<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower SFR Module - No connection events in FMC event viewer? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487280#M1084410</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you again for your suggestions. Today we carried out some testing:&lt;/P&gt;&lt;P&gt;In the applied ACP, I added a specific block rule from x.x.x.x to y.y.y.y and observed that this &lt;EM&gt;&lt;STRONG&gt;DID&lt;/STRONG&gt; &lt;/EM&gt;block the traffic flow so I know that the traffic is punted up from the ASA to the SFR module and the SFR module is doing what it's supposed to do.&lt;/P&gt;&lt;P&gt;However, despite logging being enabled on that rule to both the FMC event viewer and also a syslog server, we did not see any events logged.&lt;/P&gt;&lt;P&gt;I can also see from the output of "show access-control-config" that there are hits against the rule and confirmation that logging is enabled:&lt;/P&gt;&lt;P&gt;####################################################################&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;===============[ Rule Set: (User) ]================&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;--------------[ Rule: matt-allow-any ]--------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Action : Allow&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Intrusion Policy : Matt-IPS-Policy&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; ISE Metadata :&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Logging Configuration&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DC : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; Beginning : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; End : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; Files : Disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Safe Search : No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Rule Hits : &lt;FONT color="#FF0000"&gt;48287&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Variable Set : Matt-Variable-Set&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;####################################################################&lt;/P&gt;&lt;P&gt;One thing that is odd is that sometimes when I run "show summary", it says "Access control policy not yet applied." but then after I execute "show access-control-config", the output of "show summary" then changes to be what you'd expect (policy info, plus list of interfaces).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host discover is correctly configured but there are no hosts listed in the network map.&lt;/P&gt;&lt;P&gt;There is "No data" listed in any of the traffic related dashboard widgets in the FMC.&lt;/P&gt;&lt;P&gt;We tried rebooting the FMC - no change.&lt;/P&gt;&lt;P&gt;We tried rebooting the SFR module - no change.&lt;/P&gt;&lt;P&gt;I'm out of ideas here, it's driving me crazy! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any help that you, or anybody else can provide is very much appreciated. I'm running out of hair to pull out here!&lt;/P&gt;&lt;P&gt;Many thanks,&lt;BR /&gt;Matt.&lt;/P&gt;</description>
    <pubDate>Sat, 16 Oct 2021 13:16:09 GMT</pubDate>
    <dc:creator>mattw</dc:creator>
    <dc:date>2021-10-16T13:16:09Z</dc:date>
    <item>
      <title>Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486891#M1084384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm looking into a issue where no connection events are shown in the FMC event viewer despite the configuration of the ASA and FMC looking good:&lt;/P&gt;&lt;P&gt;ASA5515 running&amp;nbsp;9.12(3)12&lt;/P&gt;&lt;P&gt;SFR module running 6.4.0.9&lt;/P&gt;&lt;P&gt;FMCv running 6.4.0.9&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Service policy is configured in fail-open monitor-only mode and I see packets incrementing:&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp; class sfr_map&lt;BR /&gt;&amp;nbsp; &amp;nbsp; sfr fail-open monitor-only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW# show service-policy sfr&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;Service-policy: global_policy&lt;BR /&gt;Class-map: sfr_map&lt;BR /&gt;SFR: card status Up, mode fail-open monitor-only&lt;BR /&gt;packet input 0, packet output 102498529867, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;There is an any any MONITOR rule at the top of the ACP but I see absolutely no events in the event viewer on the FMC. I'm really struggling to figure out why nothing is being logged.&lt;/P&gt;&lt;P&gt;Can anyone suggest what to look at??&lt;/P&gt;&lt;P&gt;Many thanks in advance,&lt;/P&gt;&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 11:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486891#M1084384</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-15T11:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486893#M1084385</link>
      <description>&lt;P&gt;Does your rule in the ACP have logging turned on? It's off by default.&lt;/P&gt;
&lt;P&gt;If that's OK then check the clock on both the ASA and FMC to ensure they match. The Firepower service module will take its clock time from the ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:00:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486893#M1084385</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-15T12:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486896#M1084386</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thank you for the response. ACP rule does have logging enabled. Looks like the timezones are different:&lt;/P&gt;&lt;P&gt;FW# show clock&lt;BR /&gt;13:01:34.359 GMT/BDT Fri Oct 15 2021&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&amp;gt; show time&lt;BR /&gt;UTC - Fri Oct 15 12:01:36 UTC 2021&lt;BR /&gt;Localtime - Fri Oct 15 08:01:37 EDT 2021&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think this could be part of the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486896#M1084386</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-15T12:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486908#M1084388</link>
