This Article explain way to back and restore configuration of ASA running on Firepower 2100 series platform. When you run ASA on Firepower 2100 platform, you have two software, FXOS and ASA on the platform. You need to backup config on both software. As on ASA 9.8.2, you can backup ASA config using Copying "show running-config". FXOS needs manual configuring.
Backup ASA Configuration:
ASA Configuration can be backup with any one of below items.
1) Copy running-config ftp:/scp:/smb:/tftp: (Copying ASA running configuration to ftp, scp, SMB, tftp, through Management or any of data interfaces)
2) Copy startup-config ftp:/scp:/smb:/tftp: (Copying ASA running configuration to ftp, scp, SMB, tftp, through Management or any of data interfaces)
3) Simply copy (show running-config) and paste to text file
Restoring ASA Configuration:
Restoring ASA config to ASA can be either of below steps.
1) Simply copy past ASA config file on ASA console/Terminal.
2) Copy ftp:/scp:/smb:/tftp: running-config
FXOS Configuration Backup & Restore:
Since FXOS on FP2100 doesn't have backup option, all configurations need to be noted down manually. "show tech-support fprm" can be also used, which have some of below configuration. You may use FCM Firepower Chassis Manager or FXOS CLI to configure below parameters.
Firepower Chassis Manager: https://<FXOS-IP>
Management IP address for FXOS: firepower-2110#Scop fabric-interconnect a firepower-2110 /fabric-interconnect #set out-of-band static/DHCP
DNS Config: firepower-2110#Scope system firepower-2110 /System#Scope Services firepower-2110 /system/services # create dns
I want to configure my AD as an external identity source for ISE CLI access. The only documentation I've found so far is this:
Hi, We are receiving High unmanaged disk usage on /ngfw alarms on a FTD 4100 and it seams like the issue is tons of filesunder the /ngfw//var/sf/detection_engines folder. I saw there was a bug reported on this issue and I've alr...
Hi Im looking for conformation of the default behavior of DOT1x in the event that no authentication servers are available and equally can this be controlled. I am mid deployment and testing and expect that my customer will require the network to...
I am working on Integration of ISE 18.104.22.1688 (Cisco) against Mobility Master 22.214.171.124 (Aruba Network).The scope includes the creation of authorization and rule policies in the ISE for 2 types of guests that the SSID Guest will have; Guests of invited guest...