cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
1
Helpful
2
Replies

Second FTD in FMC

san.carlos
Level 3
Level 3

Looking to add a second ftd in fmc. This second ftd was previously replaced by the existing ftd. The older ftd has a different management ip address which should be fine however the data interfaces still have the same ip addresses. I am wanting to confirm that it should not be an issue as long as the data interfaces are not online at the time of adding the device with the intention of changing the data interfaces ip addresses once it has been successfully re-added. Please advise.

TIA!

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame
Looking to add a second ftd in fmc. This second ftd was previously replaced by the existing ftd. The older ftd has a different management ip address which should be fine however the data interfaces still have the same ip addresses. I am wanting to confirm that it should not be an issue as long as the data interfaces are not online at the time of adding the device with the intention of changing the data interfaces ip addresses once it has been successfully re-added. Please advise.

Is this part of the HA you are replacing with a new one?

Yes, adding the second Firepower Threat Defense (FTD) to your Firepower Management Center (FMC) with overlapping data interface IP addresses is generally safe, provided the data interfaces are disconnected or in a "shutdown" state to prevent network-level IP conflicts (ARP/routing issues)

OLD guide still steps valid, make sure new FTD correct stable version and FMC can manage.

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame
Looking to add a second ftd in fmc. This second ftd was previously replaced by the existing ftd. The older ftd has a different management ip address which should be fine however the data interfaces still have the same ip addresses. I am wanting to confirm that it should not be an issue as long as the data interfaces are not online at the time of adding the device with the intention of changing the data interfaces ip addresses once it has been successfully re-added. Please advise.

Is this part of the HA you are replacing with a new one?

Yes, adding the second Firepower Threat Defense (FTD) to your Firepower Management Center (FMC) with overlapping data interface IP addresses is generally safe, provided the data interfaces are disconnected or in a "shutdown" state to prevent network-level IP conflicts (ARP/routing issues)

OLD guide still steps valid, make sure new FTD correct stable version and FMC can manage.

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for your response. It is not an HA setup and not yet looking to go HA, just register the device for now. Thanks for confirming should be no issue adding the device provided the data interfaces are offline. Yes, I have confirmed FMC can manage FTD.

Review Cisco Networking for a $25 gift card