2024 05:29 AM - edited 04-30-2024 05:30 AM
Please take a look at "Change the Manager Access Interface from Management to Data" section in this doc:
Secure Firewall Management Center and Threat Defense Management Network Administration - Cisco
However, I think a bit safer approach to achieve this would be to route the management interface traffic via the FTD inside to outside interfaces, essentially using the FTD data interfaces as the gateway for management. In that case you would need to create a static NAT entry to translate/untranslate the traffic going/coming from the management interface to the FMC. You might need to use NAT ID to register the FTD in this case if the FTD traffic will be translated to a public IP used by other translations.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide