<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD not connecting to FMC after Re-IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718256#M1094885</link>
    <description>&lt;P&gt;The FTD still shows the FMC as the current manager.&amp;nbsp; So correct me if I am wrong here.&amp;nbsp; But if I delete the current manager it will wipe the configuration on the FTD.&amp;nbsp; I will loose connectivity and drop all user traffic.&amp;nbsp; This should not change the management of the device so I should be able to still SSH to the FTD using the outside interface .&amp;nbsp; Then I connect the FTD again to the FMC by running the "connect manager add&amp;nbsp; x.x.x.x&amp;nbsp; &amp;lt;pass&amp;gt;" command.&amp;nbsp; This is where I cannot find any documentation on how to associate the existing configuration back to the device.&amp;nbsp; Should it pick it up automatically or is there a step i am missing here.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 21:03:06 GMT</pubDate>
    <dc:creator>keibler</dc:creator>
    <dc:date>2022-11-08T21:03:06Z</dc:date>
    <item>
      <title>FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718209#M1094879</link>
      <description>&lt;P&gt;We had to change the outside interface IP of a remote office FTD that was connected to a central FMC.&amp;nbsp; After changing the IP the FTD does not want to reconnect to the FMC.&amp;nbsp; The network objects were updated to the new IP address (for NAT, Policies, etc..), device IP was changed under device management on the FMC,&amp;nbsp; and the IP was changed on the FTD.&amp;nbsp; &amp;nbsp;I am able login to the the remote FTD via SSH from the central site.&amp;nbsp; Any suggestions what to look out would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 20:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718209#M1094879</guid>
      <dc:creator>keibler</dc:creator>
      <dc:date>2022-11-08T20:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718213#M1094880</link>
      <description>&lt;P&gt;if the IP changed you need to de-register and&amp;nbsp; re-register&lt;/P&gt;
&lt;P&gt;check on FTD or FMC&lt;/P&gt;
&lt;P&gt;&amp;gt; show managers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 20:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718213#M1094880</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-08T20:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718256#M1094885</link>
      <description>&lt;P&gt;The FTD still shows the FMC as the current manager.&amp;nbsp; So correct me if I am wrong here.&amp;nbsp; But if I delete the current manager it will wipe the configuration on the FTD.&amp;nbsp; I will loose connectivity and drop all user traffic.&amp;nbsp; This should not change the management of the device so I should be able to still SSH to the FTD using the outside interface .&amp;nbsp; Then I connect the FTD again to the FMC by running the "connect manager add&amp;nbsp; x.x.x.x&amp;nbsp; &amp;lt;pass&amp;gt;" command.&amp;nbsp; This is where I cannot find any documentation on how to associate the existing configuration back to the device.&amp;nbsp; Should it pick it up automatically or is there a step i am missing here.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 21:03:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718256#M1094885</guid>
      <dc:creator>keibler</dc:creator>
      <dc:date>2022-11-08T21:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718352#M1094899</link>
      <description>&lt;P&gt;Removing manager and adding back will not have any impact on the traffic. but from FMC you able to push changes (any way its not working for you now)&lt;/P&gt;
&lt;P&gt;Most of the config is stored in FMC, so once it registers you can make changes, no config will be lost.&lt;/P&gt;
&lt;P&gt;But saying that 1 in 10000 may have a different issue ( so from FMC backup the config out of the box)&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 23:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718352#M1094899</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-08T23:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718642#M1094943</link>
      <description>&lt;P&gt;Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;I tried that this morning and I am still having some issues on this remote ftd to get it reconnect.&amp;nbsp; I removed the manager.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure manager delete&lt;/LI-CODE&gt;&lt;P&gt;Then added the manager again&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure manager add x.y.z.83 JoinMe JoinMe&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show managers
Host                      : x.y.z.83
Registration Key          : ****
Registration              : pending
RPC Status                :
&amp;gt; show managers
Host                      : x.y.z.83
Registration Key          : ****
Registration              : pending
RPC Status                :&lt;/LI-CODE&gt;&lt;P&gt;When I enable the existing device it errors with timeout.&amp;nbsp; When I try and add the device it tells me that that the time is not synced.&amp;nbsp; the FMC is configured for NTP. I also validated the time on the FTD and it is within 1 second.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; sftunnel-status

SFTUNNEL Start Time: Wed Nov  9 13:15:15 2022

        Both IPv4 and IPv6 connectivity is supported
        Broadcast count = 1
        Reserved SSL connections: 1
        Management Interfaces: 2
        management0 (control events) 192.168.98.3,
        tap0.1000 (control events) 169.254.1.3,fd00:0:0:1::3

***********************
peer ~JoinMe did not reply at /usr/local/sf/bin/sftunnel_status.pl line 304.
Retry rpc status poll at /usr/local/sf/bin/sftunnel_status.pl line 310.

