<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re-Installing Firepower on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454623#M1083140</link>
    <description>&lt;P&gt;I've got issues with a Firepower Module on our system and will be re-installing it.&lt;/P&gt;&lt;P&gt;I've researched the method and I've never done this before and would appreciate a sanity check to see if I'm missing anything before I go ahead and submit the change documents&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is&lt;/P&gt;&lt;P&gt;Four ASA 5555-x with Firepower configured as two separate active/passive failover pairs&lt;/P&gt;&lt;P&gt;ASDM for ASA management&lt;/P&gt;&lt;P&gt;FMC 6.0 for Firepower management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;High level plan&lt;/P&gt;&lt;P&gt;Collect the following info&lt;/P&gt;&lt;P&gt;Hostname =&lt;/P&gt;&lt;P&gt;Network Address =&lt;/P&gt;&lt;P&gt;Subnet Mask =&lt;/P&gt;&lt;P&gt;Gateway =&lt;/P&gt;&lt;P&gt;DNS Servers =&lt;/P&gt;&lt;P&gt;Local Domain Name =&lt;/P&gt;&lt;P&gt;Search Domain =&lt;/P&gt;&lt;P&gt;NTP Server =&lt;/P&gt;&lt;P&gt;Issue the command show summary and make note of the result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure the ASA and Firepower is in fail open mode&lt;/P&gt;&lt;P&gt;Ensure the node I'm working on is the standby&lt;/P&gt;&lt;P&gt;Remove the Module form the FMC&lt;/P&gt;&lt;P&gt;Shutdown and remove the FP module&lt;/P&gt;&lt;P&gt;Install a new (supported in the ASA and FMC matrix) image&lt;/P&gt;&lt;P&gt;"Mount" and config the SFR&lt;/P&gt;&lt;P&gt;Install the relevant software package&lt;/P&gt;&lt;P&gt;config the SFR&lt;/P&gt;&lt;P&gt;Add the FP module back into the FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this sound solid?&lt;/P&gt;&lt;P&gt;Is there any more info I should collect to ensure it's all smooth? Maybe licences?&lt;/P&gt;&lt;P&gt;Will adding the Module back into the FMC reload the policies or is there additional config I will need to do once I do so?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the process fully documented. If anybody is interested in seeing it I'm happy to share although I'm not planning to post it here as this post is quite long already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 10:05:02 GMT</pubDate>
    <dc:creator>HimeshGohil</dc:creator>
    <dc:date>2021-08-25T10:05:02Z</dc:date>
    <item>
      <title>Re-Installing Firepower on ASA</title>
      <link>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454623#M1083140</link>
      <description>&lt;P&gt;I've got issues with a Firepower Module on our system and will be re-installing it.&lt;/P&gt;&lt;P&gt;I've researched the method and I've never done this before and would appreciate a sanity check to see if I'm missing anything before I go ahead and submit the change documents&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our setup is&lt;/P&gt;&lt;P&gt;Four ASA 5555-x with Firepower configured as two separate active/passive failover pairs&lt;/P&gt;&lt;P&gt;ASDM for ASA management&lt;/P&gt;&lt;P&gt;FMC 6.0 for Firepower management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;High level plan&lt;/P&gt;&lt;P&gt;Collect the following info&lt;/P&gt;&lt;P&gt;Hostname =&lt;/P&gt;&lt;P&gt;Network Address =&lt;/P&gt;&lt;P&gt;Subnet Mask =&lt;/P&gt;&lt;P&gt;Gateway =&lt;/P&gt;&lt;P&gt;DNS Servers =&lt;/P&gt;&lt;P&gt;Local Domain Name =&lt;/P&gt;&lt;P&gt;Search Domain =&lt;/P&gt;&lt;P&gt;NTP Server =&lt;/P&gt;&lt;P&gt;Issue the command show summary and make note of the result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure the ASA and Firepower is in fail open mode&lt;/P&gt;&lt;P&gt;Ensure the node I'm working on is the standby&lt;/P&gt;&lt;P&gt;Remove the Module form the FMC&lt;/P&gt;&lt;P&gt;Shutdown and remove the FP module&lt;/P&gt;&lt;P&gt;Install a new (supported in the ASA and FMC matrix) image&lt;/P&gt;&lt;P&gt;"Mount" and config the SFR&lt;/P&gt;&lt;P&gt;Install the relevant software package&lt;/P&gt;&lt;P&gt;config the SFR&lt;/P&gt;&lt;P&gt;Add the FP module back into the FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this sound solid?&lt;/P&gt;&lt;P&gt;Is there any more info I should collect to ensure it's all smooth? Maybe licences?&lt;/P&gt;&lt;P&gt;Will adding the Module back into the FMC reload the policies or is there additional config I will need to do once I do so?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the process fully documented. If anybody is interested in seeing it I'm happy to share although I'm not planning to post it here as this post is quite long already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 10:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454623#M1083140</guid>
      <dc:creator>HimeshGohil</dc:creator>
      <dc:date>2021-08-25T10:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Installing Firepower on ASA</title>
      <link>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454655#M1083141</link>
      <description>&lt;P&gt;Small advise, You can edit the IP and rename the dead SFR on FMC, instead of deleting it completely from the FMC, also remove the licenses for it via FMC, by editing the existing device, and unchecking the licenses.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 547px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128772i6E623EF6FE8C96ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But dont delete it from FMC, as you might want to refer to the old SFR for zone mapping etc.&lt;/P&gt;
&lt;P&gt;Licenses for SFR are classic licenses so that would remain on the FMC, under system--&amp;gt; licenses, since you are re-imaging it, the mac address would remain same.&lt;/P&gt;
&lt;P&gt;You can delete the old one in there once you are satisfied with the new one working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chakshu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 11:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454655#M1083141</guid>
      <dc:creator>Chakshu Piplani</dc:creator>
      <dc:date>2021-08-25T11:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Installing Firepower on ASA</title>
      <link>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454697#M1083144</link>
      <description>&lt;P&gt;Thank you Chakshu, that's a really good tip.&lt;/P&gt;&lt;P&gt;I'll add that to my plan&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 12:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/re-installing-firepower-on-asa/m-p/4454697#M1083144</guid>
      <dc:creator>HimeshGohil</dc:creator>
      <dc:date>2021-08-25T12:46:57Z</dc:date>
    </item>
  </channel>
</rss>

