<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC cannot connect AMP cloud in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928166#M1003449</link>
    <description>&lt;P&gt;Not sure if this is still an issue for anyone but I thought I'd share what happened to my FMC after an upgrade with regard to AMP not connecting to the Cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After an upgrade, in this case it was to 6.4.0, once complete I received the AMP Cannot Connect to Cloud issue.&amp;nbsp; I then took it to the interim update, the most recent at the time of this writing being 6.4.0.5 and the error still existed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a little investigation I noticed it was the SSL Policy preventing this.&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;I created a rule to not encrypt anything from the FMC and that has resolved the issue.&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; A better fix may be to get the self signed root certificate on the appliance (although it is using itself as a CA, so why it does not trust its own CA is a little strange).&amp;nbsp; If I get more time I may investigate this further but just for clarity it is an issue with the FMC not the sensors.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps some of you!&lt;/P&gt;</description>
    <pubDate>Sun, 22 Sep 2019 15:56:29 GMT</pubDate>
    <dc:creator>djsample</dc:creator>
    <dc:date>2019-09-22T15:56:29Z</dc:date>
    <item>
      <title>FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3718454#M1003407</link>
      <description>&lt;P&gt;I used FMC on VMWare version 6.2.3 (build 83) to control FTD 2110.&amp;nbsp; I have the Malware license and installed to FMC already.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to turn on AMP for network but no luck, it could not connect to any Cloud (US, EU, APJC).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already tried to troubleshooting as the following method;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Changed DNS then connected to the internet that could surf internet normally. It can resolve the hostname "&lt;SPAN&gt;api.amp.sourcefire.com"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Deleted and Changed AMP Cloud to US,EU and APJC but it could not connect to any Cloud.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- Allowed IP Address of FMC and FTD&amp;nbsp; to every Firewall rules to any any for both inbound and outbound that can connect to the internet normally.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Nash.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3718454#M1003407</guid>
      <dc:creator>Nashja</dc:creator>
      <dc:date>2020-02-21T16:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3718644#M1003418</link>
      <description>&lt;P&gt;SSH to FMC and get in to superuser mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;try below see if you have access to cloud ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;root@FMC62:/Volume/home/admin# telnet api.amp.sourcefire.com 443&lt;BR /&gt;Trying 52.73.183.156...&lt;BR /&gt;Connected to api.amp.sourcefire.com.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 19:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3718644#M1003418</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-03T19:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3728418#M1003433</link>
      <description>&lt;P&gt;Hi BB,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of FMC &amp;amp; FTD can access&amp;nbsp;&lt;SPAN&gt;api.amp.sourcefire.com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@FTD:~$ telnet api.amp.sourcefire.com 443&lt;BR /&gt;Trying 52.73.183.156...&lt;BR /&gt;Connected to api.amp.sourcefire.com.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@FMC:~$ telnet api.amp.sourcefire.com 443&lt;BR /&gt;Trying 50.17.105.89...&lt;BR /&gt;Connected to api.amp.sourcefire.com.&lt;BR /&gt;Escape character is '^]'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nash&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 06:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3728418#M1003433</guid>
      <dc:creator>Nashja</dc:creator>
      <dc:date>2018-10-19T06:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3728695#M1003441</link>
      <description>&lt;P&gt;i do not see any reason, may be reboot once and test it.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 14:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3728695#M1003441</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-19T14:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928166#M1003449</link>
      <description>&lt;P&gt;Not sure if this is still an issue for anyone but I thought I'd share what happened to my FMC after an upgrade with regard to AMP not connecting to the Cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After an upgrade, in this case it was to 6.4.0, once complete I received the AMP Cannot Connect to Cloud issue.&amp;nbsp; I then took it to the interim update, the most recent at the time of this writing being 6.4.0.5 and the error still existed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a little investigation I noticed it was the SSL Policy preventing this.&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;I created a rule to not encrypt anything from the FMC and that has resolved the issue.&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; A better fix may be to get the self signed root certificate on the appliance (although it is using itself as a CA, so why it does not trust its own CA is a little strange).&amp;nbsp; If I get more time I may investigate this further but just for clarity it is an issue with the FMC not the sensors.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps some of you!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 15:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928166#M1003449</guid>
      <dc:creator>djsample</dc:creator>
      <dc:date>2019-09-22T15:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928176#M1003462</link>
      <description>&lt;P&gt;Hi djsample,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can you create "&lt;EM&gt;&lt;STRONG&gt;rule to not encrypt anything from the FMC"&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nash&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 16:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928176#M1003462</guid>
      <dc:creator>Nashja</dc:creator>
      <dc:date>2019-09-22T16:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928189#M1003475</link>
