<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic registering FTDv Azure to FMC on-prem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445528#M1082764</link>
    <description>&lt;P&gt;Hei,&lt;/P&gt;&lt;P&gt;I am trying to register FTDv in Azure to FMC on-prem over express route. I am getting error " "Discovery failed due to internal error contact TAC". I also see communication established messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Used same configure manager add IP key nat-id on both sides...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp; any tips ?&lt;/P&gt;</description>
    <pubDate>Fri, 06 Aug 2021 13:44:58 GMT</pubDate>
    <dc:creator>mateens</dc:creator>
    <dc:date>2021-08-06T13:44:58Z</dc:date>
    <item>
      <title>registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445528#M1082764</link>
      <description>&lt;P&gt;Hei,&lt;/P&gt;&lt;P&gt;I am trying to register FTDv in Azure to FMC on-prem over express route. I am getting error " "Discovery failed due to internal error contact TAC". I also see communication established messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Used same configure manager add IP key nat-id on both sides...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp; any tips ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 13:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445528#M1082764</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-06T13:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445661#M1082767</link>
      <description>&lt;P&gt;Can you confirm that you have bidirectional communication (must be able to initiate from either end) over tcp/8305?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 19:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445661#M1082767</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-08-06T19:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445724#M1082768</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you try by creating a new policy while registering the device and chose default action as "intrusion prevention", I have seen this happening when the default action is selected to be "Network Discovery".&lt;/P&gt;
&lt;DIV id="tinyMceEditor_70bd97bb06f37cChakshuPiplani_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chakshu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 22:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445724#M1082768</guid>
      <dc:creator>Chakshu Piplani</dc:creator>
      <dc:date>2021-08-06T22:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445785#M1082770</link>
      <description>&lt;P&gt;I can ping both ways and the ports are open. I see communication established notification in FMC. sftunnel status shows output on FTD with FMCs hostname looks like it established connection with FMC. any other way to verify ?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 07:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445785#M1082770</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-07T07:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445786#M1082771</link>
      <description>&lt;P&gt;I tried changing the acp's default action to intrusion prevention max detection. any other tip ?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 07:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445786#M1082771</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-07T07:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445889#M1082776</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From FMC CLI go to expert mode and run this command:&lt;BR /&gt;&lt;BR /&gt;pigtail -f var/logs/messages&lt;BR /&gt;&lt;BR /&gt;This will help you to see whats happening during registration.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful&lt;BR /&gt;</description>
      <pubDate>Sat, 07 Aug 2021 17:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445889#M1082776</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-08-07T17:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445939#M1082780</link>
      <description>&lt;P&gt;i see no log messages on fmc with that command, just says displaying.&lt;/P&gt;&lt;P&gt;in fmc i see following notifications:&lt;/P&gt;&lt;P&gt;-registration started&lt;/P&gt;&lt;P&gt;-registration communication established&lt;/P&gt;&lt;P&gt;-FTDv discovery from the device in progress ( many messages and it takes almost 30 min)&lt;/P&gt;&lt;P&gt;-unregistration unable to get status message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on FTD i see&lt;/P&gt;&lt;P&gt;-pending&lt;/P&gt;&lt;P&gt;-show managers "registration :completed"&lt;/P&gt;&lt;P&gt;-no managers when fmc finishes unregistration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 23:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445939#M1082780</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-07T23:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445945#M1082781</link>
      <description>That doesn't make sense. Are you sure the FMC IP is correct?&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sun, 08 Aug 2021 00:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4445945#M1082781</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-08-08T00:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446257#M1082788</link>
      <description>&lt;P&gt;Yes, show managers command on ftd shows the ip of the fmc and registration completed.&lt;/P&gt;&lt;P&gt;but after about 30min on Discovery from the device is in progress, FMC unregisters the FTD and says unable to get status message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 08:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446257#M1082788</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-09T08:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446408#M1082795</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 07:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446408#M1082795</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-10T07:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446418#M1082797</link>
