<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD: Unable to reach FQDNs in the Internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234745#M1118079</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;
&lt;P&gt;our customer has 1 cluster of two Firepower 1120 running rel. 7.4.2.1&lt;BR /&gt;managed by the FMCv running rel. 7.4.2.1 too.&lt;/P&gt;
&lt;P&gt;The Health Monitor shows the error message:&lt;BR /&gt;Cisco Cloud Configuration - Unable to reach Cisco Cloud from the device. Please check the network connection..&lt;BR /&gt;for both devices.&lt;/P&gt;
&lt;P&gt;The firewalls can resolve FQDNs in th Internet:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@firepower:~$ nslookup api-sse.cisco.com
Server:         192.168.100.25
Address:        192.168.100.25#53

Non-authoritative answer:
api-sse.cisco.com       canonical name = api-sse.cisco.com.akadns.net.
Name:   api-sse.cisco.com.akadns.net
Address: 54.166.161.63
Name:   api-sse.cisco.com.akadns.net
Address: 3.82.76.181
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200a:48c5:ffc1:9e69:b18a
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200b:d1e:17aa:513b:e947&lt;/LI-CODE&gt;
&lt;P&gt;It can ping IP addresses in the Internet:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping 8.8.8.8
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms&lt;/LI-CODE&gt;
&lt;P&gt;But when I try to ping FQDNs in the Internet the ping responds with "U" (unreachable):&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping intelligence.sourcefire.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2620:28:c000:0:aba:ca:daba:58, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)

&amp;gt; ping www.google.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2a00:1450:4016:80c::2004, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)&lt;/LI-CODE&gt;
&lt;P&gt;What is going wrong here?&lt;/P&gt;
&lt;P&gt;Every hint is welcome.&lt;/P&gt;
&lt;P&gt;Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bye&lt;BR /&gt;Rene&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 08:48:50 GMT</pubDate>
    <dc:creator>swscco001</dc:creator>
    <dc:date>2024-12-10T08:48:50Z</dc:date>
    <item>
      <title>FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234745#M1118079</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;
&lt;P&gt;our customer has 1 cluster of two Firepower 1120 running rel. 7.4.2.1&lt;BR /&gt;managed by the FMCv running rel. 7.4.2.1 too.&lt;/P&gt;
&lt;P&gt;The Health Monitor shows the error message:&lt;BR /&gt;Cisco Cloud Configuration - Unable to reach Cisco Cloud from the device. Please check the network connection..&lt;BR /&gt;for both devices.&lt;/P&gt;
&lt;P&gt;The firewalls can resolve FQDNs in th Internet:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@firepower:~$ nslookup api-sse.cisco.com
Server:         192.168.100.25
Address:        192.168.100.25#53

Non-authoritative answer:
api-sse.cisco.com       canonical name = api-sse.cisco.com.akadns.net.
Name:   api-sse.cisco.com.akadns.net
Address: 54.166.161.63
Name:   api-sse.cisco.com.akadns.net
Address: 3.82.76.181
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200a:48c5:ffc1:9e69:b18a
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200b:d1e:17aa:513b:e947&lt;/LI-CODE&gt;
&lt;P&gt;It can ping IP addresses in the Internet:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping 8.8.8.8
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms&lt;/LI-CODE&gt;
&lt;P&gt;But when I try to ping FQDNs in the Internet the ping responds with "U" (unreachable):&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping intelligence.sourcefire.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2620:28:c000:0:aba:ca:daba:58, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)

