<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1120: sftunnel-status connection never happened after re in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4681013#M1093158</link>
    <description>&lt;P&gt;Been a long time since this update, but it helped me get my Firepower 1010 back online with FMC.&lt;/P&gt;&lt;P&gt;Turns out the 1010 thought it was the year 2034 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;sftunnel_status.pl&lt;/P&gt;&lt;P&gt;SFTUNNEL Start Time: Mon Sep 4 22:01:57 2034&lt;/P&gt;&lt;P&gt;Set the time per this post with:&amp;nbsp;date -s "Mon Sep 4 22:14:00 UTC 2022"&lt;/P&gt;&lt;P&gt;then I restarted the sftunnel process on the 1010:&amp;nbsp;# pmtool restartbyid sftunnel&lt;/P&gt;&lt;P&gt;and it worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 Sep 2022 22:16:52 GMT</pubDate>
    <dc:creator>Skjalg Eggen</dc:creator>
    <dc:date>2022-09-04T22:16:52Z</dc:date>
    <item>
      <title>Firepower 1120: sftunnel-status connection never happened after reboot</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4484297#M1084311</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after an electrical maintanance, our FTD is no longer registrated to FMC, thought was due to this bug:&amp;nbsp;&lt;SPAN&gt;CSCvs98328&amp;nbsp;&lt;/SPAN&gt;, but as you can see, even forcing the correct ntp it is still reporting :"&lt;STRONG&gt;Connection to peer '10.1.1.1' never happened&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;The managers have been correctly added with the "configure manager add" command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Firepower 1120 Threat Defense v6.6.4 (build 64)&lt;/P&gt;&lt;P&gt;&amp;gt; show managers&lt;/P&gt;&lt;P&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Manager&lt;/P&gt;&lt;P&gt;Host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10.1.1.1&lt;/P&gt;&lt;P&gt;Registration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Completed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Manager&lt;/P&gt;&lt;P&gt;Host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10.1.1.2&lt;/P&gt;&lt;P&gt;Registration&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: Completed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;trying to force ntp as per&amp;nbsp;&lt;SPAN&gt;CSCvs98328:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;root@-FW:/home/admin# ntpdate -u internalt.ntp.org&lt;/P&gt;&lt;P&gt;5 Oct 09:39:09 ntpdate[15009]: step time server &lt;A href="https://protect-eu.mimecast.com/s/1NhzClOZNFX7y7DYuVlqwB?domain=185.157.229.254" target="_blank" rel="noopener"&gt;xx.xxx.xxx.xxx&lt;/A&gt; offset -36.7659 sec&lt;/P&gt;&lt;P&gt;root@-FW:/home/admin# date&lt;/P&gt;&lt;P&gt;Tue Oct&amp;nbsp; 5 09:39:19 UTC 2021&lt;/P&gt;&lt;P&gt;root@-FW:/home/admin# pmtool restartbyid sftunnel&lt;/P&gt;&lt;P&gt;root@-FW:/home/admin# exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;STRONG&gt;sftunnel-status&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SFTUNNEL Start Time: Tue Oct&amp;nbsp; 5 09:40:02 2021&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Both IPv4 and IPv6 connectivity is supported&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Broadcast count = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reserved SSL connections: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Management Interfaces: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; management0 (control events) 10.1.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;**RUN STATUS****10.1.1.1*************&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Connected: No&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Verification status: ok&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Registration: Completed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Connection to peer '10.1.1.1' never happened&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Connection to peer '10.1.1.1' Attempted at Tue Oct&amp;nbsp; 5 09:40:15 2021&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have any suggestions to solve this problem?&lt;/P&gt;&lt;P&gt;both ftd and fmc are version 6.6.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 08:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4484297#M1084311</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2021-10-12T08:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: sftunnel-status connection never happened after re</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4485005#M1084327</link>
      <description>&lt;P&gt;I see you have got FMC HA by any chance is 10.1.1.2 the active FMC.&lt;/P&gt;
&lt;P&gt;How does the GUI looks like on FMC, are you getting alerts on FMC for appliance heartbeats?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chakshu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 06:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4485005#M1084327</guid>
      <dc:creator>Chakshu Piplani</dc:creator>
