<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC validation errors in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-validation-errors/m-p/3714548#M133218</link>
    <description>&lt;P&gt;It seems that the device will show up as red if the service-policy is not applied on the ASA. This is due to packets not being sent to the Firepower virtual appliance. It is possible to successfully deploy to the device without the service-policy being applied.&amp;nbsp; The device being in the FMC showing up as red can be confusing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Sep 2018 19:15:31 GMT</pubDate>
    <dc:creator>Alex Pfeil</dc:creator>
    <dc:date>2018-09-27T19:15:31Z</dc:date>
    <item>
      <title>FMC validation errors</title>
      <link>https://community.cisco.com/t5/network-security/fmc-validation-errors/m-p/3095774#M133216</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i was able to add a ASA 5525-X sensor in FMC but i'm unable to add/tick licenses (grayed out) and saw this error:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Initial policy deployment not started due to validation errors. For details, redeploy manually&lt;/EM&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt; show managers&amp;nbsp; &lt;BR /&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Manager&lt;BR /&gt;Host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 172.20.x.x&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;Registration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Completed&lt;/SPAN&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i got enough URL filtering, malware, etc licenses for this sensor but not sure why FMC doesn't let me add them and push the access policy. see attached photo.&lt;/P&gt;
&lt;P&gt;note this ASA 5525-X is not yet in production and only got 'management' interface and FP module both using same IP subnet and able they both able to ping/reach FMC. not sure if ASA needs to have other 'interfaces' working and operational.&lt;/P&gt;
&lt;P&gt;i also saw this and not sure if it's bug related.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/relnote/firepower-system-release-notes-version-600.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/relnote/firepower-system-release-notes-version-600.html&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In some cases, if you do not select the required licenses for a device prior to device &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;registration, the system generates an Initial policy deployment not started due to &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;validation errors. For details, redeploy manually message. For more information on the &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;correct licenses to select for your device, see the Licensing the FireSIGHT System chapter &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;of the Firepower Management Center Configuration Guide . &lt;SPAN style="color: #ff0000;"&gt;(CSCuw85743)&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;can someone advise if ASA sensor (specifically its 'interfaces) needs to be in production for it to be able to add/tick licenses and push access policies? do i need to reboot ASA or FP and see if it helps?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-validation-errors/m-p/3095774#M133216</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T09:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC validation errors</title>
      <link>https://community.cisco.com/t5/network-security/fmc-validation-errors/m-p/3714548#M133218</link>
      <description>&lt;P&gt;It seems that the device will show up as red if the service-policy is not applied on the ASA. This is due to packets not being sent to the Firepower virtual appliance. It is possible to successfully deploy to the device without the service-policy being applied.&amp;nbsp; The device being in the FMC showing up as red can be confusing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 19:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-validation-errors/m-p/3714548#M133218</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-09-27T19:15:31Z</dc:date>
    </item>
  </channel>
</rss>