      <description>&lt;P&gt;The time zone &lt;EM&gt;shouldn't&lt;/EM&gt; affect the logging as events are sent with UTC timestamps and adjusted per the timezone of the user's settings in FMC.&lt;/P&gt;
&lt;P&gt;Has this ever worked? Is it the only managed device in your FMC?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486908#M1084388</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-15T12:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486913#M1084391</link>
      <description>&lt;P&gt;OK cool. I don't believe this has ever worked, no.&lt;/P&gt;&lt;P&gt;There are 2 ASAs configured as an active/standby pair.&lt;/P&gt;&lt;P&gt;Both FPR modules are known by the FMC but only these two, nothing else.&lt;/P&gt;&lt;P&gt;Any chance some old module config on the ASA for IPS and CXSC could be causing an issue?:&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;FW# sh run&lt;BR /&gt;service-module 0 keepalive-timeout 4&lt;BR /&gt;service-module 0 keepalive-counter 6&lt;BR /&gt;service-module ips keepalive-timeout 4&lt;BR /&gt;service-module ips keepalive-counter 6&lt;BR /&gt;service-module cxsc keepalive-timeout 4&lt;BR /&gt;service-module cxsc keepalive-counter 6&lt;BR /&gt;service-module sfr keepalive-timeout 4&lt;BR /&gt;service-module sfr keepalive-counter 6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;bdavpn# show module&lt;/P&gt;&lt;P&gt;Mod Card Type Model Serial No.&lt;BR /&gt;---- -------------------------------------------- ------------------ -----------&lt;BR /&gt;0 ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5515 FCH19257K3C&lt;BR /&gt;ips Unknown N/A FCH19419K3D&lt;BR /&gt;cxsc Unknown N/A FCH19419K3D&lt;BR /&gt;sfr FirePOWER Services Software Module ASA5515 FCH19419K3D&lt;/P&gt;&lt;P&gt;Mod MAC Address Range Hw Version Fw Version Sw Version&lt;BR /&gt;---- --------------------------------- ------------ ------------ ---------------&lt;BR /&gt;0 188b.9d72.9b38 to 188b.9d72.9b3f 1.0 2.1(9)8 9.12(3)12&lt;BR /&gt;ips 188b.9d72.9b36 to 188b.9d72.9b36 N/A N/A&lt;BR /&gt;cxsc 188b.9d72.9b36 to 188b.9d72.9b36 N/A N/A&lt;BR /&gt;sfr 188b.9d72.9b36 to 188b.9d72.9b36 N/A N/A 6.4.0.9-62&lt;/P&gt;&lt;P&gt;Mod SSM Application Name Status SSM Application Version&lt;BR /&gt;---- ------------------------------ ---------------- --------------------------&lt;BR /&gt;ips Unknown No Image Present Not Applicable&lt;BR /&gt;cxsc Unknown No Image Present Not Applicable&lt;BR /&gt;sfr ASA FirePOWER Up 6.4.0.9-62&lt;/P&gt;&lt;P&gt;Mod Status Data Plane Status Compatibility&lt;BR /&gt;---- ------------------ --------------------- -------------&lt;BR /&gt;0 Up Sys Not Applicable&lt;BR /&gt;ips Unresponsive Not Applicable&lt;BR /&gt;cxsc Unresponsive Not Applicable&lt;BR /&gt;sfr Up Up&lt;/P&gt;&lt;P&gt;Mod License Name License Status Time Remaining&lt;BR /&gt;---- -------------- --------------- ---------------&lt;BR /&gt;ips IPS Module Disabled perpetual&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4486913#M1084391</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-15T12:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487039#M1084393</link>
      <description>&lt;P&gt;The old modules types are not installed - they're only listed in the output for consistency across older and newer ASAs.&lt;/P&gt;
&lt;P&gt;Do you have your class-map defined?&lt;/P&gt;
&lt;P&gt;"show run class-map sfr_map" will give us that info.&lt;/P&gt;
&lt;P&gt;By the way, it should pretty much follow this guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc12&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 17:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487039#M1084393</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-15T17:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487280#M1084410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you again for your suggestions. Today we carried out some testing:&lt;/P&gt;&lt;P&gt;In the applied ACP, I added a specific block rule from x.x.x.x to y.y.y.y and observed that this &lt;EM&gt;&lt;STRONG&gt;DID&lt;/STRONG&gt; &lt;/EM&gt;block the traffic flow so I know that the traffic is punted up from the ASA to the SFR module and the SFR module is doing what it's supposed to do.&lt;/P&gt;&lt;P&gt;However, despite logging being enabled on that rule to both the FMC event viewer and also a syslog server, we did not see any events logged.&lt;/P&gt;&lt;P&gt;I can also see from the output of "show access-control-config" that there are hits against the rule and confirmation that logging is enabled:&lt;/P&gt;&lt;P&gt;####################################################################&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;===============[ Rule Set: (User) ]================&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;--------------[ Rule: matt-allow-any ]--------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Action : Allow&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Intrusion Policy : Matt-IPS-Policy&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; ISE Metadata :&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Logging Configuration&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DC : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; Beginning : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; End : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; Files : Disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Safe Search : No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Rule Hits : &lt;FONT color="#FF0000"&gt;48287&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Variable Set : Matt-Variable-Set&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;####################################################################&lt;/P&gt;&lt;P&gt;One thing that is odd is that sometimes when I run "show summary", it says "Access control policy not yet applied." but then after I execute "show access-control-config", the output of "show summary" then changes to be what you'd expect (policy info, plus list of interfaces).