<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC communication ports &amp;amp; deployment error. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404087#M925854</link>
    <description>&lt;P&gt;Dear Yogdhanu,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;The other alert/warning means that you have included in your rules zones which match interfaces to different device other than the one on which you are deploying so that specific  rule will not match because  the interface does not exist on that device.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so what I understand is the secondary SFR&amp;nbsp;device which is&amp;nbsp;shown in the screenshot have those interfaces and&amp;nbsp;the primary sfr doesn't have, this is what the deployment error is mentioning ???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My firewall 5525-X is in failover mode and working perfect for failover, so this means that all the interfaces are sync and also the sensor are in device group, so whenever the deployment happens it applies to both, but still I get the error why???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it&amp;nbsp;some think that identity policy is not created properly ?? Please find the attached identity policy&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jun 2018 18:04:29 GMT</pubDate>
    <dc:creator>adamgibs7</dc:creator>
    <dc:date>2018-06-22T18:04:29Z</dc:date>
    <item>
      <title>FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3402969#M925852</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;Please find the attached,&lt;/P&gt;
&lt;P&gt;In the communication ports list what is the host input client&amp;nbsp;refers&amp;nbsp;as a &amp;nbsp;bidirectional traffic to FMC, actually what is host input client ??? and what does bidirectional means ??? what I understand by bidirectional is traffic initiated by host to the FMC on port 8307 and the return traffic should come back&amp;nbsp;from FMC&amp;nbsp; Please correct me if I m wrong ????&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;STRONG&gt;&amp;nbsp;OR IT MEANS&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Bidirectional means that both the host input client and FMC&amp;nbsp; can initiate a traffic on destination port 8307.&lt;/P&gt;
&lt;P&gt;Also I would like to know the inbound is referred as destined traffic to FMC and outbound is referred as destined traffic to the remote host ( ldap, radius server etc etc ), Please correct me if I m wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also&amp;nbsp;please find the attached&amp;nbsp;error when I deploy the configuration to the Firepower.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3402969#M925852</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T15:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3403004#M925853</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The communication between FMC and its managed sensor is on TCP port 8305 and not on 8307.&lt;/P&gt;
&lt;P&gt;Its should be open bidirectional which means sensor/FTD can initiate connection on 8305 to FMC and vice versa.&lt;/P&gt;
&lt;P&gt;8307 is not needed for policy deployment. You can get more details from this link about host input client.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/host_identity_sources.html?bookSearch=true#ID-2219-000004f9" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/host_identity_sources.html?bookSearch=true#ID-2219-000004f9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/api/host-input/HostInputAPIGuide/Configuring-HostInputClient.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/api/host-input/HostInputAPIGuide/Configuring-HostInputClient.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other alert/warning means that you have included in your rules zones which match interfaces to different device other than the one on which you are deploying so that specific&amp;nbsp; rule will not match because&amp;nbsp; the interface does not exist on that device.&lt;/P&gt;
&lt;P&gt;You can still proceed with deployment though.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rate it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 01:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3403004#M925853</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-06-21T01:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404087#M925854</link>
      <description>&lt;P&gt;Dear Yogdhanu,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;The other alert/warning means that you have included in your rules zones which match interfaces to different device other than the one on which you are deploying so that specific  rule will not match because  the interface does not exist on that device.&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so what I understand is the secondary SFR&amp;nbsp;device which is&amp;nbsp;shown in the screenshot have those interfaces and&amp;nbsp;the primary sfr doesn't have, this is what the deployment error is mentioning ???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My firewall 5525-X is in failover mode and working perfect for failover, so this means that all the interfaces are sync and also the sensor are in device group, so whenever the deployment happens it applies to both, but still I get the error why???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it&amp;nbsp;some think that identity policy is not created properly ?? Please find the attached identity policy&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 18:04:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404087#M925854</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-06-22T18:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404318#M925855</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its possible that 1 of the SFR does not have correct interface zone mapping. Please be aware that FMC treats both sfr as individual device. So the interface zone mapping has to be done manually on both.&lt;/P&gt;
&lt;P&gt;Once that's done, than you should not get error.&lt;/P&gt;
&lt;P&gt;Not sure about identity policy question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 08:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404318#M925855</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-06-23T08:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404591#M925856</link>
      <description>&lt;P&gt;thanks for the hints and suggestions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2018 20:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3404591#M925856</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-06-24T20:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: FMC communication ports &amp; deployment error.</title>
      <link>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3712571#M925857</link>
      <description>&lt;P&gt;Hi Just wanted to trigger this thread with a doubt.Using here an ASA w/ FP services&lt;/P&gt;
&lt;P&gt;We are unable to deploy policy on the sensor getting error message&amp;nbsp; -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deployment failed due to configuration error. If problem persists after retrying contact Cisco TAC.&lt;/P&gt;
&lt;P&gt;I am getting this is due to devices being in disabled state under device management, if yes how to enable them.&lt;/P&gt;
&lt;P&gt;Also&amp;nbsp;have an alarm under health for missing appliance&amp;nbsp;heartbeats.&lt;/P&gt;
&lt;P&gt;Do provide your insights. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 03:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-communication-ports-amp-deployment-error/m-p/3712571#M925857</guid>
      <dc:creator>mssgrocsupport</dc:creator>
      <dc:date>2018-09-25T03:47:12Z</dc:date>
    </item>
  </channel>
</rss>

