07-16-2024 06:54 AM - edited 07-16-2024 07:09 AM
Good afternoon,
We are planning to move a FMC pair which are hosted across two datacentres, to two new datacentres. We have to change the IP address of the FMCs which manage a number of FTD pairs. My plan is:
expert
sudo su
/etc/sysconfig/configure-network
configure manager delete
configure manager add <IP add> <Unique Code>
Thoughts?
Thank you for any feedback.
Regards
Jimmy
07-17-2024 01:52 AM
What version are you running on the FMC and FTDs? and are you managing the FTDs over VPN or via data-interface?
In newer versions you can updated the FMC IP on the FTD devices without removing them from management, saving you a lot of time and hassle adding it back and reconfiguring everything.
If memory serves me correct the option to updated management IPs came in 6.7.
Also, changing the IP on the FMC, the FTDs should re-establish connection automatically once the FMC IP is changed given that reachability sftunnel is up when the change happens. I am not entirely sure how this will be if the IP is changed while sftunnel is down.
So here are my suggestion on how to proceed depending on software version running:
07-18-2024 12:12 AM
Thank you for your reply.
I never thought about the sftunnel establishment with the secondary FMC, i.e. this information is passed to the FTDs once they have registered with the primary FTD.
Therefore, changing the FTD2's IP address (and physically moving it to the new DC) but then ensuring it re-establishes the HA with FMC1 again should in theory update all the FTDs manager IP address for the secondary/FTD2. Then if I fail the FMC's over, FTD2 should now be managing all the FTDs via it's new IP address and I can undertake the same process on FTD1. Great news. A lot less work and disruptive than my proposal.
07-17-2024 08:51 PM
the FMC will establish sftunnel as it has changed the ip... the client will not now about the ip change of FMC it until the FMC re-establishes the sftunnel to each ftd box.. I would suggest doing this in phases..
1) change ip of secondary FMC
2) verify that primary / secondary FMC are communicating
3) verify sftunnel is there to secondary FMC from all FTD boxes
4) Make FMC secondary the active unit.. check sftunnel status to secondary ...test a policy push to 1 FTD (if you want to be sure that its work)
5) Change old primary FMC ip address
6) verify HA
7) verify sftunnel to old primary and new primary (old secondary)
This is a safer option rather than having to change both FMC units ip.
07-18-2024 12:14 AM
Thank you ! This makes sense and is way simpler than what I had planned. I have never deployed a FMC or FTD in a live environment, I usually just manage them once they are in service. Looking forward to the migration, good learning curve.
Thank you again !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide