Chassis management interface
A chassis management interface is a network hardware feature that
-
provides a dedicated pathway for device management and control,
-
supports multi-instance modes by allowing each software instance its own management IP address, and
-
separates management, eventing, and application access to streamline security, access, and monitoring.
Chassis management
The chassis uses the dedicated Management interface on the device. Multi-instance mode does not support using a data interface for chassis management or DHCP addressing for the Management interface.
You can only configure the chassis Management interface at the Firewall Threat Defense CLI (at initial setup) or FXOS CLI (after you convert to multi-instance mode). Refer to Change chassis management settings at the FXOS CLI to change Management interface settings in multi-instance mode.
Note | By default, SSH is not allowed to this interface in multi-instance mode unless you enable the SSH server and an SSH access list. This difference means that you can connect to the application-mode threat defense Management interface using SSH, but after you convert to multi-instance mode, you can no longer connect using SSH by default. For more information, refer to Configure SSH and SSH access list. |
Instance management
All instances share the chassis management interface, and each instance has its own IP address on the Management network. After you add the instance and specify the IP address, you can make changes to the network settings at the Firewall Threat Defense CLI.
The instance Management IP address allows SSH by default.