<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: You're welcome. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3346861#M134092</link>
    <description>I believe that because Firepower is not HA aware and you have an HA configuration and monitoring Interface dataplane0 you are receiving this error. Do not monitor interface dataplane0 in an HA configuration, the error will disappear.</description>
    <pubDate>Mon, 12 Mar 2018 15:46:50 GMT</pubDate>
    <dc:creator>John Roshek</dc:creator>
    <dc:date>2018-03-12T15:46:50Z</dc:date>
    <item>
      <title>Firepower Management center</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084939#M134075</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When i try to add the firepower sensor to FMC it shows this massage (Could not establish a connection with sensor. Make sure the registration keys match, that the software versions are compatible, and that the network is not blocking the connection.)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;the&amp;nbsp;&lt;SPAN&gt;registration keys ok , their is ping between the fmc and sensor and the firepower service&amp;nbsp;is version 6.2.0 and the FMC its also 6.2.0 and i install Hotfix A 6.2.0.1 &amp;nbsp;successfully.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;sh version&lt;/P&gt;
&lt;H4&gt;Cisco Adaptive Security Appliance Software Version 9.8(1)&lt;BR /&gt;&lt;STRONG&gt;Firepower Extensible Operating System Version 2.2(1.47)&lt;/STRONG&gt;&lt;BR /&gt;Device Manager Version 7.8(1)&lt;/H4&gt;
&lt;P&gt;--------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;1# session sfr console&lt;BR /&gt;Opening console session with module sfr.&lt;BR /&gt;Connected to module sfr. Escape character sequence is 'CTRL-^X'.&lt;/P&gt;
&lt;H4&gt;&amp;gt; show version&lt;BR /&gt;---------------------[ gpgsfr ]---------------------&lt;BR /&gt;&lt;STRONG&gt;Model : ASA5525 (72) Version 6.2.0 (Build 362)&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Rules update version : 2016-03-28-001-vrt&lt;BR /&gt;VDB version : 271&lt;BR /&gt;----------------------------------------------------&lt;/H4&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084939#M134075</guid>
      <dc:creator>nasser2002_2005</dc:creator>
      <dc:date>2019-03-12T09:41:58Z</dc:date>
    </item>
    <item>
      <title>Can you confirm that you can</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084940#M134076</link>
      <description>&lt;P&gt;Can you confirm that you can ssh from one to the other (FMC to the module and vice versa)?&lt;/P&gt;
&lt;P&gt;Also, if there is a firewall between them at all, verify that tcp/8305 is allowed. That is the required port that must be open bidirectionally. You should be able to initiate a telnet connection from either end and specify port 8305 to verify it.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 16:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084940#M134076</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-13T16:43:11Z</dc:date>
    </item>
    <item>
      <title>Hi marvin,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084941#M134078</link>
      <description>&lt;P&gt;Hi marvin,&lt;/P&gt;
&lt;P&gt;there is&amp;nbsp;&lt;SPAN&gt;telnet connection from either. what do you mean about last part (specify port 8305 to verify it)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;verify that tcp/8305 is allowed (could you please explain more )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;again thank you very mach&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084941#M134078</guid>
      <dc:creator>nasser2002_2005</dc:creator>
      <dc:date>2017-07-13T19:28:56Z</dc:date>
    </item>
    <item>
      <title>i notice that there is no</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084942#M134080</link>
      <description>&lt;P&gt;i notice that there is no ping petween the fmc and firepower&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 19:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084942#M134080</guid>
      <dc:creator>nasser2002_2005</dc:creator>
      <dc:date>2017-07-13T19:48:01Z</dc:date>
    </item>
    <item>
      <title>If there's no ping (icmp),</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084943#M134081</link>
      <description>&lt;P&gt;If there's no ping (icmp), there's likely no tcp as well.&lt;/P&gt;
&lt;P&gt;Fix that issue first. The most common cause is mis-configuration of the networking on the module. The second most common is an intervening network firewall that either blocks the communications or NATs one or the other address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I mentioned using telnet to check tcp 8305 becasue that is the tcp port that is used between FMC and its managed sensors.&lt;/P&gt;
&lt;P&gt;From the bash shell (underlying Linux cli for both FMC and FirePOWER module) you simply start a telnet session and specify the (non-standard for telnet) port 8305. (telnet usually uses tcp/23).&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;telnet &amp;lt;remote address&amp;gt; 8305&lt;/PRE&gt;
&lt;P&gt;On a FirePOWER module sensor you need to first switch to expert mode to get into the bash shell.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 04:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084943#M134081</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-14T04:34:50Z</dc:date>
    </item>
    <item>
      <title>Thank you Mr. Marvin</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084944#M134082</link>
      <description>&lt;P&gt;Thank you Mr. Marvin &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;it working now the issue was mis-configuration ,&lt;/P&gt;
&lt;P&gt;I have question. shell I register the 2 ASA ( primary and secondary ) on the FMC with different firepower ip .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thank you again .&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 05:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084944#M134082</guid>
