cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2632
Views
0
Helpful
12
Replies

AMP Private Cloud Sanity Check Failling

peter.peng
Level 1
Level 1

Hi Sir:

   My AMP Private Cloud has below error message and I can't update VDB and IOS. Could you help me to solve this issue ?

螢幕快照 2019-01-06 下午12.20.15.png螢幕快照 2019-01-06 下午12.20.34.png螢幕快照 2019-01-06 下午12.22.37.png

1 Accepted Solution

Accepted Solutions

I believe it does require re-install for that change. It's pretty fundamental with respect to how the VM is built.

View solution in original post

12 Replies 12

Marvin Rhoads
Hall of Fame
Hall of Fame

For an air-gap installation, you must install the amp-sync tool on an Internet-connected Linux PC and use it to download a protect-db snapshot. Then transfer and upload that snapshot to your AMP Private Cloud host as indicated in your third screenshot.

.

https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-private-cloud-virtual-appliance/118336-configure-fireampprivatecloud-00.html#anc11

 

For details on using amp-sync, please refer to Appendix B in the FireAMP Private Cloud User Guide:

 

https://docs.amp.cisco.com/FireAMPPrivateCloudUserGuide-latest.pdf

 

Hi Marvin:

   I had tried to setup it by user guide. It ask me to download it.But It will lost many packet. Does it impact any update AMP private cloud procedure ?

Select the following packages to install:

All -> Net -> curl

All -> Utils -> genisoimage

All -> Utils -> xmlstarlet

Yes it impacts the product operations. As I noted and is specified in the product documentation, "you must install the amp-sync tool on an Internet-connected Linux PC and use it to download a protect-db snapshot".

 

Only after you successfully complete that will you be able to properly operate your AMP Private cloud appliance in air gap mode.

Hi Marvin:

    I had fixed this issue. But I have other question. After I download these files and make a ISO by below command. How to update it to AMP Private Cloud ?

   ./amp-sync package -o newfile.iso

Hi Peter,

 

Please do let me know how you fixed this issue.

Hi Marvin:

   I had found the user guide. It told me:

Attach your ISO file to the device through the Cisco Integrated Management Controller (CIMC) on your appliance, then click Check Update ISO.

  Could I attach the ISO file to the ESXi ? or just only by CIMC ?

Hi Marvin:

   If I setup the Standalone Air Gap Mode. Could I change it to proxy mode? Dos it impact license or any others ?

Air Gap mode is used when the AMP private cloud server is not allowed (usually by policy or regulation) to have Internet connectivity. So you should setup the appliance according to your organization's policy and requirements.

 

If you use Cloud Proxy mode then the license is the same.

 

The setup is a bit simpler and ongoing maintenance is easier since you do not have to regularly download and update the server using the manual method via an external server the way you are struggling with now. Also, the resource requirements for the server are significantly less since much of the analysis functionality is handled in the cloud vs. on your on premise server.

Hi Marvin:

   Thanks for your recommendation. 

So... If I want to change the mode (From Air Gap mode to Proxy mode). The only way is re-install. Right ?

I believe it does require re-install for that change. It's pretty fundamental with respect to how the VM is built.

Hi Marvin:

   Sorry!! Could I confirm one question ?

If I re-install AMP. Should I apply the new License key ?

Re-installation will require re-applying the license.

 

I'm not positive on whether or not you can use the same one - Cisco may have validated the first one and not automatically accept it being presented with what looks like a new server.

 

I'd suggesting contacting the TAC for that one (or you can email licensing@cisco.com).

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card