cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2461
Views
0
Helpful
9
Replies

ASA FirePOWER URL filtering not working - could not download Database

lsladmin
Level 1
Level 1

Connection to service.brightcloud.com and database.brightcloud.com with telnet works finde.
But a database download should not work.

 

SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Returning until retry: 0 equals NUMBER_OF_RETRIES = 2
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Returning until retry: 0 equals NUMBER_OF_RETRIES = 2
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Returning until retry: 1 equals NUMBER_OF_RETRIES = 2
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Returning until retry: 1 equals NUMBER_OF_RETRIES = 2
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Set failure_time to:'1520326105'
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4407]: [4432] CloudAgent:CloudAgent [INFO] Set failure_time to:'1520326105'

9 Replies 9

Marvin Rhoads
Hall of Fame
Hall of Fame

There are some documented bugs you may be hitting.

 

What is your platform and version number?  Has it ever worked?

Hi thanks for your quick answer.
FirePower is running in Version 6.2.1 at our ASA5516.

System Output in FirePower WebUI says:
Model Cisco Firepower Management Center for VMWare
Serial Number None
Software Version 6.2.1 (build 342)
OS Cisco Fire Linux OS 6.2.1 (build6)
Snort Version 2.9.11 GRE (Build 101)
Rule Update Version 2018-02-28-001-vrt
Rulepack Version 2035
Module Pack Version 2313
Geolocation Update Version 2018-02-26-002
VDB Version build 294 ( 2018-02-09 01:06:55 )

Cisco recommends moving off of 6.2.1 and on to 6.2.2. (6.2.2.2 is the latest patch.)

 

There is at least one bug similar to what you are seeing that should be fixed with 6.2.2:

 

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve08525

After updating, still the same problem here.

 

Model	Cisco Firepower Management Center for VMWare
Serial Number	None
Software Version	6.2.2.2 (build 109)
OS	Cisco Fire Linux OS 6.2.2 (build11)
Snort Version	2.9.11 GRE (Build 273)
Rule Update Version	2018-03-05-001-vrt
Rulepack Version	2036
Module Pack Version	2314
Geolocation Update Version	2018-02-26-002
VDB Version	build 294 ( 2018-02-09 01:06:55 )
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Returning until retry: 0 equals NUMBER_OF_RETRIES = 2
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Returning until retry: 0 equals NUMBER_OF_RETRIES = 2
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Returning until retry: 1 equals NUMBER_OF_RETRIES = 2
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Returning until retry: 1 equals NUMBER_OF_RETRIES = 2
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Set failure_time to:'1520404241'
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [WARN] DownloadURLDBFilesOnDC: URL Database update: Malformed message received. Status: -102
SF-IMS[4863]: [4886] CloudAgent:CloudAgent [INFO] Set failure_time to:'1520404241'

It looks like you're either hitting a new bug or you have a corrupted URL database.

 

I'd recommend opening a TAC case to investigate in real time.

 

Please let us know what they say.

Is there a way to reset the database?

I'am very sure that a corrupt database is the problem.

Hello Isladmin

I don't think there is way to reset only the URL database. This error happens only for the URL db download .The error code -102 means its a malformed or corrupted message from the server. We have to check pcaps at points along the path from the server and see where the message is being corrupted. I would recommend a TAC case to investigate it further.

Regards
Jetsy

We could fix the problem.

For anyone who also struggles with this problem.

Firepower Management Center has a proxy option under Configuration --> Management Interfaces.
Our Proxy has blocked the Connection to Brightcloud.

Oh - blocked by your web proxy.

 

I incorrectly assumed it worked in the past.

 

Thanks for letting us know the resolution.

 

 

Review Cisco Networking for a $25 gift card