<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1120: FDM - unable to upgrade the cluster in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/5002542#M1108241</link>
    <description>&lt;P&gt;Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;after failover the &lt;SPAN&gt;wildcard certificate of 2023 was already there&amp;nbsp;for the&amp;nbsp;Management Web Server!&lt;BR /&gt;&lt;BR /&gt;After that I retried the upgrade and it worked even if it took much time.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot for your useful hints!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2024 13:51:53 GMT</pubDate>
    <dc:creator>swscco001</dc:creator>
    <dc:date>2024-01-22T13:51:53Z</dc:date>
    <item>
      <title>Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996615#M1107924</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;
&lt;P&gt;our customer has a cluster of two Firepower 1120 runnig rel. 7.3.0-69 with FDM.&lt;/P&gt;
&lt;P&gt;I wanted to upgrade the cluster to rel. 7.4.1.&lt;/P&gt;
&lt;P&gt;I downloaded the file from CCO and uploaded it to the standby device.&lt;/P&gt;
&lt;P&gt;There were no open deployments.&lt;/P&gt;
&lt;P&gt;The Readiness Check was successful.&lt;/P&gt;
&lt;P&gt;Then I started the upgrade and it took a pretty long time while counting&lt;BR /&gt;up the percentage of progress (see screen dumps).&lt;/P&gt;
&lt;P&gt;After the reboot the old 7.3.0-69 was booted again without any error message.&lt;/P&gt;
&lt;P&gt;I repeated the whole procedure once again but with the same result.&lt;/P&gt;
&lt;P&gt;The I performed a normal reboot but the standby device stayed at rel. 7.3.0-69.&lt;/P&gt;
&lt;P&gt;What could be the reason for this issue and what can be done to upgrade the &lt;BR /&gt;cluster.&lt;/P&gt;
&lt;P&gt;If you need any further information please let me know.&lt;/P&gt;
&lt;P&gt;Thanks a lot for every hint!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 08:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996615#M1107924</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-15T08:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996659#M1107927</link>
      <description>&lt;P&gt;In the cli expert mode, check under /ngfw/log/sf - you should see a folder there with the 7.4 upgrade designation. Within that folder, check status.log file for the last handful of entries (tail status.log) and share that output please.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 09:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996659#M1107927</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-01-15T09:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996812#M1107944</link>
      <description>&lt;P&gt;H Marvin,&lt;BR /&gt;&lt;BR /&gt;thanks for your fast reply!&lt;BR /&gt;&lt;BR /&gt;There is no folder&amp;nbsp;&lt;SPAN&gt;/ngfw/log/sf.&lt;BR /&gt;&lt;BR /&gt;I found the&amp;nbsp;/ngfw/var/log/sf with teh following content:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The date of the upgrade attempt was Jan. 12.&lt;BR /&gt;&lt;BR /&gt;I searched the whole system and found a status.log file with the following content:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;root@FW-Bermueller:/ngfw/var/log/sf# tail /opt/cisco/csp/applications/cisco-ftd.6.6.1.91__ftd_001_JMX2611X1S6O1OQB61/app_data/Volume/root2/ngfw/var/log/sf/Cisco_FTD_SSP_FP1K_Upgrade-7.4.1.1705079784.rollback/status.log
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/500_analysis_cleanup.pl)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/720_update_devices.pl)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/720_update_peers.pl)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/780_remove_future_flagsconf.pl)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/810_clean_upgrade_workflow.sh)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/810_update_ld_conf.sh)
ui: Upgrade in progress: (35% done.26 mins to reboot). Updating configurations... (800_post/850_clear_eula.sh)
ui: Upgrade in progress: (38% done.25 mins to reboot). Updating configurations... (800_post/870_update_fireamp_cert.sh)
ui: Upgrade in progress: (38% done.25 mins to reboot). Updating configurations... (800_post/880_install_VDB.sh (in background: 800_post/100_ftd_onbox_data_import.sh))
ui:__[] Fatal error: Upgrade Failed: The chosen certificate has already expired. Please apply an unexpired certificate.. Returning to previous version (7.3.0)...
