Management/Diagnostic interface
A management/diagnostic interface is a shared physical interface that enables communication between the diagnostic logical interface and the management logical interface on security appliances.
Interface configuration details
The physical management interface is shared between the Diagnostic logical interface and the Management logical interface.
Management interface
The Management interface is separate from the other interfaces on the device. It is used to set up and register the device to the Firewall Management Center. It uses its own IP address and static routing.
Management interface configuration and monitoring
You can configure its settings at the CLI using the configure network command. If you change the IP address at the CLI after you add it to the Firewall Management Center, you can match the IP address in the Secure Firewall Management Center in the area.
You can alternatively manage the Firewall Threat Defense using a data interface instead of the management interface.
Diagnostic interface
Diagnostic interface shares a physical port with the Management interface but requires different IP addresses on the same network. A diagnostic interface allows only management traffic.
Legacy diagnostic interface support
-
A data interface named "management"—This name is reserved for use with the merged Management interface.
-
IP Address on Diagnostic
-
DNS enabled on Diagnostic
-
Syslog, SNMP, RADIUS or AD (for remote access VPN) source interface is Diagnostic
-
RADIUS or AD (for remote access VPN) with no source interface specified, and there is at least one interface configured as management-only (including Diagnostic)—The default route lookup for these services has changed from the management-only routing table to the data routing table, with no fallback to management. Therefore, you cannot use a management-only interface other than Management.
-
Static routes on Diagnostic
-
Dynamic routing on Diagnostic
-
HTTP server on Diagnostic
-
ICMP on Diagnostic
-
DDNS for Diagnostic
-
FlexConfig using Diagnostic
The Diagnostic logical interface can be configured along with the rest of the data interfaces on the window by clicking the device name and then Interfaces tab. Using the Diagnostic interface is optional (see the routed and transparent mode deployments for scenarios). The Diagnostic interface only allows management traffic, and does not allow through traffic. It does not support SSH; you can SSH to data interfaces or to the Management interface only. The Diagnostic interface is useful for SNMP or syslog monitoring.
Note |
Although the Diagnostic and Management interfaces share a physical port, you must assign different IP addresses to each interface on the same network. |




)
)

Feedback