ā02-02-2025 08:32 PM
Hi all,
Does anyone foresee any issues in configuring the same range of IP addresses on the management interface and one of the data interfaces?
We have a complex setup here, and we believe this could ease it up a bit.
Thanks,
Dodzi
ā02-03-2025 01:34 AM
The management interface is typically used for administrative tasks and should ideally be isolated from user or data traffic for security reasons. Sharing an IP range with a data interface may expose the management interface to unintended risks unless strict access control policies are implemented. A very similar question has already asked here in this community Here is the link and This one too
Instead of using the same IP range, consider using a separate subnet for the management interface while leveraging a data interface for FMC communication if needed.
ā02-03-2025 09:57 AM
I agree with @Sheraz.Salim, the management ports should be configured on a separate subnet, and even better in a proper out-of-band network, but I also understand that sometimes we need to adapt to certain requirements. If you have to have the management interfaces of your FTDs in the same segment as one of the data interfaces then at the very least you should configure the "Secure Shell" restriction in the FMC platform settings applied to that FTD. This will at least restrict the SSH accesses to that firewall allowing only the defined IP addresses/subnet. If you are managing that firewall via FDM then you would need to do the same from the "Management Access" tab.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide