300-710 · Question #355
An engineer must change the mode of a Cisco Secure Firewall Threat Defense (FTD) firewall in the Cisco Secure Firewall Management Center (FMC) inventory. The engineer must take these actions…
The correct answer is C. Access the Secure FTD CLI from the console port. Changing the firewall mode on a Cisco FTD (e.g., from routed mode to transparent mode or vice versa) requires executing the 'configure firewall transparent' or 'configure firewall routed' command directly in the FTD CLI. This cannot be done through FMC's GUI. To access the FTD…
Question
An engineer must change the mode of a Cisco Secure Firewall Threat Defense (FTD) firewall in the Cisco Secure Firewall Management Center (FMC) inventory. The engineer must take these actions:
- Register Secure FTD with Secure FMC.
- Change the firewall mode.
- Deregister the Secure FTD device from Secure FMC.
How must the engineer take FTD take the actions?
Options
- AReload the Secure FTD device.
- BConfigure the management IP address.
- CAccess the Secure FTD CLI from the console port.
- DErase the Secure FTD configuration
How the community answered
(23 responses)- A4% (1)
- B17% (4)
- C74% (17)
- D4% (1)
Explanation
Changing the firewall mode on a Cisco FTD (e.g., from routed mode to transparent mode or vice versa) requires executing the 'configure firewall transparent' or 'configure firewall routed' command directly in the FTD CLI. This cannot be done through FMC's GUI. To access the FTD CLI for this purpose, the engineer must connect via the console port. The workflow is: (1) register FTD with FMC, (2) deregister FTD from FMC via CLI, (3) access the FTD CLI from the console port and issue the mode change command, then (4) re-register with FMC. Reloading (A) does not change the mode. Reconfiguring the management IP (B) is unrelated. Erasing configuration (D) is destructive and unnecessary.
Topics
Community Discussion
No community discussion yet for this question.