cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1937
Views
6
Helpful
25
Replies

New Cisco Firepower FPR 1120 Configuration

ssan239
Level 1
Level 1

Hi Team,

We have got new Cisco Firepower FPR 1120 which is the replacement FTD for our ASA 5545. We need to configure the FTD as same as ASA. ASA do not have any Mgmt interface configured. So we need to manage the LAN interface of FTD as the Mgmt interface. Also we need to manage the FTD locally not via FMC. 

What will be our first step. How can we use the Firepower Migration tool for the FTD which is managed locally? 

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp1100/firepower-1100-gsg/ftd-fmc.html

I was going through the link above but that is again for the device managed via FMC. 

Is there any link which i go through. Also if i manage the device locally it is managing with the FDM itself right? Also if i am managing locally can i use CLI for any configuration of the device?

Please add some inputs on this. Need to get it done by Thursday please suggest.

Regards,

Sanjay S

25 Replies 25

@ssan239 unfortunately its not free, you need a CDO license for that appliance.....however there is a 30 day trial license you could try and use that.

https://www.cisco.com/c/en/us/products/security/defense-orchestrator/free-trial.html

 

Thanks again Rob.

In that case if i go with managing the FTD via FMC, then if i need to use the data interface as the management interface is it possible? Is there an option?

@ssan239 yes you can manage the FTD from the FMC over a data interface, since version 6.7 - the management interface is optional.

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html

 

 

 

Thank you @Rob Ingram and @MHM Cisco World  for your continuous help on this.

I prefer managing it locally instead of FMC. Because of below reasons.

> There are ASAs Firepowers are managed using the same FMC.

> Is it possible to manage the FTDs also from the same FMC?

> Also is there any other way to migrate the ASA to FDM instead of CDO? CDO license for the Appliance in the sense the FDM device should have CDO license?

Sorry too many questions but need to understand better to give a solution on this.

Thanks again.

@ssan239 yes of course you can manage ,multiple FTDs from the FMC.

To repeat what was previously stated, if you are using FDM to manage the device locally, then you cannot use the Firepower Migration Tool. You can use the CDO tool to migrate the ASA configuration to FDM. https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-CDO/ASA2FTD_Using_CDO/m_how_to_implement_migration.html or manually configure the FDM.

 

Thanks Rob, so if we are going to manage the device locally then there is only one option to migrate that is using CDO tool.

We can manage multiple FTDs. understood but in our case, we are managing the ASA firepower modules using the FMC now. If we add this new FPR1120 then it will be the first FTD.

Thanks again Rob for your patience and support.

as I know FMC need to connect to mgmt interface, what I think you have FMC in different site and you need to access FTD via FMC and hence the mgmt interface must be reachable  by FMC ?
if that right then connect mgmt to INside of FTD and FTD will Forword mgmt traffic to FMC 

Thank you MHM,

if that right then connect mgmt to INside of FTD and FTD will Forword mgmt traffic to FMC - Does it mean configure the Inside interafce as Mgmt interface? and use the Inside int for both Data and Mgmt purpose?

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215540-configure-verify-and-troubleshoot-firep.html

NO mgmt connect to INside and FPR will forward traffic (note this not cisco recommend) but it one of three solution to connect FPR to FMC

Thank you MHM for the clarification.

Review Cisco Networking for a $25 gift card