Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Actually thinking about it more, that command won't apply here because the DHCP traffic won't be sent to the subnet broadcast address. You might have an ACL on the router interface that is blocking that traffic or you might be missing the IP helper o...
I think the command that you would need to look at on the router interface would be "no ip directed-broadcast" which denies the broadcast traffic on the receving interface. This has nothting to do with the ACL in itself.
https://www.cisco.com/c/en/us...
You can still the same public IP assigned to the FTD outside interface, you'll have to create a NAT rule to pass the management traffic from the outside interface on port 8305/tcp to the dedicated management interface.
If you can't do users certificate authentication alongside machine certificate right away and you really have no option other than using MSCHAPv2 then I think you just need to start talking to the business about moving away from the legacy authentica...