<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794790#M1032207</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You would definitely need to get the Management interface on ASA up and running because all the packets from SFR .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check this : http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are yo able to ping the Firesight manager from SFR&amp;nbsp; and vice a versa ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2016 17:36:28 GMT</pubDate>
    <dc:creator>Aastha Bhardwaj</dc:creator>
    <dc:date>2016-02-05T17:36:28Z</dc:date>
    <item>
      <title>Unable to add powerfire to powersight</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794789#M1032206</link>
      <description>&lt;P&gt;I am trying to add ASA5508 to the firesight but failing.&lt;/P&gt;
&lt;P&gt;show netstat displays established session with DNS server.&lt;/P&gt;
&lt;P&gt;But with powersight, it is SYN_SENT&lt;/P&gt;
&lt;P&gt;My powersight is in the inside interface.&lt;/P&gt;
&lt;P&gt;show int ip br indicates the management 1/1 is in down/down state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;powerpower version 5.4.1&lt;/P&gt;
&lt;P&gt;powersight version 6.0.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; show netstat&lt;BR /&gt;Active Internet connections (w/o servers)&lt;BR /&gt;Proto Recv-Q Send-Q Local Address Foreign Address State &lt;BR /&gt; &lt;BR /&gt;tcp 0 1 172.16.222.24:50346 172.16.22.25:8305 SYN_SENT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt; form firesight&lt;BR /&gt; &lt;BR /&gt;udp 0 0 172.16.222.24:49151 172.16.22.32:53 ESTABLISHED &amp;nbsp; &amp;nbsp; &amp;lt;with DNS server&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I will post configs and other show outputs necessary.&lt;/P&gt;
&lt;P&gt;Can somebody help me please?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show interface in the firepower module&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;System&amp;gt; show interfaces &lt;BR /&gt;----------------------[ eth0 ]----------------------&lt;BR /&gt;Physical Interface : eth0&lt;BR /&gt;Type : Management&lt;BR /&gt;Status : Enabled&lt;BR /&gt;MDI/MDIX : Auto&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : EC:BD:1D:5F:A8:38&lt;BR /&gt;IPv4 Address : 172.16.22.24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ASA# sh int ip br&lt;/STRONG&gt;&lt;BR /&gt;Management1/1 unassigned YES unset&lt;STRONG&gt; down down&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794789#M1032206</guid>
      <dc:creator>pgamage</dc:creator>
      <dc:date>2019-03-12T12:53:29Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794790#M1032207</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You would definitely need to get the Management interface on ASA up and running because all the packets from SFR .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check this : http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are yo able to ping the Firesight manager from SFR&amp;nbsp; and vice a versa ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 17:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794790#M1032207</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-02-05T17:36:28Z</dc:date>
    </item>
    <item>
      <title>I agree with Aastha's</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794791#M1032209</link>
      <description>&lt;P&gt;I agree with Aastha's recommendations.&lt;/P&gt;
&lt;P&gt;Also check the sfr module status from the ASA:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;show module sfr details&lt;/PRE&gt;
&lt;P&gt;Here's what a healthy module should look like:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ciscoasa# show module sfr details &lt;BR /&gt;Getting details from the Service Module, please wait...&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;Card Type: FirePOWER Services Software Module&lt;BR /&gt;Model: ASA5506&lt;BR /&gt;Hardware version: N/A&lt;BR /&gt;Serial Number: JAD192903QT&lt;BR /&gt;Firmware version: N/A&lt;BR /&gt;Software version: 6.0.0-1005&lt;BR /&gt;MAC Address Range: 5897.bd27.8360 to 5897.bd27.8360&lt;BR /&gt;App. name: ASA FirePOWER&lt;BR /&gt;App. Status: Up&lt;BR /&gt;App. Status Desc: Normal Operation&lt;BR /&gt;App. version: 6.0.0-1005&lt;BR /&gt;Data Plane Status: Up&lt;BR /&gt;Console session: Ready&lt;BR /&gt;Status: Up&lt;BR /&gt;DC addr: 192.168.107.220 &lt;BR /&gt;Mgmt IP addr: 10.0.128.21 &lt;BR /&gt;Mgmt Network mask: 255.255.255.0 &lt;BR /&gt;Mgmt Gateway: 10.0.128.1 &lt;BR /&gt;Mgmt web ports: 443 &lt;BR /&gt;Mgmt TLS enabled: true &lt;BR /&gt;ciscoasa#&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;ciscoasa# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;Virtual0 127.1.0.1 YES unset up up &lt;BR /&gt;GigabitEthernet1/1 10.0.129.1 YES CONFIG up up &lt;BR /&gt;GigabitEthernet1/2 10.0.131.1 YES CONFIG up up &lt;BR /&gt;GigabitEthernet1/3 10.0.130.1 YES CONFIG up up &lt;BR /&gt;GigabitEthernet1/4 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/5 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/6 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/7 unassigned YES unset administratively down down&lt;BR /&gt;GigabitEthernet1/8 unassigned YES unset administratively down down&lt;BR /&gt;Internal-Control1/1 127.0.1.1 YES unset up up &lt;BR /&gt;Internal-Data1/1 unassigned YES unset up up &lt;BR /&gt;Internal-Data1/2 unassigned YES unset up up &lt;BR /&gt;Internal-Data1/3 unassigned YES unset up up &lt;BR /&gt;Management1/1 unassigned YES unset up up &lt;BR /&gt;ciscoasa# session sfr console&lt;BR /&gt;Opening console session with module sfr.