<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FP4120 FTD Policy deploy fail issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3743060#M157295</link>
    <description>This solved my issue in GNS3 on a virtual FTD. Thanks so much</description>
    <pubDate>Fri, 09 Nov 2018 18:24:06 GMT</pubDate>
    <dc:creator>NETAD</dc:creator>
    <dc:date>2018-11-09T18:24:06Z</dc:date>
    <item>
      <title>FP4120 FTD Policy deploy fail issue</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911109#M157290</link>
      <description>&lt;P&gt;HI, i am OSung&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;we were discussed about prepare for FP4120 FTD (Firepower Threat Defense) PoV&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;SPAN&gt;BUT&amp;nbsp;FP4120 FTD Policy deploy fail issue&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;: When we deploy Policy at FMC, update fail was occurred.&lt;/P&gt;
&lt;P&gt;After occurred update fail, we tried again deploy policy but &lt;SPAN lang="KO"&gt;“&lt;/SPAN&gt;Deployment failed due to conflict with ongoing previous deployment. If problem persists aster retrying, contact Cisco TAC.&lt;SPAN lang="KO"&gt;”&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This is not first time, last night the same case was occurred, so we delete FP4120 device at FMC. After then we add device again and deploy policy it was OK.&amp;nbsp;But tonight the same case was occurred again. Before PoV starting, We have to fix it&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;FMC Model and version : Cisco Firepower Management Center for VMWare (memory 16G, CPU 8 core) , version 6.0.1 (build 1213)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Managed Device model and version : FP4120 Threat Defense version 6.0.1 , Firewall is routed mode&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Why happend this situation? &lt;SPAN&gt;I need your experience and advice for FTD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang="EN-US"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang="EN-US" mce-data-marked="1"&gt;OSung Kwon&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911109#M157290</guid>
      <dc:creator>kwon65211</dc:creator>
      <dc:date>2019-03-12T07:56:53Z</dc:date>
    </item>
    <item>
      <title>Hi OSung,</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911110#M157291</link>
      <description>&lt;P&gt;Hi OSung,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have this problem as well with FP4110 appliances with FTD logical devices running v6.1 in an HA failover pair in routed mode. Our setup is already used productively and I'm currently waiting for Cisco TAC to reply to my message. Removing the FTDs from FMC and re-adding them is currently no option for us because they are already heavily under load and used productively.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Florian&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 13:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911110#M157291</guid>
      <dc:creator>Florian Stroemmer</dc:creator>
      <dc:date>2016-12-07T13:54:11Z</dc:date>
    </item>
    <item>
      <title>Hi Osung,</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911111#M157292</link>
      <description>&lt;P&gt;Hi Osung,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cisco TAC (and developers!) helped me to solve my problem. It was related to the following bug: CSCuz65543 which is detailed here: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz65543"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz65543&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Our customer had two network objects with "&amp;amp;" in the description which caused the policy deployment to fail. Even if you remove the "&amp;amp;" character in the GUI, the deployment still fails. They created a way to enter "conf t" on the LINA CLI to manually remove the "&amp;amp;" character from the description of the objects and then the policy was deployed without any issues.&lt;/P&gt;
&lt;P&gt;TAC told me that they are not allowed to use this special way to access the CLI and that they have to involve the developers in order to take this path.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Florian&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2016 08:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/2911111#M157292</guid>
      <dc:creator>Florian Stroemmer</dc:creator>
      <dc:date>2016-12-13T08:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: FP4120 FTD Policy deploy fail issue</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3325017#M157293</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;- Policy deployment takes 30 minutes and then fails on FMC due to a timeout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Subsequent policy deployment fails with "Deployment failed due to conflict with ongoing previous deployment."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;FTD 6.2.1+&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;1. login to the expert mode in FTD CLI&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. escalate to the root level with "sudo su"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. do "pmtool restartbyid ngfwManager"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg58754/?referring_site=bugquickviewredir" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg58754/?referring_site=bugquickviewredir&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 03:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3325017#M157293</guid>
      <dc:creator>nwannura</dc:creator>
      <dc:date>2018-02-05T03:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Osung,</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3367253#M157294</link>
      <description>&lt;P&gt;I love it how Cisco is handeling these kind of issues - you may configure it in the Management tool, but its not supported on the actual device..... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And every time customers have to call the TAC to fix it....&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 09:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3367253#M157294</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2018-04-17T09:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: FP4120 FTD Policy deploy fail issue</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3743060#M157295</link>
      <description>This solved my issue in GNS3 on a virtual FTD. Thanks so much</description>
      <pubDate>Fri, 09 Nov 2018 18:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3743060#M157295</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-11-09T18:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: FP4120 FTD Policy deploy fail issue</title>
      <link>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3745327#M157296</link>
      <description>&lt;P&gt;Hi&amp;nbsp;OSung Kwon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope you are doing great,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many issues with this FTDs are not rsolved through the same solution, so what I would recommend you to do is to debug the deployment and see the logs, many of those would tell you what is the FTD not accepting, sometimes it can be that the FMC can see the HA or Cluster of FTDs or an "systax error". You can debug it with the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;FMC:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;pigtail deploy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;FTDs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;expert&lt;/P&gt;
&lt;P&gt;sudo su&lt;/P&gt;
&lt;P&gt;pigtail deploy&lt;/P&gt;
&lt;DIV id="messageBodySimpleDisplay" class="lia-message-body lia-component-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;Keep us posted with the results whether it worked with one of the workaround provided or you can share this info,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Regards,&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="formessage" class="LabelsForArticle lia-component-labels"&gt;&amp;nbsp;David Castro,&lt;/DIV&gt;</description>
      <pubDate>Mon, 12 Nov 2018 20:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp4120-ftd-policy-deploy-fail-issue/m-p/3745327#M157296</guid>
      <dc:creator>David Castro F.</dc:creator>
      <dc:date>2018-11-12T20:38:15Z</dc:date>
    </item>
  </channel>
</rss>

