<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPR-2110 Time Synch in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366347#M1124303</link>
    <description>&lt;P&gt;So, I did try changing the Timezone to UTC. It didn't change anything. After extensive t-shooting with TAC it appears that the LINA side is experiencing a time drift. It is odd. Logging into FTD and inputting show clock shows correct time. Connect fxos and show clock displays correct time. Connecting to system support diagnostic-cli and show clock displays time that is behind. Time is set to sync from FMC which is on current time. No other firewalls are impacted. TAC couldn't figure out why the LINA side is out of sync. We may just put this on the back burner since we are close to migrating that firewall to new hardware.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jan 2026 14:53:28 GMT</pubDate>
    <dc:creator>davparker</dc:creator>
    <dc:date>2026-01-30T14:53:28Z</dc:date>
    <item>
      <title>FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5365923#M1124286</link>
      <description>&lt;P&gt;On the FPR-2110 we may be experiencing an issue with time synchronization that might be preventing SAML auth.&lt;BR /&gt;In system support diagnostic-cli the clock appears to be several minutes off.&lt;BR /&gt;When I show time from a regular cli prompt, time shows correct.&lt;BR /&gt;Time is set to sync via NTTP from Management Center, which looks to be correct&lt;/P&gt;&lt;P&gt;&amp;gt; show time&lt;BR /&gt;UTC - Wed Jan 28 23:01:35 UTC 2026&lt;/P&gt;&lt;P&gt;&amp;gt; system support diagnostic-cli&lt;BR /&gt;Attaching to Diagnostic CLI ... Press 'Ctrl+a then d' to detach.&lt;BR /&gt;Type help or '?' for a list of available commands.&lt;/P&gt;&lt;P&gt;PPFTD-01&amp;gt; en&lt;BR /&gt;Password:&lt;BR /&gt;PPFTD-01# show clock&lt;BR /&gt;22:54:31.228 UT&lt;/P&gt;&lt;P&gt;Health Monitor shows the following faults:&lt;BR /&gt;Platform Faults&lt;BR /&gt;Jan 28, 2026 4:49 PM&lt;BR /&gt;2 Major Events&lt;BR /&gt;Code - F0853; Occurrence - 1; Time - 2025-03-12T00.18.45.390; Description - FDM Keyring's certificate is invalid&lt;/P&gt;&lt;P&gt;We are attempting to enable SAML auth against Azure. It fails. Below is debug output from:&lt;BR /&gt;debug webvpn saml 255&lt;/P&gt;&lt;P&gt;Jan 28 22:21:22 [SAML] get_validity: Assertion validity: NotBefore:2026-01-28T22:24:19.244Z NotOnOrAfter:2026-01-28T23:29:19.244Z&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Processing time values:&lt;BR /&gt;raw NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;raw NotOnOrAfter: 23:29:19 UTC Jan 28 2026&lt;BR /&gt;clock skew: 0&lt;BR /&gt;timeout: 0&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Effective time values :&lt;BR /&gt;adjusted NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;adjusted NotOnOrAfter: 23:29:19 UTC Jan 28 2026&lt;BR /&gt;current time: 22:21:22 UTC Jan 28 2026&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Assertion not yet valid.&lt;BR /&gt;Current time: 22:21:22 UTC Jan 28 2026&lt;BR /&gt;adjusted NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;Jan 28 22:21:22 [SAML] consume_assertion: assertion is expired or not valid&lt;BR /&gt;[saml] webvpn_login_primary_username: SAML assertion validation failed&lt;BR /&gt;saml_get_ac_token_data: Passed SAML token is NULL&lt;/P&gt;&lt;P&gt;Basically, it appears that time drift is preventing SAML auth? I also can't figure out why time doesn't agree depending upon how I check it.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 23:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5365923#M1124286</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-01-28T23:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5365975#M1124288</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Review these&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt; bug reports&lt;/EM&gt;&lt;/FONT&gt; :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Firepower%202110%20Security%20Appliance&amp;amp;kw=FDM%20Keyring%27s%20certificate%20is%20invalid%20F0853%20certificate%20is%20invalid&amp;amp;bt=custV&amp;amp;sb=anfr" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Firepower%202110%20Security%20Appliance&amp;amp;kw=FDM%20Keyring%27s%20certificate%20is%20invalid%20F0853%20certificate%20is%20invalid&amp;amp;bt=custV&amp;amp;sb=anfr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 07:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5365975#M1124288</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2026-01-29T07:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366043#M1124290</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp;Can you ensure the timezone is UTC, as&lt;SPAN&gt;&amp;nbsp;validity time seen in the assertion is in UTC:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/interfaces-modules/catalyst-6500-series-7600-series-asa-services-module/223564-troubleshoot-common-problems-with-saml.html#toc-hId-350712260" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/interfaces-modules/catalyst-6500-series-7600-series-asa-services-module/223564-troubleshoot-common-problems-with-saml.html#toc-hId-350712260&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You perform changes via Platform Settings:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/interfaces-settings-platform.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/interfaces-settings-platform.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cristian.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 11:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366043#M1124290</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-29T11:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366135#M1124297</link>
