<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco_Firepower deployment issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259209#M1119492</link>
    <description>&lt;P&gt;For the integration itself I don't believe you need SXP as ISE and FMC are integrated via pxGrid. However, the SXP could be required if you want to propagate the SGTs over L3 links where the devices in the path (ISP CPE for instance) do not keep or process the tag. In that case SXP would be required, but as I said not for the integration between ISE and FMC.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 16:48:09 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2025-02-11T16:48:09Z</dc:date>
    <item>
      <title>Cisco_Firepower deployment issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5257415#M1119367</link>
      <description>&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="1e9099580a0a3c0874ac17963aab6026" aria-hidden="false" aria-labelledby="section_tab.1e9099580a0a3c0874ac17963aab6026"&gt;&lt;SPAN class="section state-closed" data-header-only="false"&gt;&lt;SPAN&gt;We were affected several times for an error that prevented us to continue with the deployment of any modifications in our Cisco Firepower, and the error seems to be related to ISE/SGT integration:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;At the moment, we are using the following workaround: uncheck “SXP Topic” -&amp;gt; Save, then check back again “SXP Topic” -&amp;gt; Save:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorAmen_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Amen_1-1738828280435.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/239376i2AC2CD373108C553/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Amen_1-1738828280435.png" alt="Amen_1-1738828280435.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Amen_2-1738828309318.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/239377iF6C477FD73D12120/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Amen_2-1738828309318.png" alt="Amen_2-1738828309318.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="1e9099580a0a3c0874ac17963aab6026" aria-hidden="false" aria-labelledby="section_tab.1e9099580a0a3c0874ac17963aab6026"&gt;&lt;SPAN class="section state-closed" data-header-only="false"&gt;&lt;SPAN&gt;&lt;BR /&gt;After execution of this workaround, we can continue normally.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;is there anyway to avoid that? Is there any know bug or information about this? Perhaps some commands we can run to gather information to help troubleshoot next time?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 07:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5257415#M1119367</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2025-02-06T07:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco_Firepower deployment issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5257699#M1119378</link>
      <description>&lt;P&gt;Are you using that security rule that has "DigIT_Infra" tag selected? if not, you can remove that rule. The error you shared seems to be talking about having that tag deleted, mabye there is an issue between ISE and your FMC that is preventing the synchronization from happening? Finally, if you are not using SXP then you can leave it off, you only need that if you are actually encapsulating the SGTs over L3 links.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 17:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5257699#M1119378</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-06T17:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco_Firepower deployment issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259207#M1119491</link>
      <description>&lt;P&gt;Yes, we are using the “DigIT_Infra” SGT. That is the only one you can see in the screenshot, but the full list of all SGT is included in the scroll down window. This mans that is complaining about all of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I understand, I need SXP between Firepower an ISE server,&amp;nbsp;Communications between them are over internal L3 links. right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259207#M1119491</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2025-02-11T16:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco_Firepower deployment issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259209#M1119492</link>
      <description>&lt;P&gt;For the integration itself I don't believe you need SXP as ISE and FMC are integrated via pxGrid. However, the SXP could be required if you want to propagate the SGTs over L3 links where the devices in the path (ISP CPE for instance) do not keep or process the tag. In that case SXP would be required, but as I said not for the integration between ISE and FMC.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259209#M1119492</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-11T16:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco_Firepower deployment issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259220#M1119495</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171234"&gt;@Amen&lt;/a&gt; the FMC will learn the SGT (and dynamic IP bindings) via the pxGrid integration to ISE. The SXP integration to ISE would be used if you are publishing static IP binding from ISE, optional not mandatory.&lt;/P&gt;
&lt;P&gt;From the FMC expert mode, you can r&lt;SPAN&gt;un the command &lt;STRONG&gt;&lt;EM&gt;adi_cli session &lt;/EM&gt;&lt;/STRONG&gt;will display the sessions sent from ISE to the FMC and&amp;nbsp;run the command &lt;STRONG&gt;&lt;EM&gt;cat /var/sf/run/adi-health&lt;/EM&gt;&lt;/STRONG&gt; will provide information on the state to confirm this integration is working.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 17:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-deployment-issue/m-p/5259220#M1119495</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-02-11T17:00:41Z</dc:date>
    </item>
  </channel>
</rss>

