When we configure a site to site VPN in FMC, on the IKE tab, we see an authentication type option to use a Preshared Automatic Key. In this post we will see what that option does for us. FMC as you know can manage multiple FTD appliances. The appliances that…
In this post we will see how to configure DHCP Relay Agent on FTD through FMC. DHCP Relay Agent would be required when our DHCP server is not located in the same broadcast domain as the DHCP clients. For instance, we might have a centralized DHCP server located in a…
This post will show you how to configure AnyConnect SSL VPN in FMC. However, it will show you a slightly different configuration comparing to the common one we mostly use. In this lab we will have a DHCP server inside our network, and that DHCP server will assign the AnyConnect…
Before we try to add an ISE node to our ISE cube, we need to make sure all the nodes are running the same exact software version. If not, ISE won’t allow us to add that node. This is applicable for both the major and the patch releases. For instance,…
As Cisco was suggesting, the Firepower User Agent for Active Directory as an identity source for FMC was going to be removed in the future releases. In fact, as of FMC version 6.6.0 the Firepower User Agent is gone. The only option left is integrating FMC with ISE using pxGrid.…
In this post I will show you how to fix the FMC deploy error traffic will never match this rule shown below. As the error states, that would happen when you try to deploy changes that are referring to an empty security zone. In this case, the error is complaining…
This post will show you how to integrate Cisco FMC with ISE using pxGrid. Let’s first start off with some brief description of what pxGrid is. pxGrid stands for Platform Exchange Grid. and it is a technology that allows integrating multiple vendors security products together and grouping them in an…
The FMC Identity Policy is a requirement when we plan to use the users or group in our Access Control Policy. Many companies nowadays are moving away from the traditional ways of configuring the security policies based on the IP addresses. The main reasons of this is because using the…
The other day while I was playing with my FTD lab I came across a very strange issue. Basically the FMC was failing deploying the…
In this post we are going to talk about the FMC Health Monitor Policy. The main purpose of this policy is to keep a close…