      <description>&lt;P&gt;When I ssh into FTD and issue "show time" it shows the correct current time in UTC format. The Platform settings do specify CST-6 for the FTD appliance. When I test auth to VPN it shows the validity period beginning several minutes into the future and not the 6 hour offset. When I 'connect fxos' and 'show clock' the time is UTC but the time is offset by what looks like the same several minutes behind as shown in the same debug webcpn saml 255 outut. Weird. I could try changing the Timezone. I'm not sure what impact that will have. We don't currently have any time based rules.&lt;/P&gt;&lt;P&gt;debug webvpn saml 255&lt;BR /&gt;Jan 28 22:21:22 [SAML] get_validity: Assertion validity: NotBefore:2026-01-28T22:24:19.244Z NotOnOrAfter:2026-01-28T23:29:19.244Z&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Processing time values:&lt;BR /&gt;raw NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;raw NotOnOrAfter: 23:29:19 UTC Jan 28 2026&lt;BR /&gt;clock skew: 0&lt;BR /&gt;timeout: 0&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Effective time values :&lt;BR /&gt;adjusted NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;adjusted NotOnOrAfter: 23:29:19 UTC Jan 28 2026&lt;BR /&gt;current time: 22:21:22 UTC Jan 28 2026&lt;BR /&gt;Jan 28 22:21:22 [SAML] saml_util_check_expiration: Assertion not yet valid.&lt;BR /&gt;Current time: 22:21:22 UTC Jan 28 2026&lt;BR /&gt;adjusted NotBefore: 22:24:19 UTC Jan 28 2026&lt;BR /&gt;Jan 28 22:21:22 [SAML] consume_assertion: assertion is expired or not valid&lt;BR /&gt;[saml] webvpn_login_primary_username: SAML assertion validation failed&lt;BR /&gt;saml_get_ac_token_data: Passed SAML token is NULL&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 17:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366135#M1124297</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-01-29T17:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366138#M1124298</link>
      <description>&lt;P&gt;We are actually close to replacing this firewall. Doing some MFA testing in the meantime. Trying to avoid upgrading unless necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 18:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366138#M1124298</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-01-29T18:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366152#M1124300</link>
      <description>&lt;P&gt;Hey Mark,&lt;/P&gt;&lt;P&gt;I did check out the bugs. This device is managed by FMC.&lt;/P&gt;&lt;P&gt;According to bug&amp;nbsp;&lt;SPAN class=""&gt;CSCvk26612&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;SPAN&gt;For FMC: The fault do not cause any impact.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Jan 2026 19:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366152#M1124300</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-01-29T19:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366347#M1124303</link>
      <description>&lt;P&gt;So, I did try changing the Timezone to UTC. It didn't change anything. After extensive t-shooting with TAC it appears that the LINA side is experiencing a time drift. It is odd. Logging into FTD and inputting show clock shows correct time. Connect fxos and show clock displays correct time. Connecting to system support diagnostic-cli and show clock displays time that is behind. Time is set to sync from FMC which is on current time. No other firewalls are impacted. TAC couldn't figure out why the LINA side is out of sync. We may just put this on the back burner since we are close to migrating that firewall to new hardware.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 14:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366347#M1124303</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-01-30T14:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366414#M1124304</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1494970"&gt;@davparker&lt;/a&gt;&amp;nbsp;Thanks for reaching back, obviously a bug. Before closing, ask TAC to open a bug on this, ideally get RCA and possible WA's attached to the bug.&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 20:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5366414#M1124304</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-30T20:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: FPR-2110 Time Synch</title>
      <link>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5370967#M1124505</link>
      <description>&lt;P&gt;You know I tried but they just wanted me to do the workaround, rebooting and failing over. That did work for now. Azure MFA is working. We are working towards replacing the 2110s with 3105s so this hopefully will become a non-issue.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 15:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr-2110-time-synch/m-p/5370967#M1124505</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2026-02-18T15:48:21Z</dc:date>
    </item>
  </channel>
</rss>

