<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 4110 FTD 6.4 - Active Standby HA ISSUE with upraging FXOS to From 2.6(1.174) to 2.8.(1.143) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4300330#M1078936</link>
    <description>&lt;P&gt;Hi Marvin&amp;nbsp;&lt;BR /&gt;Thank you for response. As I mentioned abow here&amp;nbsp; the chassie has been reboded. You are right 2 hours is &lt;SPAN&gt;excessive for an upgrade. It took almost 45 min for ograding the first FTD&amp;nbsp; 4110 chassie. Actuly I did open a TAC case and I am trynig to explain below here and I hope it can help some one else in the same situation.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;One of the thing that I verified, was that when I logged to the&amp;nbsp; Firepower chassie manager it shows that I was runing with the new FXOS 2.8 and chassie seems to be updated&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then I tried to check the &lt;STRONG&gt;Security Engine&lt;/STRONG&gt; state on the&amp;nbsp;Firepower chassie manager and it was down pand Powered " OFF". I tried to change the state and power it on but It dosen't work.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When I got the Cisco TAC enginner on the case. He did the same thing. He tried to " Power on " the Security Engine. But still the same problem.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then he told me that he can try&amp;nbsp; somthing else from CLI for "Power on " the Security Engine. But before that he would check the firmware debug utility &amp;nbsp;power status on the moduel&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;He tried the following command:&lt;BR /&gt;&lt;/SPAN&gt;&lt;P&gt;FTD01# &lt;STRONG&gt;connect cimc 1/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Trying 127.5.1.1...&lt;/P&gt;&lt;P&gt;Connected to 127.5.1.1.&lt;/P&gt;&lt;P&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;CIMC Debug Firmware Utility Shell [ support ]&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[ help ]# &lt;STRONG&gt;power&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;OP:[ status ]&lt;/P&gt;&lt;P&gt;Power-State:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ off ]&lt;/P&gt;&lt;P&gt;Master-State:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Master ]&lt;/P&gt;&lt;P&gt;VDD-Power-Good:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ inactive ]&lt;/P&gt;&lt;P&gt;Power-On-Fail:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ inactive ]&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Power-Ctrl-Lock:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ permanent lock ]&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Power-System-Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Bad ]&lt;/P&gt;&lt;P&gt;Front-Panel Power Button:&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Disabled ]&lt;/P&gt;&lt;P&gt;Front-Panel Reset Button:&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Disabled ]&lt;/P&gt;&lt;P&gt;Source of Last Power Change: [ No Transition ]&lt;/P&gt;&lt;P&gt;OP-CCODE:[ Success ]&lt;/P&gt;&lt;P&gt;[ power ]#&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Regarding to Cisco TAC engineer "&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;Power-Ctrl-Lock:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ permanent lock ]&lt;/STRONG&gt;&lt;/U&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;" means that you can not do any&amp;nbsp; thing to " &lt;STRONG&gt;power on&amp;nbsp;&lt;/STRONG&gt;" the Module and the only solution will be Hardware Replacment.&lt;BR /&gt;According TAC Engineer, For alle &lt;STRONG&gt;FTD 4110 you need to RMA whole the chassie&lt;/STRONG&gt;&amp;nbsp;but if this the same issue happning for &lt;STRONG&gt;FTD 9300&lt;/STRONG&gt; chassie you don't need to do hardware replacment. You just need to do RMA for that faulty moduel.&lt;BR /&gt;So in my case we did RMA for FTD 4100. I hope my explenation is good enough :).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Tue, 02 Mar 2021 22:06:17 GMT</pubDate>