      <description>&lt;P&gt;I digged some log messages from the devices. What is the role og SSL during registration ?&lt;/P&gt;&lt;P&gt;fw01:&lt;BR /&gt;-------&lt;BR /&gt;fw01: Built inbound TCP connection for Azure_FMC:172.30.7.1/52255 to LNK:10.240.1.6/8305&lt;BR /&gt;fw01: Built inbound TCP connection for LNK:10.240.1.6/52451 to Azure_FMC:172.30.7.1/8305&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;---------------&lt;BR /&gt;logs from FMC:&lt;/P&gt;&lt;P&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_connections [INFO] DISCONNECTED:do_services_read_write: Broken connection to service 9009 (FD 10), peer 10.240.1.6&lt;BR /&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_peers [INFO] Confirm RPC service in CONTROL channel&lt;BR /&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_connections [INFO] Accepting a service connection..&lt;BR /&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_heartbeat [INFO] CSM_CCM service is published for peer 10.240.1.6&lt;BR /&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_peers [INFO] Using a 750 entry queue for 10.240.1.6 - 9009&lt;BR /&gt;Aug 9 10:01:55 fmc01 SF-IMS[28415]: [14152] sftunneld:sf_channel [INFO] Peer 10.240.1.6. SWITCH SERVICE 9009 CHANNEL 2&lt;BR /&gt;Aug 9 10:01:56 fmc01 stunnel: LOG3[24057]: SSL_connect: 14090086: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed&lt;BR /&gt;Aug 9 10:02:30 fmc01 SF-IMS[7541]: [7541] pm:process [INFO] Started RUAScheduledDownload (24189)&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;Logs from FTD:&lt;/P&gt;&lt;P&gt;Aug 9 10:04:15 ftd01 SF-IMS[16639]: [17150] sftunneld:sf_heartbeat [INFO] Received message for not published CSM_CCM service for peer 172.30.7.1&lt;BR /&gt;Aug 9 10:05:09 ftd01 syslog-ng[1549]: Connection failed; fd='18', server='AF_UNIX(/dev/asalog)', local='AF_UNIX(anonymous)', error='No such file or directory (2)'&lt;BR /&gt;Aug 9 10:05:09 ftd01 syslog-ng[1549]: Initiating connection failed, reconnecting; time_reopen='60'&lt;BR /&gt;Aug 9 10:06:09 ftd01 syslog-ng[1549]: Connection failed; fd='17', server='AF_UNIX(/dev/asalog)', local='AF_UNIX(anonymous)', error='No such file or directory (2)'&lt;BR /&gt;Aug 9 10:06:09 ftd01 syslog-ng[1549]: Initiating connection failed, reconnecting; time_reopen='60'&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 12:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446418#M1082797</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-09T12:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446422#M1082798</link>
      <description>&lt;P&gt;error Looks like this bug CSCvg62301.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 13:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446422#M1082798</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-09T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446429#M1082799</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 07:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4446429#M1082799</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-10T07:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4449090#M1082865</link>
      <description>&lt;P&gt;What does this log mean ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;on FTD i see:&lt;/P&gt;&lt;P&gt;ACTQ: 08-13 13:45:27 pid=15605 Remote heartbeat task processing failed on 172.30.7.1: &lt;STRONG&gt;Appliance is set to ignore&lt;/STRONG&gt;, ignore heartbeat from 4eb60038-c462-11eb-a04d-m3017b472bc8 at /ngfwPERLLIB/SF/Synchronize/VerticalSync.pm line 462.&lt;BR /&gt;SERR: 08-13 13:45:27 ActionQueueScrape[3300]: Remote heartbeat task processing failed on 172.30.7.1: Appliance is set to ignore, ignore heartbeat from eb60038-c462-11eb-a04d-m3017b472bc8 at /ngfwPERLLIB/SF/Synchronize/VerticalSync.pm line 462.&lt;/P&gt;&lt;P&gt;&amp;nbsp;on FMC i see:&lt;/P&gt;&lt;P&gt;SERR: 08-13 13:37:08 ActionQueueScrape[27936]: REMOTE WARNING FROM '&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;': &lt;STRONG&gt;Platform_info file not present.&lt;/STRONG&gt;&lt;BR /&gt;USMS: 08-13 13:37:08 "hostName": "&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;",&lt;BR /&gt;USMS: 08-13 13:37:08 "mgmtIpAddress": "&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;",&lt;BR /&gt;ACTQ: 08-13 13:37:08 pid=10302 Applying Custom FP remotely to &lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt; at PERLLIB/SF/RNA/CustomFP.pm line 1803.&lt;BR /&gt;ACTQ: 08-13 13:37:08 pid=8270 'displayName' =&amp;gt; '&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;'&lt;BR /&gt;USMS: 08-13 13:37:08 "hostName": "&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;",&lt;BR /&gt;USMS: 08-13 13:37:08 "mgmtIpAddress": "&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;",&lt;BR /&gt;SERR: 08-13 13:37:08 ActionQueueScrape[27936]: Applying Custom FP remotely to &lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt; at PERLLIB/SF/RNA/CustomFP.pm line 1803.&lt;BR /&gt;SERR: 08-13 13:37:08 ActionQueueScrape[27936]: 'displayName' =&amp;gt; '&lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt;'&lt;BR /&gt;SERR: 08-13 13:37:08 ActionQueueScrape[27936]: END TASK || 4c4bba94-fc4b-11eb-ac6f-87cd8c764v65 || Registration || Communication with &lt;SPAN&gt;10.240.1.6&lt;/SPAN&gt; has been &lt;STRONG&gt;established&lt;/STRONG&gt;, discovery in progress || 138&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 13:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4449090#M1082865</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-13T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: registering FTDv Azure to FMC on-prem</title>
      <link>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4452259#M1083010</link>
      <description>&lt;P&gt;Problem was actually at the Azure end. It worked after I added fourth interface to the FTDv VM in azure (i had 3) and did Detach and attach on the all the interfaces.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 07:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/registering-ftdv-azure-to-fmc-on-prem/m-p/4452259#M1083010</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2021-08-20T07:33:05Z</dc:date>
    </item>
  </channel>
</rss>

