<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD HA pair - interface changes detected after failover in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4918372#M1104034</link>
    <description>&lt;P&gt;Have you heard anything from TAC? Is it just a cosmetic or impacts devices after you deploy changes?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 21:25:12 GMT</pubDate>
    <dc:creator>dmitrykalinsky</dc:creator>
    <dc:date>2023-09-05T21:25:12Z</dc:date>
    <item>
      <title>FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4889635#M1102849</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I upgraded FMCv from 6.6.5 to 7.2.4. A few days later, my active-standby HA pair of FTD 6.6.5 devices failed over during resilience testing. FMC gave a health monitor alert about interface changes detected. In the Interface config screen for the HA pair,&amp;nbsp; I have a notice stating:&lt;BR /&gt;'Interface configuration has changed on device. Click to know more'&lt;BR /&gt;&lt;BR /&gt;Clicking takes me to an Interface Changes screen with a Validate Changes option. Validating gives:&lt;BR /&gt;'Changes validated successfully.&lt;BR /&gt;Close this window and click Save.'&lt;BR /&gt;&lt;BR /&gt;I'm nervous about making changes to the Device policy when I did not make any changes. Can anyone advise if this behaviour is seen after failover? Is it safe to Save the Device policy and Deploy or should I do something else (e.g. Sync Device)?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Piaras&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 11:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4889635#M1102849</guid>
      <dc:creator>plwalsh</dc:creator>
      <dc:date>2023-07-21T11:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4889951#M1102878</link>
      <description>&lt;P&gt;Are you by any chance managing 1000 or 2100 series FTD appliances?&lt;BR /&gt;I'm wondering since you were upgrading from pre 6.7, if it's possible you might be hitting bug&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa29956" target="_blank" rel="noopener"&gt;CSCwa29956&lt;/A&gt; ?&lt;BR /&gt;Could be if you can't clear the health alert.&lt;BR /&gt;(The workaround is "Contact TAC")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;It's supposed to be fixed in 7.2.0, but sometimes bug resurface.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 21:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4889951#M1102878</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2023-07-21T21:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4890154#M1102888</link>
      <description>&lt;P&gt;I also see this message from time to time, and also see it on FMC / FTD running 7.2.4.&amp;nbsp; The interfaces the message refers in my case are unused interfaces.&amp;nbsp; No changes have actually been made to them and when checking the audit logs it shows that the culprit is the "system" user.&amp;nbsp; I have not yet opened a TAC for this as it is purely cosmetic, but my best guess is that the FMC does some checks and through the process of these checks these messages appear.&lt;/P&gt;
&lt;P&gt;If the error is worrying you then I would suggest opening a TAC case as this most likely will require changes to a database or two.&amp;nbsp; But all in all, it is a cosmetic warning message, which arguably should not be there, and is safe to ignore so long as the interfaces being referred to are not in use.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 16:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4890154#M1102888</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-07-22T16:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4891207#M1102932</link>
      <description>&lt;P&gt;Hi Jonatan.&lt;BR /&gt;&lt;BR /&gt;I am managing 2100 devices and port-channels are configured on them. Port-channels configured on the device is one of the conditions for bug&amp;nbsp;CSCwa29956. I think a TAC call is warranted. Thank you for your reply.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Piaras&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 15:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4891207#M1102932</guid>
      <dc:creator>plwalsh</dc:creator>
      <dc:date>2023-07-24T15:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4897602#M1103182</link>
      <description>&lt;P&gt;Thank you for your reply Marius.&lt;BR /&gt;&lt;BR /&gt;I failed back my 6.6.5 FTD HA pair and again FMC 7.2.4 alerted to say device interfaces have changed, but there have been no changes. I think you are probably correct that this is a cosmetic bug but I am nervous to save the device policy in case it sets a 10GE etherchannel to 1GE or something else unexpected. I was surprised to see 7.2.4.1 that wa released last week, has so many bug fixes in it. Very odd considering 7.2 has been available for 2 years. I have opened a TAC case but no response yet as my issue is not urgent. I will update this topic once I hear from TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4897602#M1103182</guid>
      <dc:creator>plwalsh</dc:creator>
      <dc:date>2023-08-02T13:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4918372#M1104034</link>
      <description>&lt;P&gt;Have you heard anything from TAC? Is it just a cosmetic or impacts devices after you deploy changes?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 21:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4918372#M1104034</guid>
      <dc:creator>dmitrykalinsky</dc:creator>
      <dc:date>2023-09-05T21:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4918893#M1104055</link>
      <description>&lt;P&gt;Yes, I did. The bug seemed to be cosmetic - the interfaces had not changed. TAC had me:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;1) From the FTD interface menu, select Sync Device, confirm and Save changes and deploy&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2) enter the FMC CLI and use&amp;nbsp;OmniQuery.pl to identify the UUID of the amber interface alerts&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;3) delete any amber interface alerts identifed in 2) using&amp;nbsp;OmniQuery.pl&lt;BR /&gt;&lt;BR /&gt;The above steps cleared my amber interface alerts. Check with TAC if you have the same issue.&lt;BR /&gt;&lt;BR /&gt;I see 7.2.5 is now the recommended software. Maybe it fixes this bug/behaviour.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 12:05:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4918893#M1104055</guid>
      <dc:creator>plwalsh</dc:creator>
      <dc:date>2023-09-06T12:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: FTD HA pair - interface changes detected after failover</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4920361#M1104114</link>
      <description>&lt;P&gt;Hit the same bug on FMC7.2.4 and FPR2140 7.0.1 with two SFP ports in a port-channel.&lt;/P&gt;&lt;P&gt;The warning message was fixed by Cisco TAC using OmniQuery.pl (see the message from plwalsh) and the "&lt;SPAN&gt;Interface configuration has changed on device&lt;/SPAN&gt;" message was cleared by saving changes and deploying the config during off business hours. I didn't see a single drop.&lt;/P&gt;&lt;P&gt;Here is the change log after saving config on the Device&amp;gt;Interface page:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dmitrykalinsky_0-1694183588173.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/196670i2B3B11E9551D7765/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dmitrykalinsky_0-1694183588173.png" alt="dmitrykalinsky_0-1694183588173.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looks like FMC thought that the speed was 1000 and then discovered 10G from the device and wanted to save and implement the change.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 14:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ha-pair-interface-changes-detected-after-failover/m-p/4920361#M1104114</guid>
      <dc:creator>dmitrykalinsky</dc:creator>
      <dc:date>2023-09-08T14:34:54Z</dc:date>
    </item>
  </channel>
</rss>

