09-08-2025 11:21 PM
Hi, facing this issue when trying to add the same FTD agian in the FMC after deleting it.
Any help would be appreciated.
Thanks.
09-08-2025 11:39 PM
That error usually happens when the FTD still has the old CA/certificate record from the previous FMC registration. When you try to re-add it, FMC can’t issue a new cert because the device still presents the stale identity.
Fix is to clear the old registration info on the FTD and then re-register clean:
On the FTD CLI run:
configure manager delete
to wipe the FMC registration state.
If you use NAT, also re-apply the correct configure manager add <fmc_ip> <reg_key>
.
Then go back to FMC and add the device again with the same key and management IP.
That forces the device to generate a new cert request and FMC will accept it. If it still fails, make sure the clock/timezone are in sync on both FMC and FTD, because mismatched time can also break certificate enrollment.
–––
Best regards,
Stefan Mihajlov
Mark this post as Helpful if it helped you, and Accept as Solution if it resolved your question.
09-09-2025 01:42 AM
Delete or unregistered?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide