You are here
SEC0237 - FTD 6.1 Firewall Mode and Interface Type (Part 2)
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video walks you through different operational mode on Cisco FTD 6.1 as physical and virtual (NGFWv) devices covering, routed, passive, inline, transparent and ERSPAN modes. We will focus on interface configuration of each type, zone configuration, and how to get traffic to pass through or to the device.
Part 2 of this video covers FTD in passive and inline modes
Topic:
-
FTD Routed Mode
- Routed Zone
- Routed Interface
- Redundant Interface
- Static Route
-
FTD Passive Mode
- Passive Zone
- Passive Interface
- SPAN Session
-
FTD Inline Mode
- Inline Zone
- Inline Set
-
FTD Transparent Mode
- Etherchannel
- Sub-Interface
- Bridge Group Interface
- FTD with ERSPAN
4 comments
FTD in Transparent Mode
Hi Metha,
Thanks for your very helpful videos. Its really helpful to learn about cisco stuff. However, i got a question here. What if FTD-HA pair is set up in Transparent mode and interface is in Inline mode and security zone is Inside and outside. In this case, do we still need to assign IPV4 in BVI interface?
Any help is much appreciated!
FTD in Transparent Mode
Absolutely. The BVI is required regardless of HA. It is used for firewall-generated traffic.
Thanks for the quick response
Thanks for the quick response! But then, when i go for BVI and to assign IP address, it does not showing me the interfaces in the BVI list for which i have assign the IP. Lets say, Inside and Outside and in Transparent we give Ip address to the one which acts as one communication line for both. But in order to give the IP we need to select the interfaces in the BVI list, but its not showing up as its in Trust <-> Untrust zone.
FTD in Transparent Mode
Can you make sure your FW is in fact in transparent mode? Do you see any interfaces listed as available and able to move them to Selected Interface?