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host discover is correctly configured but there are no hosts listed in the network map.&lt;/P&gt;&lt;P&gt;There is "No data" listed in any of the traffic related dashboard widgets in the FMC.&lt;/P&gt;&lt;P&gt;We tried rebooting the FMC - no change.&lt;/P&gt;&lt;P&gt;We tried rebooting the SFR module - no change.&lt;/P&gt;&lt;P&gt;I'm out of ideas here, it's driving me crazy! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any help that you, or anybody else can provide is very much appreciated. I'm running out of hair to pull out here!&lt;/P&gt;&lt;P&gt;Many thanks,&lt;BR /&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 13:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487280#M1084410</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-16T13:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487812#M1084430</link>
      <description>&lt;P&gt;I know you said that logging is enabled, but could you verify that logging to Event Viewer is enabled under logging on the ACP rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 09:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487812#M1084430</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-10-18T09:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487823#M1084432</link>
      <description>&lt;P&gt;Thank you for your suggestion&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;.&amp;nbsp;I can confirm that logging to event viewer is enabled under logging on the ACP rule.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 09:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4487823#M1084432</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-18T09:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4489697#M1084528</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Anybody got any ideas on this?&lt;/P&gt;&lt;P&gt;Unfortunately the kit is not under TAC support at this time otherwise I'd be raising a case. I've asked the customer to look into getting TAC support but in the meantime, I'm thinking this must be either a bug or some sort of corruption of a database somewhere as I'm fairly sure the config is good?&lt;/P&gt;&lt;P&gt;I've read things about corruption occurring if you make certain changes through expert mode CLI (like clock or NTP changes for example).&lt;/P&gt;&lt;P&gt;I'm wondering if there is any way to prove this as the cause or to rule it out?&lt;/P&gt;&lt;P&gt;Would I be right in thinking that all the event logging from the FPR module to the FMC goes via the SF_tunnel so I wouldn't be able to verify if events are being sent from the module or received at the FMC as it's all encrypted?&lt;/P&gt;&lt;P&gt;Finally, what about next step assuming we can't get TAC support? I'm thinking:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Upgrade the firepower modules to the latest supported &amp;amp; compatible image (not sure this will fix any corruption of FPR DBs??)&lt;/LI&gt;&lt;LI&gt;Upgrade the ASAs to the&amp;nbsp;latest supported &amp;amp; compatible image&lt;/LI&gt;&lt;LI&gt;Perform a full reimage on the Firepower modules using the latest version&lt;/LI&gt;&lt;LI&gt;Build a new FMCv to replace the existing FMCv in case there is some corruption on the FMC?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 08:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4489697#M1084528</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-10-21T08:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4490250#M1084553</link>
      <description>&lt;P&gt;If this is a new setup then I would go with your suggestion #4 and #3 in that order.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 03:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4490250#M1084553</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-10-22T03:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower SFR Module - No connection events in FMC event viewer?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4504247#M1085157</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Solution (from TAC) to this was as follows just in case it help anyone else in the future...&lt;/P&gt;&lt;P&gt;=============================&lt;/P&gt;&lt;P&gt;-Checked the FMC messages:&lt;/P&gt;&lt;P&gt;Nov 17 12:07:38 firepower SF-IMS[11905]: [11905] SFDataCorrelator:RNAEventDatabase [ERROR] failed to initialize rna_flow_stats table&lt;/P&gt;&lt;P&gt;Nov 17 12:07:38 firepower SF-IMS[11905]: [11905] SFDataCorrelator:SFDataCorrelator [ERROR] Failed to initialize the dispatcher: Unhandled database error&lt;/P&gt;&lt;P&gt;Nov 17 12:08:39 firepower SF-IMS[12106]: [12106] SFDataCorrelator:RNAEventDatabase [ERROR] failed to initialize rna_flow_stats table&lt;/P&gt;&lt;P&gt;Nov 17 12:08:39 firepower SF-IMS[12106]: [12106] SFDataCorrelator:SFDataCorrelator [ERROR] Failed to initialize&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Checked similar cases and found that the command to repair:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:root@firepower:/var/log" target="_blank"&gt;root@firepower:/var/log#repair_table.pl&lt;/A&gt; -arms --optimize rna_flow_stats&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Checked the SFDataCorrelator:&lt;/P&gt;&lt;P&gt;&amp;nbsp;root@firepower:/var/log# pmtool status | egrep -i sfdata&lt;/P&gt;&lt;P&gt;SFDataCorrelator (normal) - &lt;U&gt;Running 15612&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- The SFDataCorrelator is running and the FMC GUI is showing data&lt;/P&gt;&lt;P&gt;=============================&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 14:25:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-sfr-module-no-connection-events-in-fmc-event-viewer/m-p/4504247#M1085157</guid>
      <dc:creator>mattw</dc:creator>
      <dc:date>2021-11-17T14:25:51Z</dc:date>
    </item>
  </channel>
</rss>