    <dc:creator>Behzad Sharifi</dc:creator>
    <dc:date>2021-03-02T22:06:17Z</dc:date>
    <item>
      <title>4110 FTD 6.4 - Active Standby HA ISSUE with upraging FXOS to From 2.6(1.174) to 2.8.(1.143)</title>
      <link>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4298880#M1078849</link>
      <description>&lt;P&gt;I am about to uprade two FTD 4110 FXOS. The first upgrade has been succeced on the Secondary and then I tried do run the same steps on the primery FTD. I has been runing upgrade in more than 2 hours on the primery FTD now and I am soure that some thing is wrong. When I connect the chassie from the GUI, I is showing that the runing version is 2.8.(1.143) but if I check the CLI, I seems to be the upgrade process still runing after two hours. Is there any one that has seen this issue before. I am not sure if I have to reboot the chassie.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FTD01 /system # show firmware monitor&lt;BR /&gt;FPRM:&lt;BR /&gt;Package-Vers: 2.8(1.143)&lt;BR /&gt;Upgrade-Status: Ready&lt;/P&gt;&lt;P&gt;Fabric Interconnect A:&lt;BR /&gt;Package-Vers: 2.8(1.143)&lt;BR /&gt;Upgrade-Status: Ready&lt;/P&gt;&lt;P&gt;Chassis 1:&lt;BR /&gt;Server 1:&lt;BR /&gt;Package-Vers: 2.8(1.143),2.6(1.174)&lt;BR /&gt;Upgrade-Status: Upgrading&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*****&lt;/P&gt;&lt;P&gt;FTD01 /chassis # show version&lt;BR /&gt;Chassis 1:&lt;BR /&gt;Server 1:&lt;BR /&gt;CIMC:&lt;BR /&gt;Running-Vers: 4.1(30b)&lt;BR /&gt;Package-Vers: 2.8(1.143)&lt;BR /&gt;Update-Status: Ready&lt;BR /&gt;Activate-Status: Ready&lt;/P&gt;&lt;P&gt;Adapter 1:&lt;BR /&gt;Running-Vers: 5.6(1.10)&lt;BR /&gt;Package-Vers: 2.6(1.174)&lt;BR /&gt;Update-Status: Updating&lt;BR /&gt;Activate-Status: Activating&lt;BR /&gt;Bootloader-Update-Status: Ready&lt;BR /&gt;BIOS:&lt;BR /&gt;Running-Vers: FXOSSM1.1.2.1.18.052320191712&lt;BR /&gt;Package-Vers: 2.8(1.143)&lt;BR /&gt;Update-Status: Ready&lt;BR /&gt;Activate-Status: Ready&lt;/P&gt;&lt;P&gt;SSP OS:&lt;BR /&gt;Running-Vers: 2.6(1.156)&lt;BR /&gt;Package-Vers: 2.6(1.174)&lt;BR /&gt;Update-Status: Updating&lt;BR /&gt;Activate-Status:&lt;/P&gt;&lt;P&gt;RAID Controller 1:&lt;BR /&gt;Running-Vers:&lt;BR /&gt;Package-Vers:&lt;BR /&gt;Activate-Status:&lt;/P&gt;&lt;P&gt;BoardController:&lt;BR /&gt;Running-Vers: 14.0&lt;BR /&gt;Package-Vers: 2.8(1.143)&lt;BR /&gt;Activate-Status: Ready&lt;/P&gt;&lt;P&gt;Local Disk 1:&lt;BR /&gt;Running-Vers:&lt;BR /&gt;Package-Vers:&lt;BR /&gt;Activate-Status:&lt;/P&gt;&lt;P&gt;C2DC01FTD01 /chassis #&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2021 23:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4298880#M1078849</guid>
      <dc:creator>Behzad Sharifi</dc:creator>
      <dc:date>2021-02-27T23:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: 4110 FTD 6.4 - Active Standby HA ISSUE with upraging FXOS to From 2.6(1.174) to 2.8.(1.143)</title>
      <link>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4298969#M1078857</link>
      <description>&lt;P&gt;You should not have to perform a manual reboot. 2 hours is excessive for an upgrade - my experience is that they should take about 30-40 minutes total per chassis.&lt;/P&gt;
&lt;P&gt;I would recommend opening a TAC case (and not performing a manual reboot). Rebooting unexpectedly in the middle of an ongoing upgrade (even a "hung" one) could leave the system in an unstable state.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 11:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4298969#M1078857</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-02-28T11:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: 4110 FTD 6.4 - Active Standby HA ISSUE with upraging FXOS to From 2.6(1.174) to 2.8.(1.143)</title>
      <link>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4300330#M1078936</link>