&amp;gt; ping www.google.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2a00:1450:4016:80c::2004, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)&lt;/LI-CODE&gt;
&lt;P&gt;What is going wrong here?&lt;/P&gt;
&lt;P&gt;Every hint is welcome.&lt;/P&gt;
&lt;P&gt;Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bye&lt;BR /&gt;Rene&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 08:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234745#M1118079</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-12-10T08:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234751#M1118081</link>
      <description>&lt;P&gt;Show network &amp;lt;&amp;lt;- in ftd' check dns server you add&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remember this dns not for user traffic it for ftd.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 08:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234751#M1118081</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-10T08:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234761#M1118084</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/96014"&gt;@swscco001&lt;/a&gt; you are pinging from the data interface, have you configured the DNS servers in the Platform Settings Policy which is assigned to that FTD cluster? &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/interfaces-settings-platform.html#id_74914" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/interfaces-settings-platform.html#id_74914&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 09:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5234761#M1118084</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-12-10T09:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235277#M1118125</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;
&lt;P&gt;thanks for your reply!&lt;/P&gt;
&lt;P&gt;Every other customer get the error message of missing access of the firewalls to the&lt;BR /&gt;Cisco cloud &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I followed the Cisco guide:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/217616-troubleshoot-cisco-cloud-configuration.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/217616-troubleshoot-cisco-cloud-configuration.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I used the DNS server 192.168.100.25 that I found in the Platform Settings of the FMC&lt;BR /&gt;for the configuration of the network of the Firewall CLI.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show network
===============[ System Information ]===============
Hostname                  : firepower
DNS Servers               : 8.8.8.8
                            192.168.100.25
                            208.68.222.222
DNS from router           : disabled
Management port           : 8305
IPv4 Default route
  Gateway                 : 192.168.18.254
...&lt;/LI-CODE&gt;
&lt;P&gt;This was used when I try a nslookup:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dmin@firepower:~$ nslookup api-sse.cisco.com
Server:         192.168.100.25
Address:        192.168.100.25#53

Non-authoritative answer:
api-sse.cisco.com       canonical name = api-sse.cisco.com.akadns.net.
Name:   api-sse.cisco.com.akadns.net
Address: 54.166.161.63
Name:   api-sse.cisco.com.akadns.net
Address: 3.82.76.181
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200a:48c5:ffc1:9e69:b18a
Name:   api-sse.cisco.com.akadns.net
Address: 2600:1f18:56c:200b:d1e:17aa:513b:e947&lt;/LI-CODE&gt;
&lt;P&gt;I can ping IP-Adresses in the Internet:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping 208.67.222.222
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 208.67.222.222, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 10/12/20 ms&lt;/LI-CODE&gt;
&lt;P&gt;But at FQDNs I get back "U" (unreachable), and no ".":&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; ping api-sse.cisco.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2600:1f18:56c:200b:d1e:17aa:513b:e947, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)

&amp;gt; ping www.google.com
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2a00:1450:4016:80c::2004, timeout is 2 seconds:
UUUUU
Success rate is 0 percent (0/5)&lt;/LI-CODE&gt;
&lt;P&gt;This is hard to understand.&lt;/P&gt;
&lt;P&gt;Do you have any explanation?&lt;/P&gt;
&lt;P&gt;Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 08:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235277#M1118125</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-12-11T08:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235310#M1118127</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/96014"&gt;@swscco001&lt;/a&gt; "show network" is showing information related to the &lt;U&gt;mgmt&lt;/U&gt; interface (not the data interface). You are pinging from the data interface. If you have the mgmt interface connected, you run a ping using the command "ping &lt;U&gt;system&lt;/U&gt; &amp;lt;fqdn&amp;gt;".&lt;/P&gt;
&lt;P&gt;So are you saying you do have a Platform Setting policy that is applied to this FTD? Can the FTD reach the DNS server 192.168.100.25 via it's data interface?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 09:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235310#M1118127</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-12-11T09:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235439#M1118133</link>
      <description>&lt;P&gt;Hi Rob,&lt;BR /&gt;&lt;BR /&gt;with your hints I could bring the traffic from the management-IF through a firewall to the Internet and the error message in the FMC disappeared.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;BR /&gt;R.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 13:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235439#M1118133</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2024-12-11T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD: Unable to reach FQDNs in the Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235467#M1118138</link>
      <description>&lt;P&gt;what was problem ? and what is solution?&amp;nbsp;&lt;BR /&gt;it seem that the DNS is missing from mgmt interface, or I am wrong ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-unable-to-reach-fqdns-in-the-internet/m-p/5235467#M1118138</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-11T14:07:23Z</dc:date>
    </item>
  </channel>
</rss>