&lt;BR /&gt;Connected to module sfr. Escape character sequence is 'CTRL-^X'.&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;BR /&gt;labsfr login: admin&lt;BR /&gt;Password: &lt;BR /&gt;Last login: Thu Dec 3 02:24:36 UTC 2015 on ttyS1&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;Copyright 2004-2015, Cisco and/or its affiliates. All rights reserved. &lt;BR /&gt;Cisco is a registered trademark of Cisco Systems, Inc. &lt;BR /&gt;All other trademarks are property of their respective owners.&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;Cisco Fire Linux OS v6.0.0 (build 258)&lt;BR /&gt;Cisco ASA5506 v6.0.0 (build 1005)&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&amp;gt; show netstat&lt;BR /&gt;Active Internet connections (w/o servers)&lt;BR /&gt;Proto Recv-Q Send-Q Local Address Foreign Address State &lt;BR /&gt;tcp 0 0 127.0.2.1:7000 127.0.1.1:1385 ESTABLISHED &lt;BR /&gt;tcp 0 0 10.0.128.21:57169 192.168.107.220:8305 ESTABLISHED &lt;BR /&gt;tcp 0 0 10.0.128.21:8305 192.168.107.220:55172 ESTABLISHED &lt;BR /&gt;Active UNIX domain sockets (w/o servers)&lt;BR /&gt;Proto RefCnt Flags Type State I-Node Path&lt;BR /&gt;&lt;BR /&gt;&amp;lt;snip&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;BR /&gt;&amp;gt; show interfaces&lt;BR /&gt;--------------------[ outside ]---------------------&lt;BR /&gt;Physical Interface : GigabitEthernet1/1&lt;BR /&gt;Type : ASA&lt;BR /&gt;Security Zone : Lab_ASA_Outside&lt;BR /&gt;Status : Enabled&lt;BR /&gt;Load Balancing Mode : N/A&lt;BR /&gt;---------------------[ inside ]---------------------&lt;BR /&gt;Physical Interface : GigabitEthernet1/2&lt;BR /&gt;Type ASA&lt;BR /&gt;Security Zone : Lab_ASA_Inside&lt;BR /&gt;Status : Enabled&lt;BR /&gt;Load Balancing Mode : N/A&lt;BR /&gt;----------------------[ dmz ]-----------------------&lt;BR /&gt;Physical Interface : GigabitEthernet1/3&lt;BR /&gt;Type : ASA&lt;BR /&gt;Security Zone Lab_ASA_DMZ&lt;BR /&gt;Status : Enabled&lt;BR /&gt;Load Balancing Mode : N/A&lt;BR /&gt;---------------------[ cplane ]---------------------&lt;BR /&gt;IPv4 Address : 127.0.2.1&lt;BR /&gt;----------------------[ eth0 ]----------------------&lt;BR /&gt;Physical Interface : eth0&lt;BR /&gt;Type : Management&lt;BR /&gt;Status : Enabled&lt;BR /&gt;MDI/MDIX : Auto&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 58:97:BD:27:83:60&lt;BR /&gt;IPv4 Address : 10.0.128.21&lt;BR /&gt;----------------------[ tun1 ]----------------------&lt;BR /&gt;IPv6 Address : fdcc::bd:0:ffff:a9fe:1/64&lt;BR /&gt;---------------------[ tunl0 ]---------------------&lt;BR /&gt;----------------------------------------------------&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&amp;gt; exit&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;BR /&gt;labsfr login: &lt;BR /&gt;Escape Sequence detected&lt;BR /&gt;Console session with module sfr terminated.&lt;BR /&gt;ciscoasa#&lt;/PRE&gt;</description>
      <pubDate>Fri, 05 Feb 2016 20:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794791#M1032209</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-02-05T20:08:01Z</dc:date>
    </item>
    <item>
      <title>All those 'back ground'</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794792#M1032211</link>
      <description>&lt;P&gt;All those 'back ground' checkings are really useful. This level of focus definetly lead to solution doent matter how complex it is. really appriciated.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2016 03:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794792#M1032211</guid>
      <dc:creator>pgamage</dc:creator>
      <dc:date>2016-02-06T03:44:03Z</dc:date>
    </item>
    <item>
      <title>Thanks, Plugged a cable to</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794793#M1032223</link>
      <description>&lt;P&gt;Thanks, Plugged a cable to the Management 0/0 and everythign started to work. I wrongly thought M0/0 is software only as my power power is a software module.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2016 03:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-powerfire-to-powersight/m-p/2794793#M1032223</guid>
      <dc:creator>pgamage</dc:creator>
      <dc:date>2016-02-06T03:52:33Z</dc:date>
    </item>
  </channel>
</rss>