&lt;/LI-CODE&gt;
&lt;P&gt;When I check the current wildcard certificate I see it is not expired yet (see attached screen dump).&lt;BR /&gt;&lt;BR /&gt;Do you have any idea how to get fixed this?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bye&lt;BR /&gt;R.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 13:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996812#M1107944</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-15T13:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996820#M1107947</link>
      <description>&lt;P&gt;Sorry about the path confusion. I was working from memory earlier. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The status.log file pinpoints the issue.&lt;/P&gt;
&lt;P&gt;It could be that your older wildcard or possibly the device self-signed certificate is still in use.Check your URL bar in FDM and inspect to verify which certificate the device is using.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 14:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4996820#M1107947</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-01-15T14:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997462#M1107977</link>
      <description>&lt;P&gt;Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;I found out that the expired wildcard certificate of 2022 is currently in use (see attached screen dump).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is already a valid&amp;nbsp;wildcard certificate of 2023 on the nodes&amp;nbsp;(see attached screen dump).&lt;BR /&gt;&lt;BR /&gt;The question for me is now how to exchange the expired with the valid wildcard certificate to be used in the FDM? Is it enough to delete the&amp;nbsp;expired one or is there any guide?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 08:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997462#M1107977</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-16T08:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997580#M1107986</link>
      <description>&lt;P&gt;You should change the management web server certificate. Instructions to do so can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/730/fdm/fptd-fdm-config-guide-730/fptd-fdm-system.html#task_31B0F47D39444D6EB91A552A2B93B63E" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/730/fdm/fptd-fdm-config-guide-730/fptd-fdm-system.html#task_31B0F47D39444D6EB91A552A2B93B63E&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Once that's done, you can delete the expired certificate and retry the upgrade.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 12:16:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997580#M1107986</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-01-16T12:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997634#M1107992</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Marvin,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I followed your link and chose the valid wildcard certificate for the&amp;nbsp;Management Web Server on the active device (see screen dump). Then I logged out from FMC and closed Chrome.&lt;BR /&gt;&lt;BR /&gt;I could login to the&amp;nbsp;active device' FMC without problems but the setting was not replicated to the standby device unfortunately. I tried to set the&amp;nbsp;valid wildcard certificate for the&amp;nbsp;Management Web Server on the standby device but it rejected this attempt (see screen dump), even if the same valid&amp;nbsp;wildcard certificate is stored on the&amp;nbsp;standby device too.&lt;BR /&gt;&lt;BR /&gt;Is there a way to force the replication of this configuration?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 13:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997634#M1107992</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-16T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997704#M1107996</link>
      <description>&lt;P&gt;I have not done this actual step since most of my systems are FMC-managed.&lt;/P&gt;
&lt;P&gt;However, I would try forcing a failover and then log into the the newly Active unit (formerly Standby) and repeating the steps to change its management certificate from there.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4997704#M1107996</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-01-16T15:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4998397#M1108023</link>
      <description>&lt;P&gt;Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;I will do so at Friday and if I can change the certificate I will retry the upgrade.&lt;BR /&gt;&lt;BR /&gt;I will let you know then.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 12:23:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/4998397#M1108023</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-17T12:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1120: FDM - unable to upgrade the cluster</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/5002542#M1108241</link>
      <description>&lt;P&gt;Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;after failover the &lt;SPAN&gt;wildcard certificate of 2023 was already there&amp;nbsp;for the&amp;nbsp;Management Web Server!&lt;BR /&gt;&lt;BR /&gt;After that I retried the upgrade and it worked even if it took much time.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot for your useful hints!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 13:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1120-fdm-unable-to-upgrade-the-cluster/m-p/5002542#M1108241</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-01-22T13:51:53Z</dc:date>
    </item>
  </channel>
</rss>