      <dc:date>2021-10-13T06:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: sftunnel-status connection never happened after re</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4485071#M1084328</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Chakshu,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;yes we have fmc ha, in the gui we see heartbeats error, the strange thing is that the ftd is reachable via ssh, but e.g if we deploy a new policy, it fails due to the sftunnel down.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i've also tried this procedure with no results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; expert&lt;BR /&gt;admin@FTDv:~$ sudo su&lt;BR /&gt;Password:&lt;BR /&gt;root@FTDv:/home/admin# manage_procs.pl&lt;BR /&gt;****************&amp;nbsp; Configuration Utility&amp;nbsp; **************&lt;BR /&gt;1&amp;nbsp;&amp;nbsp; Reconfigure Correlator&lt;BR /&gt;2&amp;nbsp;&amp;nbsp; Reconfigure and flush Correlator&lt;BR /&gt;3&amp;nbsp;&amp;nbsp; Restart Comm. channel&lt;BR /&gt;4&amp;nbsp;&amp;nbsp; Update routes&lt;BR /&gt;5&amp;nbsp;&amp;nbsp; Reset all routes&lt;BR /&gt;6&amp;nbsp;&amp;nbsp; Validate Network&lt;BR /&gt;0&amp;nbsp;&amp;nbsp; Exit&lt;BR /&gt;**************************************************************&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 07:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4485071#M1084328</guid>
      <dc:creator>MaErre21325</dc:creator>
      <dc:date>2021-10-13T07:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: sftunnel-status connection never happened after re</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4610844#M1090108</link>
      <description>&lt;P&gt;Hello All&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have a very similar issue to the above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FMC/FTD 1120 code 6.6.5 running HA&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; sftunnel-status&lt;/P&gt;
&lt;P&gt;SFTUNNEL Start Time: Mon May 16 12:11:48 2022&lt;/P&gt;
&lt;P&gt;Both IPv4 and IPv6 connectivity is supported&lt;BR /&gt;Broadcast count = 1&lt;BR /&gt;Reserved SSL connections: 0&lt;BR /&gt;Management Interfaces: 1&lt;BR /&gt;management0 (control events) 10.10.10.10,&lt;/P&gt;
&lt;P&gt;***********************&lt;/P&gt;
&lt;P&gt;**RUN STATUS****10.10.10.10*************&lt;BR /&gt;Connected: No&lt;BR /&gt;SSL Verification status: ok&lt;BR /&gt;Registration: Completed.&lt;BR /&gt;Connection to peer '10.10.10.10' never happened&lt;BR /&gt;Connection to peer '10.10.10.10' Attempted at Mon May 16 12:23:23 2022&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;**RPC STATUS****10.10.10.10*************&lt;BR /&gt;RPC status :Failed&lt;BR /&gt;Check routes:&lt;BR /&gt;No peers to check&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Running the below on the FTD or FMC makes no difference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt; expert&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;admin@FTDv:~$ sudo su&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Password:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;root@FTDv:/home/admin# manage_procs.pl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;****************&amp;nbsp; Configuration Utility&amp;nbsp; **************&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1&amp;nbsp;&amp;nbsp; Reconfigure Correlator&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2&amp;nbsp;&amp;nbsp; Reconfigure and flush Correlator&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3&amp;nbsp;&amp;nbsp; Restart Comm. channel&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4&amp;nbsp;&amp;nbsp; Update routes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5&amp;nbsp;&amp;nbsp; Reset all routes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6&amp;nbsp;&amp;nbsp; Validate Network&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0&amp;nbsp;&amp;nbsp; Exit&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;**************************************************************&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This was following a power cut and the time/date was way out on the primary unit JAN 2015&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I managed to bring the time closer via expert mode:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;date -s "16 MAY 2022 11:00:00"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Time looks acceptable now however the SFtunnel remains down .....I was going to reboot FTD / FMC again following the time change but are there any other suggestions?&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unable to perform anything on the managed FTD at this stage,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&amp;nbsp;&lt;BR /&gt;#TCN&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 12:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4610844#M1090108</guid>
      <dc:creator>#TCN</dc:creator>
      <dc:date>2022-05-16T12:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: sftunnel-status connection never happened after re</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4681013#M1093158</link>
      <description>&lt;P&gt;Been a long time since this update, but it helped me get my Firepower 1010 back online with FMC.&lt;/P&gt;&lt;P&gt;Turns out the 1010 thought it was the year 2034 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;sftunnel_status.pl&lt;/P&gt;&lt;P&gt;SFTUNNEL Start Time: Mon Sep 4 22:01:57 2034&lt;/P&gt;&lt;P&gt;Set the time per this post with:&amp;nbsp;date -s "Mon Sep 4 22:14:00 UTC 2022"&lt;/P&gt;&lt;P&gt;then I restarted the sftunnel process on the 1010:&amp;nbsp;# pmtool restartbyid sftunnel&lt;/P&gt;&lt;P&gt;and it worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Sep 2022 22:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-sftunnel-status-connection-never-happened-after/m-p/4681013#M1093158</guid>
      <dc:creator>Skjalg Eggen</dc:creator>
      <dc:date>2022-09-04T22:16:52Z</dc:date>
    </item>
  </channel>
</rss>

