nerdexam
Cisco

300-710 · Question #224

A network administrator registered a new FTD to an existing FMC. The administrator cannot place the FTD in transparent mode. Which action enables transparent mode?

The correct answer is B. Deregister the FTD device from FMC and configure transparent mode via the CLI. To change a Cisco FTD's firewall mode to transparent when it is managed by an FMC, the device must first be deregistered from the FMC, configured via the CLI, and then re-registered.

Configuration

Question

A network administrator registered a new FTD to an existing FMC. The administrator cannot place the FTD in transparent mode. Which action enables transparent mode?

Options

  • AAdd a Bridge Group Interface to the FTD before transparent mode is configured.
  • BDeregister the FTD device from FMC and configure transparent mode via the CLI.
  • CObtain an FTD model that supports transparent mode.
  • DAssign an IP address to two physical interfaces.

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    71% (27)
  • C
    13% (5)
  • D
    5% (2)

Why each option

To change a Cisco FTD's firewall mode to transparent when it is managed by an FMC, the device must first be deregistered from the FMC, configured via the CLI, and then re-registered.

AAdd a Bridge Group Interface to the FTD before transparent mode is configured.

Adding a Bridge Group Interface (BVI) is a step in configuring transparent mode, but it does not enable the mode itself if the FTD is already registered to an FMC.

BDeregister the FTD device from FMC and configure transparent mode via the CLI.Correct

When a Cisco FTD device is managed by a Firepower Management Center (FMC), its operational mode (routed, transparent, or passive) cannot be changed directly through the FMC GUI. To switch the FTD to transparent mode, the device must be deregistered from the FMC, the mode configured via the FTD's CLI, and then the device can be re-registered to the FMC.

CObtain an FTD model that supports transparent mode.

Transparent mode is a fundamental feature of Cisco FTD, and it is highly unlikely that the issue is due to model incompatibility without specific context.

DAssign an IP address to two physical interfaces.

Assigning IP addresses to two physical interfaces is characteristic of routed mode deployment, not transparent mode which operates at Layer 2.

Concept tested: Cisco FTD mode change when managed by FMC

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/devices_device_management.html

Topics

#FTD transparent mode#FMC device management#CLI configuration#FTD registration

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice