<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sftunnel SSL handshake failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/2971652#M43446</link>
    <description>&lt;P&gt;We recently began receiving the following sftunnel SSL errors on several FirePower devices. &amp;nbsp;Devices have lost their connection to the FireSight and cannot be registered. &amp;nbsp;Thanks in advance, for any helpful information you can provide.&lt;/P&gt;
&lt;P&gt;Excerpt from /var/log/messages provided below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;/var/log/messages on FirePower:&lt;/STRONG&gt;&lt;BR /&gt;Nov 8 00:09:06 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7936] sftunneld:sf_ssl [ERROR] Accept:SSL handshake failed &lt;BR /&gt;Nov 8 00:09:06 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7936] sftunneld:sf_ssl [WARN] SSL Verification status: ok &lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [INFO] Processing connection from &amp;lt;FireSight_IP&amp;gt;:55444/tcp (socket 10)&lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [ERROR] Accept:SSL handshake failed &lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [WARN] SSL Verification status: ok &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7646] sftunneld:sf_ssl [ERROR] Unable to connect to port 8305 (IPv4): Connection timed out &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;FireSight_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;FireSight_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:12:45 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [ERROR] Unable to connect to port 8305 (IPv4): Connection timed out &lt;BR /&gt;Nov 8 00:12:54 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [8268] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;FireSight_IP&amp;gt; &lt;BR /&gt;Nov 8 00:12:54 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [8268] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;FireSight_IP&amp;gt;:8305/tcp&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;/var/log/messages on FireSight:&lt;/STRONG&gt;&lt;BR /&gt;Nov 8 00:09:21 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11439] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:22 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11439] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;sensor_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Connected to port 8305 (IPv4): &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:29 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1855]: [1855] sfmgr:sfmanager [INFO] set peer PEER_REMOVED pending &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1855]: [1855] sfmgr:sfmanager [INFO] free_peer &amp;lt;sensor_IP&amp;gt;.&lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;sensor_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [1854] sftunneld:sftunnel [INFO] set peer PEER_REMOVED &amp;lt;sensor_IP&amp;gt; pending &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Connected to port 8305 (IPv4): &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:42:46 GMT</pubDate>
    <dc:creator>Cory Brown</dc:creator>
    <dc:date>2019-03-10T13:42:46Z</dc:date>
    <item>
      <title>sftunnel SSL handshake failed</title>
      <link>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/2971652#M43446</link>
      <description>&lt;P&gt;We recently began receiving the following sftunnel SSL errors on several FirePower devices. &amp;nbsp;Devices have lost their connection to the FireSight and cannot be registered. &amp;nbsp;Thanks in advance, for any helpful information you can provide.&lt;/P&gt;
&lt;P&gt;Excerpt from /var/log/messages provided below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;/var/log/messages on FirePower:&lt;/STRONG&gt;&lt;BR /&gt;Nov 8 00:09:06 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7936] sftunneld:sf_ssl [ERROR] Accept:SSL handshake failed &lt;BR /&gt;Nov 8 00:09:06 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7936] sftunneld:sf_ssl [WARN] SSL Verification status: ok &lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [INFO] Processing connection from &amp;lt;FireSight_IP&amp;gt;:55444/tcp (socket 10)&lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [ERROR] Accept:SSL handshake failed &lt;BR /&gt;Nov 8 00:09:13 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7948] sftunneld:sf_ssl [WARN] SSL Verification status: ok &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7646] sftunneld:sf_ssl [ERROR] Unable to connect to port 8305 (IPv4): Connection timed out &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;FireSight_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;FireSight_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:12:45 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [7985] sftunneld:sf_ssl [ERROR] Unable to connect to port 8305 (IPv4): Connection timed out &lt;BR /&gt;Nov 8 00:12:54 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [8268] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;FireSight_IP&amp;gt; &lt;BR /&gt;Nov 8 00:12:54 &amp;lt;FirePower_hostname&amp;gt;SF-IMS[7636]: [8268] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;FireSight_IP&amp;gt;:8305/tcp&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;/var/log/messages on FireSight:&lt;/STRONG&gt;&lt;BR /&gt;Nov 8 00:09:21 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11439] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:22 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11439] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;sensor_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Connected to port 8305 (IPv4): &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:28 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:29 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11446] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1855]: [1855] sfmgr:sfmanager [INFO] set peer PEER_REMOVED pending &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1855]: [1855] sfmgr:sfmanager [INFO] free_peer &amp;lt;sensor_IP&amp;gt;.&lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Initiate IPv4 connection to &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Initiating IPv4 connection to &amp;lt;sensor_IP&amp;gt;:8305/tcp &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [1854] sftunneld:sftunnel [INFO] set peer PEER_REMOVED &amp;lt;sensor_IP&amp;gt; pending &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Connected to port 8305 (IPv4): &amp;lt;sensor_IP&amp;gt; &lt;BR /&gt;Nov 8 00:09:35 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_ssl [INFO] Connected to &amp;lt;sensor_IP&amp;gt;:8305 (IPv4) &lt;BR /&gt;Nov 8 00:09:36 &amp;lt;FIRESIGHT_HOSTNAME&amp;gt; SF-IMS[1854]: [11531] sftunneld:sf_peers [INFO] Delete:Free SSL_CONTEXT for peer &amp;lt;sensor_IP&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/2971652#M43446</guid>
      <dc:creator>Cory Brown</dc:creator>
      <dc:date>2019-03-10T13:42:46Z</dc:date>
    </item>
    <item>
      <title>Has anything changed in your</title>
      <link>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/2971653#M43449</link>
      <description>&lt;P&gt;Has anything changed in your environment recently (fmc / sensor upgrade?). You said that device could not be registered - so have they not been added to the fmc yet or are they just not able to reconnect?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In any case check your manager configuration on sensor side (fqdn used? -&amp;gt; maybe dns issues) and try to restart the sftunnel process on both sensor and fmc... Normally FMC should connect in &amp;lt; 5min to the sensor &amp;nbsp;again successfully.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Restart sftunnel via pmtool: pmtool restartById sftunnel&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 22:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/2971653#M43449</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-11-10T22:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: sftunnel SSL handshake failed</title>
      <link>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/4917502#M1104000</link>
      <description>&lt;P&gt;Experiences the same issue on FMC and FTD on version 7.2.4. &lt;BR /&gt;&lt;BR /&gt;After I issued the "pmtool restartById sftunnel" on both sides, the registration went through with success.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 20:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sftunnel-ssl-handshake-failed/m-p/4917502#M1104000</guid>
      <dc:creator>A.Foerby</dc:creator>
      <dc:date>2023-09-04T20:05:18Z</dc:date>
    </item>
  </channel>
</rss>

