Cisco Firepower 1010 Basic Configuration
 This post shows a basic configuration step for a HA setup of two Firepower 1010.Â
FDM is a web-based, simplified, on-device manager. Because it is simplified, some FTD features are not supported using FDM. You should use FDM if you are only managing a small number of devices and don't need a multi-device manager. Note Both FDM and CDO can discover the configuration on the firewall, so you can use FDM and CDO to manage the same firewall. FMC is not compatible with other managers
- Firepower Threat Defense(FTD)
- Firepower Device Manager (FDM)
- Firepower Management Center (FMC)
- Cisco Defense Orchestrator (CDO)
Diagram

Port 1 = WAN Port (DHCP Client)
Port 2 -8 = LAN Ports - 192.168.175.x
Port 7-8 = PoE Ports
Mgmt Port = DHCP Client / Manual Assign
Default login: admin / Admin
FDM Configuration
- Login to the FDM UI using the URL https://management-ip e.g https://192.168.10.24
- Accept any certificate errors presented by the web browser
- Enter the username of admin and the password you set previous

Configuration Overview

Pre-Configuration | Install the firewall. See the hardware installation guide. | |
Pre-Configuration | ||
Pre-Configuration | ||
Pre-Configuration | ||
CLI | ||
CLI or Device Manager | ||
Management Center | ||
Cisco Commerce Workspace | Obtain Licenses for the Management Center: Buy feature licenses. | |
Smart Software Manager | Obtain Licenses for the Management Center: Generate a license token for the management center. | |
Management Center | Obtain Licenses for the Management Center: Register the management center with the Smart Licensing server. | |
Management Center | ||
Management Center |
Basic Configuration
Cable Connections:
Interface configuration
- WAN (0/0)
- LAN (0/1)
- Others (0/2 - 0/6)
- Mgmt Interface
You can put Mgmt interface into a different network, or you can directly hook it up into your local LAN network.That is depending on your network architecture.Â
Default Route configuration
Switchport Configuration
Vlan configuration
VLAN 1 is untagged on trunk ports as it is the default native vlan.Â
Trunk configuration
HA Configuration
https://www.youtube.com/watch?v=HY_rHkaEq30
Cable Connections
Failover link: -Â 172.16.40.1/30Â Â 172.16.40.1.2/30
Stateful link:172.16.50.1/30Â 172.16.50.2/30
LED light will show which one is active (green) and which one is passive (amber)
Interface configuration:
WAN - Active IP, Passive IP
LAN - Active IP, Passive IP
References
- Cisco Firepower 1010 Getting Started Guide -Â Chapter: Threat Defense Deployment with the Management Center
- Cisco Firepower 1010 Initial Configuration via Setup Wizard
- Cisco Network Security Ordering Guide
- Home»AnyConnect»Cisco FTD Deploy AnyConnect (from FDM)
- Basic Interface Configuration for Firepower 1010Switch PortsÂ
No comments