cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1079
Views
3
Helpful
10
Replies

Unable to Add or Delete Subinterface/s Cisco FMC

zachartl
Level 1
Level 1

Hello,

I need to remove a sub-interface and I need to add a sub-interface.

I'm unable to do either. If I try to delete one of the sub-interfaces I find that there's no provision for it (no trash can icon). I'm unable to toggle the interfaces in Edit mode. Please see attached.

There's no list of interfaces within the Add Sub-Interfaces configuration. 

I can add the sub-interface in the FTD device (4112) FXOS mode via the management GUI but the sub-interface will not appear within the FMC upon syncing the FMC with the Device. I've tried to delete the sub-interface within the FXOS GUI but the FXOS GUI tells me it can't delete the sub-interface as it has to be done via the FMC.

It appears there's a process that I will need to follow. I've looked through the documentation and am so far unable to locate such a procedure. Has anyone experienced this?

FTD Version 7.6.2

Thank you,

Terry

10 Replies 10

sidshas03
Spotlight
Spotlight

Hey @zachartl,

You cannot add or delete subinterfaces directly from FXOS once the device is already managed by FMC. FMC becomes the single point of management for all data interfaces and subinterfaces. That is why you are seeing the “no sync” issue in FXOS when you create it there.

To rectify:

  1. Log in to FMC, go to Devices → Device Management → [Your FTD Device] → Interfaces.

  2. From there, use Add Interfaces → Add Subinterface to create the new subinterface. Give the VLAN ID, assign a security zone and IP.

  3. If you want to remove a subinterface, you need to delete it from this same FMC interface list. It will not show a trash icon inside the “edit” window you have to select the interface in the list and remove it before deploying.

  4. Once you make the changes, click Save, then hit Deploy so the configuration pushes to the FTD device.

  5. If any subinterfaces were created in FXOS earlier, delete them there first, then recreate them cleanly via FMC, otherwise they will always stay unsynced.

FXOS should only be used for chassis-level tasks (like assigning interfaces to logical devices). Anything related to VLAN subinterfaces or IP addressing must be managed in FMC. I have faced this same issue before, and cleaning up the FXOS, created subinterfaces and re-creating them from FMC resolved it. After that sync and deployment, everything worked fine. Try removing the “Port-channel 20.501” from FXOS, then add it again via FMC. That should fix your sync problem.

Hi Sidshas03,

I'm sending a screenshot of what I'm running into, I select the interface, enter the edit mode and find that I can't do anything with the interface per FMC. Please have a look.

zachartl_0-1757104516034.png

 

Thank you for the prompt response!

Terry

The reason you can’t delete or add sub-interfaces directly is because once the FTD is managed by FMC, all VLAN and sub-interface changes must be done from FMC, not FXOS. To remove one, go to Devices > Device Management > [Your FTD] > Interfaces, open the parent interface in Edit, select the sub-interface from the list inside that window, and delete it there. Then click Save and Deploy. If the sub-interfaces were originally created in FXOS, you’ll need to delete them from FXOS first and then recreate them cleanly in FMC, otherwise they’ll stay out of sync.

Sid

Hello Sid,

The screenshot I shared IS From the FMC console, using the instructions you specified, Thank you. If I return to the FXOS GUI directly within the FTD, and attempt to delete the sub-interface there, the FXOS GUI tells me it cannot and that I need to utilize the FMC to accomplish this. So I appear to have two management entities, the FMC and FXOS GUI within the target FTD incapable of managing an interface already configured. I've inherited these and am intending to repurpose them, I would like to simply remove a sub-interface then create another. It appears I may need to de-register the FTD and start anew, reregistering the FTDs within the FMC. Not sure what other direction is at my disposal under the circumstances. Perhaps I'll need to turn to TAC.

Thank you again,

Terry

If interface is L3 or use in any PO then you can not use it for subinterface 

MHM

share output of interface 

Screenshot (324).png

 

This native mode ftd? 

MHM

Hi MHM,

Native mode?

No multi instance?

MHM

Correct no multi instance.

Review Cisco Networking for a $25 gift card