Change the manager access interface from management to data
You can manage the Firewall Threat Defense from either the dedicated management interface or from a data interface. If you want to change the manager access interface after you added the device to the Cloud-Delivered Firewall Management Center , follow these steps to migrate from the Management interface to a data interface. To migrate the other direction, refer to Change the manager access interface from data to management .
When you initiate the manager access migration from management to data, the Cloud-Delivered Firewall Management Center applies a block on deployment to the Firewall Threat Defense. To remove the block, enable manager access on the data interface.
Before you begin
For high-availability pairs, unless stated otherwise, perform all steps only on the active unit. After deploying the configuration changes, the standby unit synchronizes configuration and other state information from the active unit.
Procedure
Step 1 | Initiate the interface migration. |
Step 2 |
Enable manager access on the data interface
(s)
. Click
Interfaces
, click
Edit ( Check Enable management access and click OK . By default, all networks are allowed, but you can limit access as long as the Cloud-Delivered Firewall Management Center address is allowed.
If the manager access interface uses a static IP address, you are reminded to configure routing for it.
Click Save on the Interfaces page. See Configure routed mode interfaces for more information about interface settings. You can enable manager access on one routed data interface , plus an optional secondary interface . Make sure these interfaces are fully configured with a name and IP address and that they are enabled. If you use a secondary interface for redundancy, see Configure a redundant manager access data interface for additional required configuration. |
Step 3 | (Optional) If you use DHCP for the interface, enable the web type DDNS method on the DDNS page. Navigate to , and then click DDNS under the DHCP tab. See Configure Dynamic DNS . DDNS ensures the Cloud-Delivered Firewall Management Center can reach the Firewall Threat Defense at its Fully-Qualified Domain Name (FQDN) if the FTD's IP address changes. |
Step 4 | Make sure the Firewall Threat Defense can route to the Cloud-Delivered Firewall Management Center through the data interface. Add a static route if necessary on the Static Route page. Navigate to and then click Static Route under the Routing tab. See Add a Static Route . |
Step 5 | (Optional) Configure DNS in a Platform Settings policy: choose , and click DNS . Apply the policy to this device. See Configure DNS server settings . DNS is required if you use DDNS. You may also use DNS for FQDNs in your security policies. |
Step 6 | (Optional)
Enable SSH for the data interface in a Platform Settings policy, and apply it to this device at
page. Click
Edit ( See Configure secure shell SSH access . SSH is not enabled by default on the data interfaces, so if you want to manage the Firewall Threat Defense using SSH, you need to explicitly allow it. |
Step 7 | Deploy configuration changes. You will see a validation error to confirm that you are changing the manager access interface. Check Ignore warnings and deploy again.
The Cloud-Delivered Firewall Management Center will deploy the configuration changes over the current Management interface. After the deployment, the data interface is now ready for use, but the original management connection to Management is still active. |
Step 8 | After deployment, perform these actions. |
Step 9 | Ensure the management connection is reestablished. In the page, click Manager Access Details: Configuration and then click Connection Status . Alternatively, you can check at the Firewall Threat Defense CLI. Enter the sftunnel-status-brief command to view the management connection status. This status indicates a successful connection for a data interface, showing the internal "tap_nlp" interface.
If it takes more than 10 minutes to reestablish the connection, you should troubleshoot the connection. See Troubleshoot Management Connectivity on a Data Interface . |