04-07-2025 02:03 AM
I have 2 firewalls in different locations (FW1 in City 1, FW2 in City 2). I also have 1 FMC located in City 1. How can I configure FW2 in City 2 if my FMC is in City 1?
Solved! Go to Solution.
04-07-2025 02:16 AM - edited 04-07-2025 02:47 AM
04-07-2025 02:16 AM - edited 04-07-2025 02:47 AM
04-09-2025 06:21 PM
May I ask, what could be the connection if I'm going to access the FMC remotely?
04-10-2025 01:15 AM
you can use the Data Interface instead of mgmt official document from cisco Here .you can optionally configure the device to use a data interface for management instead of the dedicated Management interface, The FMC access on a data interface is useful if you want to manage the Firepower Threat Defense remotely from the outside interface, or you do not have a separate management network. This change has to be performed on the Firepower Management Center (FMC) for FTD managed by FMC.
04-13-2025 01:48 AM
Do I need ravpn license once I set it up? So I can access remotely the FMC management or with that guide I can access the FMC via internet?
04-13-2025 02:52 AM
ravpn for end user/remote client/employess you mean? or you want to access your FMC from ravpn? in both case I beleive you FMC is on prem at DC. now youo can either access it from Internal network. if from external network means from Internet in that case for anyconnect licences you need to have a smart licence for anyconnect. Here Youtube video from cisco
04-13-2025 03:26 AM
So when I'm in the place of firewall (City 2 for example), and my FMC in on prem DC (City 1), I need anyconnect license to access the FMC management remotely to configure some settings in firewall? am I right?
04-13-2025 05:07 AM - edited 04-13-2025 05:07 AM
I see where you coming from. If you are managing a firewall located in City 2 remotely from Firepower Management Center (FMC) hosted in an on-premises data center in City 1, you will need an AnyConnect license to establish remote access for management purposes. @Marvin Rhoads could you suggest here please.
04-14-2025 01:38 AM
You need to be able to access the managing FMC. Remote access VPN that gives you connectivity to the remote FMC is one option. There are many others as well - a site-site VPN, exposing the FMC via NAT and access Control Policy, using Zero Trust Application Access, using a jump server etc. are among the other possible options - all depending on what infrastructure you have at hand.
04-14-2025 07:21 AM
Or you can expose the FMC to the public internet by only allowing the public IP address of City 2 to connect to it. However, this shouldn't be a long term solution and the long term solution should be configuring a site to site VPN between the two locations and leverage that for your management accesses to the FMC and to the firewalls. If not site to site VPN is required between those two sites, you can still configure one only for management purposes which would send the traffic of City 2 firewall management port to the FMC and vice versa.
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide