<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes I am able to ping the sfr in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800544#M170031</link>
    <description>&lt;P&gt;Yes I am able to ping the sfr module from the ASA itself. &amp;nbsp;I have included the config for the management interface as well as the ping result.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh run int management 1/1&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt; management-only&lt;BR /&gt; nameif Management&lt;BR /&gt; security-level 90&lt;BR /&gt; no ip address&lt;BR /&gt;DorseyASA# ping 192.168.16.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.16.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The 'inside' address is 192.168.16.254, which is also the DG of the module. The output of 'show network' from the SFR module is below:&lt;/P&gt;
&lt;P&gt;&amp;gt; show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : DoresyASA&lt;BR /&gt;Domains : example.net&lt;BR /&gt;DNS Servers : 75.75.75.75&lt;BR /&gt; 76.76.76.76&lt;BR /&gt;Management port : 443&lt;BR /&gt;IPv4 Default route&lt;BR /&gt; Gateway : 192.168.16.254&lt;/P&gt;
&lt;P&gt;======================[ eth0 ]======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode :&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 5C:83:8F:9B:FD:0A&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.16.1&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Broadcast : 192.168.16.255&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;
&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are you indicating that in this scenario I should also remove the 'nameif Management' ?&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2015 03:08:05 GMT</pubDate>
    <dc:creator>jcopling1</dc:creator>
    <dc:date>2015-12-04T03:08:05Z</dc:date>
    <item>
      <title>ASA 5506-x cannot connect to firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800536#M170023</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I have recently configured a 5506 with a firepower module. &amp;nbsp;When attempting to connect to the module via ASDM, I am getting the error "Cannot connect to ASA Firepower module. Check that it is correctly configured and on the network..." &amp;nbsp;I have made sure that the management port is connected to the same L2 switch that the ASA is connected to, and the IP is set to the same subnet as the Data(LAN) port.&lt;/P&gt;
&lt;P&gt;Can anyone possibly throw out some suggestions on what may be the cause of not being able to connect to the firepower module? &amp;nbsp;I'm assuming it is something simple, however as this is my first deploy I would greatly appreciate any input.&lt;/P&gt;
&lt;P&gt;I have included a screenshot of the error I am getting, as well as the 'show network' output from the sfr module.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Justin&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800536#M170023</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2019-03-12T06:59:26Z</dc:date>
    </item>
    <item>
      <title>Whenever I had these problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800537#M170024</link>
      <description>&lt;P&gt;Whenever I had these problems, they were always related to one of these three causes:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Management-Port not connected&lt;/LI&gt;
&lt;LI&gt;Management-Port shutdown&lt;/LI&gt;
&lt;LI&gt;Management-Port in the wrong VLan&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Perhaps better recheck these.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 21:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800537#M170024</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-12-03T21:01:19Z</dc:date>
    </item>
    <item>
      <title>Thank you so much for the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800538#M170025</link>
      <description>&lt;P&gt;Thank you so much for the quick reply!&lt;/P&gt;
&lt;P&gt;I failed to mention that the customer has 2 switches on site. &amp;nbsp;Now that you mention that it sounds entirely likely that they do not have the management port plugged in to the same switch as the inside interface. If they do not, would that also cause the same issue?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Justin&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 21:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800538#M170025</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-03T21:11:52Z</dc:date>
    </item>
    <item>
      <title>If both switches share the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800539#M170026</link>
      <description>&lt;P&gt;If both switches share the same VLANs and the connection between the switches also can transport the management-VLAN, then it should be fine. Can you ping the FP-Management-IP?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 21:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800539#M170026</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-12-03T21:23:40Z</dc:date>
    </item>
    <item>
      <title>Yes both switches share the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800540#M170027</link>
      <description>&lt;P&gt;Yes both switches share the same vlan and the management port is connected to the same switch as the inside port.&lt;/P&gt;
&lt;P&gt;The FP-management ip is pingable from the switch yes.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 01:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800540#M170027</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-04T01:02:18Z</dc:date>
    </item>
    <item>
      <title>Can you ssh to the FP</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800541#M170028</link>
      <description>&lt;P&gt;Can you ssh to the FP-management address from the switch?&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ssh -l admin 192.168.16.2&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800541#M170028</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-04T02:47:06Z</dc:date>
    </item>
    <item>
      <title>Unfortunately the switch is a</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800542#M170029</link>
      <description>&lt;P&gt;Unfortunately the switch is a netgear "smart" switch and the only access I have to it is via the GUI. &amp;nbsp;I am able to run the ping command from the switch however and I am successful. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am able to connect to the SFR module and ping all of the IP's as well. &amp;nbsp;I can provide any outputs that would be beneficial, I do not know much about this configuration so any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800542#M170029</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-04T02:53:29Z</dc:date>
    </item>
    <item>
      <title>Can you ping the sfr module</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800543#M170030</link>
      <description>&lt;P&gt;Can you ping the sfr module from the ASA?&lt;/P&gt;
&lt;P&gt;In this setup the ASA itself should have no interface management 0/0 IP address (and no nameif) and that management interface should be exclusively used by the sfr module.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800543#M170030</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-04T02:58:42Z</dc:date>
    </item>
    <item>
      <title>Yes I am able to ping the sfr</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800544#M170031</link>
      <description>&lt;P&gt;Yes I am able to ping the sfr module from the ASA itself. &amp;nbsp;I have included the config for the management interface as well as the ping result.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh run int management 1/1&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt; management-only&lt;BR /&gt; nameif Management&lt;BR /&gt; security-level 90&lt;BR /&gt; no ip address&lt;BR /&gt;DorseyASA# ping 192.168.16.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.16.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The 'inside' address is 192.168.16.254, which is also the DG of the module. The output of 'show network' from the SFR module is below:&lt;/P&gt;
&lt;P&gt;&amp;gt; show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : DoresyASA&lt;BR /&gt;Domains : example.net&lt;BR /&gt;DNS Servers : 75.75.75.75&lt;BR /&gt; 76.76.76.76&lt;BR /&gt;Management port : 443&lt;BR /&gt;IPv4 Default route&lt;BR /&gt; Gateway : 192.168.16.254&lt;/P&gt;
&lt;P&gt;======================[ eth0 ]======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode :&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 5C:83:8F:9B:FD:0A&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.16.1&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Broadcast : 192.168.16.255&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;
&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are you indicating that in this scenario I should also remove the 'nameif Management' ?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 03:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800544#M170031</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-04T03:08:05Z</dc:date>
    </item>
    <item>
      <title>You should have no nameif if</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800545#M170032</link>
      <description>&lt;P&gt;You should have no nameif if you're not using m1/1 for ASA management. I'm not sure that would cause the issue you're seeing though.&lt;/P&gt;
&lt;P&gt;Where is your ASDM workstation coming from?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 03:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800545#M170032</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-04T03:21:51Z</dc:date>
    </item>
    <item>
      <title>My ASDM session is connecting</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800546#M170033</link>
      <description>&lt;P&gt;My ASDM session is connecting to the public facing ip, or the 'outside' interface, either one.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have removed the nameif just for best practice as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it necessary to connect to the inside interface in order to get the firepower module connected? Could this be a problem if there is NAT on the external interface?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 03:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800546#M170033</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-04T03:30:14Z</dc:date>
    </item>
    <item>
      <title>Ahh that makes sense.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800547#M170034</link>
      <description>&lt;P&gt;Ahh that makes sense.&lt;/P&gt;
&lt;P&gt;When using the embedded FirePOWER management in the ASA, ASDM will report the native IP address of the FirePOWER module. If you are coming from the outside, you will not likely be able to reach that address via your ASDM htttps session.&lt;/P&gt;
&lt;P&gt;Either the 192.168.16.1 address is not reachable from outside via routing, is NATted with a global interface NAT, or is denied via the implict access-list denying traffic from lower security interfaces (or all three!).&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800547#M170034</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-04T04:52:11Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin!  That was the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800548#M170035</link>
      <description>&lt;P&gt;Thanks Marvin! &amp;nbsp;That was the issue, we are now good to go. &amp;nbsp;Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 14:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-cannot-connect-to-firepower-module/m-p/2800548#M170035</guid>
      <dc:creator>jcopling1</dc:creator>
      <dc:date>2015-12-04T14:16:40Z</dc:date>
    </item>
  </channel>
</rss>

