11-07-2025
08:33 AM
- last edited on
11-07-2025
08:45 AM
by
frsierra
Hello, am abit new to Firepower configuration.. We have two ftd instances, one as campus and another as perimeter, both managed from fmc. The the two instances share routes via ospf peering, and bgp retribution also configured.The problem am facing is that campus instance is not sharing sharing route with perimeter instance. When check ospf neighbour, nothing on both instances. I suspect is the main issue but now wondering how to go about it. What should I check on the two instances. Interestingly, the perimeter can ping campus, but vise versa fails.
Solved! Go to Solution.
11-10-2025 07:21 AM
Could you please share your OSPF sanitized configurations on both ends for review? it could be a mismatch value between the two ends that is causing the neighborship to fail.
11-07-2025 10:18 AM
important questions here are:
- has it worked before ?
- what has changed ?
a firewall (as it is a firewall) may be configured to NOT reply to icm-echo packets
-> check the policies if icmp-echo (and reply) are allowed.
managed by fmc ? -> does fmc throw any warnings ? like out of sync ?
-> if so there have been modifications to the FTD manually (not using FMC) => compare FMC policies and running FTD.
if necessary resync.
11-07-2025 11:18 AM
A bit confused here. Is the OSPF neighbour up? Post the show ospf neigh out here,
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
11-07-2025 11:10 PM
No neighbour adjacency between the two neighbours
11-08-2025 02:04 AM
then we need more information and check in the patch what is Blocking, any Firewalls ?
troubleshooting guide in general
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13699-29.html
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
11-10-2025 07:21 AM
Could you please share your OSPF sanitized configurations on both ends for review? it could be a mismatch value between the two ends that is causing the neighborship to fail.
11-10-2025 12:16 PM
Actually I restored an FMC back up that had all configurations after realising that it was a misconfig on one of the instance. Now the new back up unfortunately is not registered to smart license account and therfore cannot deploy the configs to the ftd instance. The current management network, which I believe is also supposed to be the gateway to Cisco smart licensing server currently doesn't have Internet access due to next hops routing issues. How do I reconfigure the management network gateway to allow the instance to access smart licensing server for registration? The only routes present on the ftd are local, with one to the the ISP router, therefore can ping ISP public IP
11-11-2025 01:21 AM
Could you please share a draft topology of your network for review?
11-11-2025 01:02 AM
there is still the possibility to activate the license using a file
it requires multiple steps, create request/ transfer to license server, generate file, transfer to FTD and activate
search smart-licensing for air-gap deployment
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide