cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
978
Views
0
Helpful
2
Replies

Secure FMC managed device access

Praveen Kumar
Level 1
Level 1

How can I implement an ACL for the managed device IP of ASA 5525s with Firepower? I have deployed a pair of "ASA 5525 with Firepower" in Active/Standby mode. These devices are managed via FMC. The FMC uses these managed device IP to connect to FTD and we are able to SSH to the same IP. I need to secure management 0/0, so only certain IPs can access it.

 

Thanks in Advance!

 

 

2 Replies 2

Hi,

You can configure the FTD to restrict access to ssh/http via Platform Settings configuration in the FMC, just create a new policy if you don't already have one and assign to the FTD(s). Reference guide here.

 

HTH

Marvin Rhoads
Hall of Fame
Hall of Fame

Not that when we use the "Platform Settings" there are separate policies / settings for FTD devices and Firepower service modules. That's because each has different capabilities in this regard.

For a Firepower service module, the appropriate place to control access is under "Access List" within the platform settings.

For an FTD device, it is done under "Secure Shell".

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card