02-01-2023 01:49 AM
Hello everyone,
we are affected by this bug CSCvx89643 and there is only a workaround to fix it: whitelist the certificate on webproxy.
https://bst.cisco.com/bugsearch/bug/CSCvx89643
How do we do that?
Regards
02-01-2023 08:45 AM
i have this error pops up once in a while, what i did is i just leave it there and the error will just go away.
02-01-2023 02:22 PM
What version FMC are you running? is the error persistent or does it go away after a while?
If you are indeed hitting this bug, you should have a webproxy server between the FMC and the internet, meaning you need to whitelist the certificate on that webproxy sever. This should be done by whoever is the administrator of the webproxy server.
02-02-2023 01:59 AM
Hello,
the version of MC is 6.7.0.
I just confirmed that there is no proxy between the FMC and the internet. We are receiving the same error message indicated in the bug. We have seen that the Cisco-DNS-and-URL-Intelligence feed hasn´t been update since June from ´22.
Regards
02-02-2023 02:20 AM
@SupportAC perhaps related to this - https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html
Affected Firepower platforms will be unable to receive the latest Talos intelligence feeds (IPs, URLs, DNS Hosts).
If impacted, as you are running 6.7.0 to resolve this issue you'd need to upgrade to 6.7.0.3 at a minimum. However 7.0.5 is the current recommended version.
02-02-2023 02:57 AM
Verify that the certificate that the FMC is using to contact tools.cisco.com is still valid. Check the following link for the field notice and how to correct the issue if this is indeed what you are hitting. I know that the only truely corrected version for this field notice is 7.x
https://www.cisco.com/c/en/us/support/docs/field-notices/721/fn72103.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide