Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Thanks to @Rob Ingram for pointing me to this LINK the other day. That said, I'm confused with Step 8 forward. Specifically, if I'm going to manage the FTD via a data interface (outside interface in this case), why would I care about the management i...
The FTD 1120 is currently paired to the FMCv using the diagnostic/management port, both FTD and FMCv are in HQ at the moment.However, the branch office that the FTD 1120 will be deployed to only has Outside Internet. No tie-back to HQIf I check "Enab...
Folks Is it best to use Umbrella or Firepower when blocking access to applications such as FB, Pandora and URLs/IPs to org banned destinations? Why one over the other. We have both FTDs and Umbrella and unfortunetly leave rules on both blocking diff...
Hey Pros, What is the best security practice for allowing guest users out to the Internet when connecting to our APs? I'm primarily interested in DHCP and DNS configuration. We use Cisco APs, firewall, and ISE coming soon. Internal network is a Wind...
I like the CLI. My counterpart likes ASDM. Sometimes when troubleshooting I need to see if he made any recent changes. What command(s) would I use in the CLI to see recent configuration changes made in the ASDM? Thank you so much, Alan
This worked for me (6.1.x) (Cisco DocumentationLog into the CLI of the FireSIGHT Management Center.Elevate your privilege level to the root user mode:admin@FireSIGHT:~$ sudo su -Enter this command into the CLI in order to restart the console:root@Fi...
If I'm following correctly you initially configured the FTD on the same network as the FMC. Then you changed the FMC management interface to reflect the outside IP address of the FTD as it got moved offsite?
Nice diagram @ipv6x. There is a LOT of moving parts in this. @keithcclark71 just did one of these, maybe he can shed some light on the process. I'll double back around and provide some documentation.
@keithcclark71 this isn't a great answer, but I don't believe so. I'm looking at ours now, and we have 21 rules that are mandatory for all of our FTDs. This is called our "Parent Policy," and all of our other policies are nested under it. No matter w...
@keithcclark71also ensure your logging is enabled on each rule so you can later troubleshoot events. For allow rules I do "log at end of connection" and for block rules "log at beginning of the connection." In our annual audits we always find a dozen...