<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to add FTD into FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505594#M1085232</link>
    <description>&lt;P&gt;ping is not good enough, if FMC behind FW you need make sure the ports are opened between FTD and FMC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="ID-2202-000000dc__ID-2202-00000127" class="table table--pgwide-1" border="1" width="100%"&gt;&lt;CAPTION&gt;&lt;FONT color="#000000"&gt;&lt;SPAN class="table--title-label tabletitle"&gt;Table 2. &lt;/SPAN&gt;&lt;SPAN class="tabletitle"&gt;Firepower Communication Port Requirements ( bottom of the table)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/CAPTION&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Security__Internet_Access__and_Communication_Ports.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Security__Internet_Access__and_Communication_Ports.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Nov 2021 14:06:43 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-11-19T14:06:43Z</dc:date>
    <item>
      <title>Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505586#M1085231</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently unable to add FTD into FMC, each attempt it comes out with error message&amp;nbsp; host x.x.x.x is not reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- FMC in Europe, FTD in China.&lt;/P&gt;&lt;P&gt;- The FMC ping successfully FTD and vice versa.&lt;/P&gt;&lt;P&gt;- I did&amp;nbsp;configure network management-data-interface.&lt;/P&gt;&lt;P&gt;- Devices not behind NAT so this setting was skipped.&lt;/P&gt;&lt;P&gt;- The FMC has other FTD running without any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt; show managers&lt;/STRONG&gt;&lt;BR /&gt;Host : x.x.x.x&lt;BR /&gt;Registration Key : ****&lt;BR /&gt;Registration : pending&lt;BR /&gt;RPC Status :&lt;BR /&gt;Type : Manager&lt;BR /&gt;Host : x.x.x.x&lt;BR /&gt;Registration : Pending&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt; sftunnel-status&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SFTUNNEL Start Time: Fri Nov 19 07:59:07 2021&lt;/P&gt;&lt;P&gt;Both IPv4 and IPv6 connectivity is supported&lt;BR /&gt;Broadcast count = 0&lt;BR /&gt;Reserved SSL connections: 0&lt;BR /&gt;Management Interfaces: 2&lt;BR /&gt;br1 (control events) x.x.x.x,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 13:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505586#M1085231</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T13:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505594#M1085232</link>
      <description>&lt;P&gt;ping is not good enough, if FMC behind FW you need make sure the ports are opened between FTD and FMC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="ID-2202-000000dc__ID-2202-00000127" class="table table--pgwide-1" border="1" width="100%"&gt;&lt;CAPTION&gt;&lt;FONT color="#000000"&gt;&lt;SPAN class="table--title-label tabletitle"&gt;Table 2. &lt;/SPAN&gt;&lt;SPAN class="tabletitle"&gt;Firepower Communication Port Requirements ( bottom of the table)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/CAPTION&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Security__Internet_Access__and_Communication_Ports.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Security__Internet_Access__and_Communication_Ports.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505594#M1085232</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-19T14:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505595#M1085233</link>
      <description>&lt;P&gt;SFtunnel port 8305 is open. From documentation that should be the one opened.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:09:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505595#M1085233</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T14:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505615#M1085235</link>
      <description>&lt;P&gt;Can you telnet using tcp 8305 in both directions? Both the FMC and managed device need to be able to initiate traffic.&lt;/P&gt;
&lt;P&gt;Note China may be blocking the traffic. You can do a packet capture on your FMC to check if the incoming attempts are reaching it. Just use tcpdump from expert mode cli as root user and filter on the FTD host address in the capture.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505615#M1085235</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-11-19T14:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505642#M1085238</link>
      <description>&lt;P&gt;ftd-1 SF-IMS[8257]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8256] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;BR /&gt;ftd-1 SF-IMS[8313]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8312] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [INFO] Default IPv4 gateway for 'br1' not configured.&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [INFO] Adding default IPv4 gateway '1.1.1.1' for 'br1'.&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [WARN] Command '/sbin/ip route add default via 1.1.1.1 dev br1' returned 512.&lt;BR /&gt;ftd-1 sudo:root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/bin/pgrep -x snort&lt;BR /&gt;ftd-1 sudo:root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/bin/pgrep -x sfhassd&lt;BR /&gt;ftd-1 SF-IMS[24318]: [24318] sftunneld:SYNC_PROC [INFO] Change in directory /ngfw/var/sf/sync detected (0 vs 1637287229)&lt;BR /&gt;ftd-1 SF-IMS[8502]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8501] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;BR /&gt;ftd-1 SF-IMS[8544]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8543] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 15:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505642#M1085238</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T15:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505695#M1085240</link>
      <description>&lt;P&gt;ftd-1 SF-IMS[8257]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8256] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;BR /&gt;ftd-1 SF-IMS[8313]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [INFO] Default IPv4 gateway for 'br1' not configured.&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [INFO] Adding default IPv4 gateway '1.1.1.1' for 'br1'.&lt;BR /&gt;ftd-1 SF-IMS[25430]: [25430] sfifd:sfifd [WARN] Command '/sbin/ip route add default via 1.1.1.1 dev br1' returned 512.&lt;BR /&gt;ftd-1 sudo:root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/bin/pgrep -x snort&lt;BR /&gt;ftd-1 sudo:root : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/bin/pgrep -x sfhassd&lt;BR /&gt;ftd-1 SF-IMS[24318]: [24318] sftunneld:SYNC_PROC [INFO] Change in directory /ngfw/var/sf/sync detected (0 vs 1637287229)&lt;BR /&gt;ftd-1 SF-IMS[8502]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;BR /&gt;ftd-1 SF-IMS[24319]: [8501] sfmgr:rexecchild [INFO] Before setting the value to 2, patience = 9&lt;BR /&gt;ftd-1 SF-IMS[8544]: SF-RPC:RemoteRun [CRITICAL] Unauthorized RPC call:SF::PeerManager::getPeerInfoLocal from fmc.net role:nobody%0A&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 15:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505695#M1085240</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T15:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505710#M1085241</link>
      <description>&lt;P&gt;From FTD to FMC:&lt;BR /&gt;admin@:~$ ssh 4.1.1.1 8305&lt;BR /&gt;Password:&lt;/P&gt;&lt;P&gt;From FMC to FTD:&lt;BR /&gt;root@:~# ssh 5.2.2.2 8305&lt;/P&gt;&lt;P&gt;ssh: connect to host 5.2.2.2 port 22: Connection timed out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried with ssh both directions it seems there is an issue from FMC to FTD.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 15:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505710#M1085241</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T15:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505725#M1085243</link>
      <description>&lt;PRE&gt;From FMC to FTD:
root@:~# ssh 5.2.2.2 8305

ssh: connect to host 5.2.2.2 port 22: Connection timed out


Tried with ssh both directions it seems there is an issue from FMC to FTD.&lt;/PRE&gt;
&lt;P&gt;Now you know where to look and fix the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 16:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505725#M1085243</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-19T16:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505808#M1085245</link>
      <description>&lt;P&gt;After reviewing I have detected there was a NAT device on the path, despite being told that there isn't. Configuration where done accordingly. Now it works fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 18:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4505808#M1085245</guid>
      <dc:creator>BmfL</dc:creator>
      <dc:date>2021-11-19T18:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to add FTD into FMC</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4507294#M1085323</link>
      <description>&lt;P&gt;Glad you able to resolve the issue, and thank you for sharing your feedback, we mark this as a solution now.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 17:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-add-ftd-into-fmc/m-p/4507294#M1085323</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-23T17:42:38Z</dc:date>
    </item>
  </channel>
</rss>