      <description>&lt;P&gt;Nash,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is quite simple.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once logged on, if you have more than one core policy or SSL Policy you may want to verify what one is in use.&amp;nbsp; To do so:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policies -- Access Control -- Access Control (yes it is named twice)&lt;/P&gt;&lt;P&gt;Click the edit icon, and when in the policy verify what SSL Policy is in place&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSLPolicy.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/45353i144F3D7884158430/image-size/large?v=v2&amp;amp;px=999" role="button" title="SSLPolicy.PNG" alt="SSLPolicy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once you have made a note of this you can continue on to edit the correct SSL Policy.&lt;/P&gt;&lt;P&gt;Policies -- Access Control --SSL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click edit on the correct SSL policy if you have more than one.&amp;nbsp; Note that it takes a little while to open the SSL Policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to create a rule that is above the rules that you have set for 'Decrypt and Resign' and the rule that you create must have the action 'Do Not Decrypt' and must come from the source IP of your FMC.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add Rule -- Name Your Rule -- Set Action as 'Do not Decrypt' ---Set the Source and Destination zones if you wish&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AddRule.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/45354iF8F6A790005763C5/image-size/large?v=v2&amp;amp;px=999" role="button" title="AddRule.PNG" alt="AddRule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then select Networks and add the host IP of your FMC then set that as the Source.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AddNetwork.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/45355i54C7496D6D4A21AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="AddNetwork.PNG" alt="AddNetwork.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Click Add&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;When out of the dialogue box click save and then deploy to your device&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will most likely find that this will not immediately fix the issue as you will have to go to health monitor to run the service again.&amp;nbsp; I think this is under System -- Health -- Monitor and then you click 'run' if I recall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 17:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928189#M1003475</guid>
      <dc:creator>djsample</dc:creator>
      <dc:date>2019-09-22T17:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928310#M1003483</link>
      <description>&lt;P&gt;Did you verify the nslookup works from the FMC cli?&lt;/P&gt;
&lt;P&gt;If so, have you checked the httpsd_error_log as described in this technote:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-private-cloud-virtual-appliance/118290-technote-fireamp-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-private-cloud-virtual-appliance/118290-technote-fireamp-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 06:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928310#M1003483</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-23T06:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928581#M1003495</link>
      <description>Yes,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;All of that was checked and verified. The root cause was resigning of SSL that is why the bypass for the FMC works.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Sep 2019 13:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928581#M1003495</guid>
      <dc:creator>djsample</dc:creator>
      <dc:date>2019-09-23T13:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928606#M1003505</link>
      <description>&lt;P&gt;Ah yes - AMP cloud does not allow man-in-the-middle certificate re-signing&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/3928606#M1003505</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-23T14:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716625#M1094801</link>
      <description>&lt;P&gt;thanks for this sir but at first the error went away but after a few hours the same error came back again. For me this error pops out just right after i upgraded my Snort version from version 2 to version 3.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2022 09:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716625#M1094801</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-11-06T09:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716658#M1094802</link>
      <description>&lt;P&gt;Are you using an FTD appliance as you may have two options, firstly you could look at creating a Fast Path rule for anything from the FMC, this will affectively bypass any higher level protocol inspection (think of it like a traditional ASA).&amp;nbsp; As you've stated after a Snort upgrade I therefore assume you're using version 7.x it could be a IPS policy getting in your way.&amp;nbsp; That brings me on to your second option, look at the logs on the FMC and filter from your management IP and see what is getting blocked.&amp;nbsp; Filter the logs to show just blocked traffic and you should be able to see what is getting blocked and apply a policy to rectify.&lt;/P&gt;
&lt;P&gt;I hope this makes sense and helps in some way.&amp;nbsp; Please also ensure what you do fits with your organisations security policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2022 12:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716658#M1094802</guid>
      <dc:creator>djsample</dc:creator>
      <dc:date>2022-11-06T12:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: FMC cannot connect AMP cloud</title>
      <link>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716831#M1094813</link>
      <description>&lt;P&gt;&lt;SPAN&gt;HI Sir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have updated my Snort version 2 to the latest Snort version 3 last weekend and right after the upgrade i encountered errors below: 1) AMP error with "cannot connect to the cloud" pops out &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) downloading updates got error cannot connect to the cisco site &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) synchronizing the licenses and cannot connect to the smart software manager &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4) some users are blocked from the internet and even accessing google.com was blocked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so after i encountered these problems above i have decided to revert my snort version back to Snort 2 and i am running currently Snort 2 right now. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so my questions are below: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) is downloading updates from cisco site is different from synchronizing the licenses? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) what are the things i should do before upgrading my Snort 2 to version 3? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) what else do i need to do after upgrading my Snort to version 3? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4) I have decided to upgrade my Snort version because i encountered high snort memory usage and hoping that upgrading to Snort 3 would help the memory usage problem. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;here are the details below: FTD 7.0.4 FMC1 7.0.4 FMC2 7.0.4&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 06:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-cannot-connect-amp-cloud/m-p/4716831#M1094813</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-11-07T06:33:36Z</dc:date>
    </item>
  </channel>
</rss>

