300-710 · Question #269
A security engineer is adding three Cisco FTD devices to a Cisco FMC. Two of the devices have successfully registered to the Cisco FMC. The device that is unable to register is located behind a router
The correct answer is B. Configure a NAT ID on both the Cisco FMC and the device. E. Remove the IP address defined for the device in the Cisco FMC.. To register a Cisco FTD device located behind a NAT router to a Cisco FMC, a NAT ID must be configured on both the FTD and FMC, and any previously defined IP address for the device in FMC must be removed.
Question
A security engineer is adding three Cisco FTD devices to a Cisco FMC. Two of the devices have successfully registered to the Cisco FMC. The device that is unable to register is located behind a router that translates all outbound traffic to the router's WAN IP address. Which two steps are required for this device to register to the Cisco FMC? (Choose two.)
Options
- AReconfigure the Cisco FMC lo use the device's private IP address instead of the WAN address.
- BConfigure a NAT ID on both the Cisco FMC and the device.
- CAdd the port number being used for PAT on the router to the device's IP address in the Cisco
- DReconfigure the Cisco FMC to use the device's hostname instead of IP address.
- ERemove the IP address defined for the device in the Cisco FMC.
How the community answered
(54 responses)- A6% (3)
- B83% (45)
- C9% (5)
- D2% (1)
Why each option
To register a Cisco FTD device located behind a NAT router to a Cisco FMC, a NAT ID must be configured on both the FTD and FMC, and any previously defined IP address for the device in FMC must be removed.
Reconfiguring FMC to use the device's private IP address would not work, as the FMC cannot directly reach the private IP through the NAT device.
When a managed device is behind a NAT device, a NAT ID configured on both the FTD and FMC provides a unique identifier for establishing and maintaining the secure communication tunnel, allowing FMC to communicate with the FTD despite IP address translation.
Adding a port number for PAT to the device's IP address in FMC is not the correct mechanism for FTD registration behind NAT; the NAT ID feature is designed for this purpose.
Reconfiguring FMC to use a hostname does not resolve the underlying NAT translation issue for communication tunnel establishment.
If a registration attempt failed or the device was previously defined with an unreachable private IP in FMC, removing the existing IP address definition ensures a clean slate for the registration process with the NAT ID.
Concept tested: Cisco FTD/FMC registration with NAT
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/devices_device_management.html
Topics
Community Discussion
No community discussion yet for this question.