<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Excellent - thanks for in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082905#M103522</link>
    <description>&lt;P&gt;Excellent - thanks for sharing!&lt;/P&gt;
&lt;P&gt;As I sometimes joke, the down side of having a PhD in Cisco Security licensing is that the shelf life of the knowledge is about a year. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2017 14:24:46 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-06-21T14:24:46Z</dc:date>
    <item>
      <title>Smart Software licensing for FR41200 with vASA</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082900#M103502</link>
      <description>&lt;P&gt;Hi, All&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We are trying to register our FP 4120 to the cisco smart licensing. We have already the smart account and assigned the licenses in the virtual acocunt.&lt;/P&gt;
&lt;P&gt;Apparenly we are having issue, now we are using the smart software satellite as our environment dont have direct connection to the internet.&lt;/P&gt;
&lt;P&gt;Somehow we are having issue genrerating the certchain. Getting invallid cert chain.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;we manage to&amp;nbsp;&amp;nbsp;directly connect the FirePower to the internet using the management port but still failed to register.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Anyone had experience to register a Firepower to the smart licensing either using the default mode or the satellite?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks and regards&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 16:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082900#M103502</guid>
      <dc:creator>Junyx sen</dc:creator>
      <dc:date>2017-06-20T16:54:33Z</dc:date>
    </item>
    <item>
      <title>I've not used a satellite</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082901#M103505</link>
      <description>&lt;P&gt;I've not used a satellite server but have setup a FirePOWER 4110 with ASA logical device.&lt;/P&gt;
&lt;P&gt;Did you get a token from Smart Software Manager portal and apply it to the chassis via FirePOWER Chassis Manager?&lt;/P&gt;
&lt;P&gt;That needs to be done before you can allocate the ASA base and 3DES-AES licenses for the ASA logical device.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 07:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082901#M103505</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-21T07:50:47Z</dc:date>
    </item>
    <item>
      <title>Hi, Marvin</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082902#M103507</link>
      <description>&lt;P&gt;Hi, Marvin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your feedback.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We just solve the issue today. Firstly we have already the smart account and was able to login to the smart licensing site. Then we created the satellite server and sync it. After we settled the satellite server we can now generate the token and apply to the firepower.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Apparently we need to create a cert chain, this is the&amp;nbsp;part were we got&amp;nbsp;an issue.&lt;/P&gt;
&lt;P&gt;After resolving this cert chain issue, we were able to successfully register our firepower and use the features for the ASA VPN.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 14:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082902#M103507</guid>
      <dc:creator>Junyx sen</dc:creator>
      <dc:date>2017-06-21T14:08:13Z</dc:date>
    </item>
    <item>
      <title>Thanks for letting us know.</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082903#M103512</link>
      <description>&lt;P&gt;Thanks for letting us know.&lt;/P&gt;
&lt;P&gt;Was there a guide or instructions from the TAC on the cert chain issue that you can share?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 14:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082903#M103512</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-21T14:13:42Z</dc:date>
    </item>
    <item>
      <title>I have attached the file.</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082904#M103515</link>
      <description>&lt;P&gt;I have attached the file.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to extract the certificate on the satellite server.&amp;nbsp;When creating the cert chain you must include both the default cert from the firepower&amp;nbsp;and from the imported certificate from the satellite server if not both you will get error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 14:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082904#M103515</guid>
      <dc:creator>Junyx sen</dc:creator>
      <dc:date>2017-06-21T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Excellent - thanks for</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082905#M103522</link>
      <description>&lt;P&gt;Excellent - thanks for sharing!&lt;/P&gt;
&lt;P&gt;As I sometimes joke, the down side of having a PhD in Cisco Security licensing is that the shelf life of the knowledge is about a year. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 14:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3082905#M103522</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-21T14:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Excellent - thanks for</title>
      <link>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3918673#M103523</link>
      <description>&lt;P&gt;We have similar problem with Firepower 2100 ASA image. The communication to Satellite server did not work too. Wireshark and log „show crypto ssl errors“ showed errors because the communication to Satellite https certificate should be from trusted certificate. We took the CA certificate from Satellitze server where certificates are stored at OS file system. If you have the CA certificate, you can add it from ASDM and test the connection by command „&lt;STRONG&gt;call-home test profile license&lt;/STRONG&gt;“. Adding via cli is possible but you need another form of the certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The default config does not contain this Cisco Licensing Root CA certificate so we spent a lot of time to find how to licence our firewall. From customer point of view, it was useless time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody know if the necessity of adding Cisco Licensing Root CA to trusted CA for allowing communication to Satellite server is somewhere described? I was not able to find it. Now I found a web page &lt;A href="https://www.cisco.com/security/pki/" target="_blank" rel="noopener"&gt;https://www.cisco.com/security/pki/&lt;/A&gt; where are Cisco CA certificates. But Cisco Licensing Root CA is not here and I do not want to read all these certificates if one of them is the same that is used by the Satellite server.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 07:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smart-software-licensing-for-fr41200-with-vasa/m-p/3918673#M103523</guid>
      <dc:creator>martin5641289</dc:creator>
      <dc:date>2019-09-04T07:23:18Z</dc:date>
    </item>
  </channel>
</rss>