**RPC STATUS****x.y.z.83*************
RPC status :Failed
Check routes:
No peers to check&lt;/LI-CODE&gt;&lt;P&gt;Again this is a remote site and the FMC is configured with a NAT that was previously working to the remote site&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 13:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718642#M1094943</guid>
      <dc:creator>keibler</dc:creator>
      <dc:date>2022-11-09T13:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718747#M1094951</link>
      <description>&lt;P&gt;You need to remove both the sides is best to re-register.&lt;/P&gt;
&lt;P&gt;if this was natted then you need to change NAT with new IP address to translate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 15:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718747#M1094951</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-09T15:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718898#M1094963</link>
      <description>&lt;P&gt;No luck.&amp;nbsp; Same error&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Could not establish connection with Device
Possible reasons could be:-

- Time on FMC and Device are not in sync. Make sure NTP is configured on both.
- There might be an IPS device between FMC/Device which might be blocking SSL connectivity between the two. Remove any rule in the IPS device which is blocking SSL connectivity.
- Device and FMC are not listening on same sftunnel Port. Current sftunnel port configured on FMC is 8305, please ensure Device is also using the same port.
- SSL certificates might have got generated with wrong/future time stamp.

For more troubleshooting tips, see https://cisco.com/go/fmc-reg-error&lt;/LI-CODE&gt;&lt;P&gt;NAT was updated when I updated the Network Object for the the FTDs outside interface.&amp;nbsp;I am seeing NAT translations, packets both inbound &amp;amp; outbound on the packet capture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FMC IP did not change.&amp;nbsp; I tried with "Unique NAT ID" and not.&amp;nbsp; &amp;nbsp;Also tried with using the "configure manager add DONTRESOLVE &amp;lt;key&amp;gt; &amp;lt;natID&amp;gt;".&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which leads maybe to the way I changed the IP address.&amp;nbsp; The outbound (outside) interface is Ethe1/1.&amp;nbsp; Here is the output of the show network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : lynn00-ftdcx01&lt;BR /&gt;DNS Servers : 208.67.222.222&lt;BR /&gt;208.67.220.220&lt;BR /&gt;2620:119:35::35&lt;BR /&gt;DNS from router : enabled&lt;BR /&gt;Management port : 8305&lt;BR /&gt;IPv4 Default route&lt;BR /&gt;Gateway : 192.168.98.1&amp;nbsp; &amp;nbsp; &amp;lt;-this is the inside address&lt;BR /&gt;Netmask : 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;==================[ management0 ]===================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Link : Up&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : &amp;lt;removed&amp;gt;&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.98.3&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Gateway : 192.168.98.1&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;&lt;P&gt;======[ System Information - Data Interfaces ]======&lt;BR /&gt;DNS Servers :&lt;BR /&gt;Interfaces : Ethernet1/1&lt;/P&gt;&lt;P&gt;==================[ Ethernet1/1 ]===================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Link : Up&lt;BR /&gt;Name : lyn_outside&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : &amp;lt;removed&amp;gt;&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : x.y.z.38&lt;BR /&gt;Netmask : 255.255.255.240&lt;BR /&gt;Gateway : x.y.z.33&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 19:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718898#M1094963</guid>
      <dc:creator>keibler</dc:creator>
      <dc:date>2022-11-09T19:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718959#M1094966</link>
      <description>&lt;P&gt;Have you had a look at the logs in&amp;nbsp;&lt;SPAN&gt;/ngfw/var/log/messages ?&amp;nbsp; There might be a clue as to why registration is failing there.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 22:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4718959#M1094966</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-11-09T22:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4719225#M1094980</link>
      <description>&lt;P&gt;Since you mentioned NAT - never tested myself : check below threat has some information may help you&amp;nbsp; apart from suggestion made &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp; logs.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/connect-ftd-to-fmc-with-nat-at-both-sides/td-p/3726411" target="_blank"&gt;https://community.cisco.com/t5/network-security/connect-ftd-to-fmc-with-nat-at-both-sides/td-p/3726411&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 09:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4719225#M1094980</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-10T09:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD not connecting to FMC after Re-IP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4719365#M1094985</link>
      <description>I will check your recommendations on Monday&lt;BR /&gt;</description>
      <pubDate>Thu, 10 Nov 2022 15:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-not-connecting-to-fmc-after-re-ip/m-p/4719365#M1094985</guid>
      <dc:creator>keibler</dc:creator>
      <dc:date>2022-11-10T15:07:20Z</dc:date>
    </item>
  </channel>
</rss>