      <description>&lt;P&gt;Hi Marvin&amp;nbsp;&lt;BR /&gt;Thank you for response. As I mentioned abow here&amp;nbsp; the chassie has been reboded. You are right 2 hours is &lt;SPAN&gt;excessive for an upgrade. It took almost 45 min for ograding the first FTD&amp;nbsp; 4110 chassie. Actuly I did open a TAC case and I am trynig to explain below here and I hope it can help some one else in the same situation.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;One of the thing that I verified, was that when I logged to the&amp;nbsp; Firepower chassie manager it shows that I was runing with the new FXOS 2.8 and chassie seems to be updated&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then I tried to check the &lt;STRONG&gt;Security Engine&lt;/STRONG&gt; state on the&amp;nbsp;Firepower chassie manager and it was down pand Powered " OFF". I tried to change the state and power it on but It dosen't work.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When I got the Cisco TAC enginner on the case. He did the same thing. He tried to " Power on " the Security Engine. But still the same problem.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Then he told me that he can try&amp;nbsp; somthing else from CLI for "Power on " the Security Engine. But before that he would check the firmware debug utility &amp;nbsp;power status on the moduel&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;He tried the following command:&lt;BR /&gt;&lt;/SPAN&gt;&lt;P&gt;FTD01# &lt;STRONG&gt;connect cimc 1/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Trying 127.5.1.1...&lt;/P&gt;&lt;P&gt;Connected to 127.5.1.1.&lt;/P&gt;&lt;P&gt;Escape character is '^]'.&lt;/P&gt;&lt;P&gt;CIMC Debug Firmware Utility Shell [ support ]&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[ help ]# &lt;STRONG&gt;power&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;OP:[ status ]&lt;/P&gt;&lt;P&gt;Power-State:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ off ]&lt;/P&gt;&lt;P&gt;Master-State:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Master ]&lt;/P&gt;&lt;P&gt;VDD-Power-Good:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ inactive ]&lt;/P&gt;&lt;P&gt;Power-On-Fail:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ inactive ]&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Power-Ctrl-Lock:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ permanent lock ]&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Power-System-Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Bad ]&lt;/P&gt;&lt;P&gt;Front-Panel Power Button:&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Disabled ]&lt;/P&gt;&lt;P&gt;Front-Panel Reset Button:&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Disabled ]&lt;/P&gt;&lt;P&gt;Source of Last Power Change: [ No Transition ]&lt;/P&gt;&lt;P&gt;OP-CCODE:[ Success ]&lt;/P&gt;&lt;P&gt;[ power ]#&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Regarding to Cisco TAC engineer "&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;Power-Ctrl-Lock:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ permanent lock ]&lt;/STRONG&gt;&lt;/U&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;" means that you can not do any&amp;nbsp; thing to " &lt;STRONG&gt;power on&amp;nbsp;&lt;/STRONG&gt;" the Module and the only solution will be Hardware Replacment.&lt;BR /&gt;According TAC Engineer, For alle &lt;STRONG&gt;FTD 4110 you need to RMA whole the chassie&lt;/STRONG&gt;&amp;nbsp;but if this the same issue happning for &lt;STRONG&gt;FTD 9300&lt;/STRONG&gt; chassie you don't need to do hardware replacment. You just need to do RMA for that faulty moduel.&lt;BR /&gt;So in my case we did RMA for FTD 4100. I hope my explenation is good enough :).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 02 Mar 2021 22:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/4110-ftd-6-4-active-standby-ha-issue-with-upraging-fxos-to-from/m-p/4300330#M1078936</guid>
      <dc:creator>Behzad Sharifi</dc:creator>
      <dc:date>2021-03-02T22:06:17Z</dc:date>
    </item>
  </channel>
</rss>

