<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After re-image FPR2110 from FTD to ASA9.8.2, the device mgmt interface UI become &amp;quot;Forbidden- you don't have permission to access / on this server&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/after-re-image-fpr2110-from-ftd-to-asa9-8-2-the-device-mgmt/m-p/3362838#M924138</link>
    <description>&lt;P&gt;Found errors logged on ASDM as following HTTPS access 403 forbidden error.&lt;/P&gt;
&lt;P&gt;authz_core:error&amp;nbsp;AH01630:client denied by server configuration:/isan/apache/&lt;/P&gt;
&lt;P&gt;(70014)Enf of file found: AH01991:SSL input filter read failed.&lt;/P&gt;
&lt;P&gt;...etc&lt;/P&gt;
&lt;P&gt;I also verified on CLI firepower /system/services/ip-block,&amp;nbsp; my origin IP is included and same setting for https and ssh.&lt;/P&gt;
&lt;P&gt;I also tried to disable /system/services/https and re-enable. No diff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Last choice, I&amp;nbsp;upgrade it from 9.8.2 to 9.9.1.3&lt;/P&gt;
&lt;P&gt;firepower /firmware/auto-install # install security-pack version 9.9.1.3&lt;/P&gt;
&lt;P&gt;it took about&amp;nbsp;5&amp;nbsp;minutes to install and reboot. FDM came back OK without any other changes..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lesson learned: because FPR2100 image is FXOS+ASA bundle, it's better choose latest ASA version to keep FXOS up-to-date.&amp;nbsp; I'm looking at 9.9.2 now.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Apr 2018 15:58:53 GMT</pubDate>
    <dc:creator>fraserC</dc:creator>
    <dc:date>2018-04-09T15:58:53Z</dc:date>
    <item>
      <title>After re-image FPR2110 from FTD to ASA9.8.2, the device mgmt interface UI become "Forbidden- you don't have permission to access / on this server"</title>
      <link>https://community.cisco.com/t5/network-security/after-re-image-fpr2110-from-ftd-to-asa9-8-2-the-device-mgmt/m-p/3362067#M924137</link>
      <description>&lt;P&gt;I'm not sure if this is by design.&amp;nbsp; Anybody else run into this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After re-image FPR2110 from FTD to ASA9.8.2, the&amp;nbsp;chassis (FXOS)&amp;nbsp;mgmt interface UI become "Forbidden- you don't have permission to access / on this server"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://mgmt-ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSH into FXOS mgmt IP works.&amp;nbsp; SSH &amp;amp; HTTPS to ASA mgmt IP also works. It's just HTTPS to FXOS chassis mgmt UI doesn't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;~Fraser&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/after-re-image-fpr2110-from-ftd-to-asa9-8-2-the-device-mgmt/m-p/3362067#M924137</guid>
      <dc:creator>fraserC</dc:creator>
      <dc:date>2020-02-21T15:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: After re-image FPR2110 from FTD to ASA9.8.2, the device mgmt interface UI become "Forbidden- you don't have permission to access / on this server"</title>
      <link>https://community.cisco.com/t5/network-security/after-re-image-fpr2110-from-ftd-to-asa9-8-2-the-device-mgmt/m-p/3362838#M924138</link>
      <description>&lt;P&gt;Found errors logged on ASDM as following HTTPS access 403 forbidden error.&lt;/P&gt;
&lt;P&gt;authz_core:error&amp;nbsp;AH01630:client denied by server configuration:/isan/apache/&lt;/P&gt;
&lt;P&gt;(70014)Enf of file found: AH01991:SSL input filter read failed.&lt;/P&gt;
&lt;P&gt;...etc&lt;/P&gt;
&lt;P&gt;I also verified on CLI firepower /system/services/ip-block,&amp;nbsp; my origin IP is included and same setting for https and ssh.&lt;/P&gt;
&lt;P&gt;I also tried to disable /system/services/https and re-enable. No diff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Last choice, I&amp;nbsp;upgrade it from 9.8.2 to 9.9.1.3&lt;/P&gt;
&lt;P&gt;firepower /firmware/auto-install # install security-pack version 9.9.1.3&lt;/P&gt;
&lt;P&gt;it took about&amp;nbsp;5&amp;nbsp;minutes to install and reboot. FDM came back OK without any other changes..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lesson learned: because FPR2100 image is FXOS+ASA bundle, it's better choose latest ASA version to keep FXOS up-to-date.&amp;nbsp; I'm looking at 9.9.2 now.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 15:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/after-re-image-fpr2110-from-ftd-to-asa9-8-2-the-device-mgmt/m-p/3362838#M924138</guid>
      <dc:creator>fraserC</dc:creator>
      <dc:date>2018-04-09T15:58:53Z</dc:date>
    </item>
  </channel>
</rss>