      <dc:creator>nasser2002_2005</dc:creator>
      <dc:date>2017-07-14T05:10:55Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084945#M134083</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Yes - each ASA FirePOWER module reuires a unique address and must be individually registered to the managing FMC (and license applied from FMC).&lt;/P&gt;
&lt;P&gt;Remember the FirePOWER modules themselves have no knowledge of the ASA HA pair.&lt;/P&gt;
&lt;P&gt;We can then logically put them in a device group and, when creating policy, assign both modules to the same policy. That's one of the advantages of using FMC - create one policy and deploy to multiple managed sensors.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 05:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084945#M134083</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-14T05:14:46Z</dc:date>
    </item>
    <item>
      <title>man your helping me a lot</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084946#M134085</link>
      <description>&lt;P&gt;man your helping me a lot&lt;/P&gt;
&lt;P&gt;Mr. Marvin&lt;/P&gt;
&lt;P&gt;im intern level how I can create policy and assign both modules to the same policy.&lt;/P&gt;
&lt;P&gt;could&amp;nbsp; you please explain to me ?&lt;/P&gt;
&lt;P&gt;one more thing I have health massage on FMC&amp;nbsp;&lt;A class="iconlink" style="color: rgb(74, 115, 153); text-decoration: none;" onclick="expandGroup(this, 'details_Interface Status');"&gt;&amp;nbsp;(&lt;/A&gt;&lt;A class="iconlink" style="color: rgb(74, 115, 153); text-decoration: none;" onclick="expandGroup(this, 'details_Interface Status');"&gt;Interface 'DataPlaneInterface0' is not receiving any packets) (by the way I did not assign outside ip)&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0px 0px 10px; color: rgb(88, 88, 91); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-weight: normal; word-spacing: 0px; white-space: normal; orphans: 2; widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;&lt;/P&gt;
&lt;P style="margin: 0px 0px 10px; color: rgb(88, 88, 91); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial, sans-serif; font-size: 16px; font-style: normal; font-weight: normal; word-spacing: 0px; white-space: normal; orphans: 2; widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;thank you again .&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 05:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084946#M134085</guid>
      <dc:creator>nasser2002_2005</dc:creator>
      <dc:date>2017-07-14T05:25:53Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084947#M134087</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;The configuration guide covers setting target devices for an Access Contorl Policy here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html#ID-2176-000002e6&lt;/P&gt;
&lt;P&gt;Dataplane0 is the internal connection between the ASA data path and the FirePOWER module. The dataplane error is most often seen in two conditions:&lt;/P&gt;
&lt;P&gt;1. There is no service policy in the ASA redirecting traffic to the FirePOWER module. Make sure you have created and applied one per the following guide:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html#pgfId-150498&lt;/P&gt;
&lt;P&gt;2. The secondary ASA in an HA pair is not normally processing any traffic and thus gives us that condition. (The same thing would apply if the whole ASA pair was in a lab or otherwise not processing any traffic through the box.)&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 05:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3084947#M134087</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-14T05:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3346861#M134092</link>
      <description>I believe that because Firepower is not HA aware and you have an HA configuration and monitoring Interface dataplane0 you are receiving this error. Do not monitor interface dataplane0 in an HA configuration, the error will disappear.</description>
      <pubDate>Mon, 12 Mar 2018 15:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/3346861#M134092</guid>
      <dc:creator>John Roshek</dc:creator>
      <dc:date>2018-03-12T15:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can you confirm that you can</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4711936#M1094564</link>
      <description>&lt;P&gt;is the ssh connection mandatory for FMC to make connection with the sensor?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 15:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4711936#M1094564</guid>
      <dc:creator>Tess238</dc:creator>
      <dc:date>2022-10-27T15:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can you confirm that you can</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4712060#M1094570</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1426104"&gt;@Tess238&lt;/a&gt; no ssh is needed. We sometimes use it for testing when the required communications are in doubt.&lt;/P&gt;
&lt;P&gt;What's required is tcp/8305, initiated from either end. FMC-FTD and vice versa use that port for sftunnel which is used for both management and eventing. At the higher layer it is using TLS 1.2.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 18:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4712060#M1094570</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-10-27T18:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Management center</title>
      <link>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4712891#M1094612</link>
      <description>&lt;P&gt;I've seen issues like this and syncing the time either manually or NTP fixed the issue. Not sure if this would apply in your case&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 16:48:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-management-center/m-p/4712891#M1094612</guid>
      <dc:creator>Chuck Reimer</dc:creator>
      <dc:date>2022-10-28T16:48:37Z</dc:date>
    </item>
  </channel>
</rss>

