cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3937
Views
4
Helpful
19
Replies

Can not see incoming connection events in FMC

zmutlu
Level 1
Level 1

Hello, 

I` am using FMC 7.0.5, connected Firepower 1120.

Test PC connected to Inside port of Firepower IPS, Outside port watching to the Internet, policy (logging configured) and routing configured. I can connect from the Internet to Test PC which is inside network, but I can not see any incoming connections In Analysis-Connections-Events and when I' am trying to ping 8.8.8.8 From Test PC which is inside this information is available in Connection Events and Intrusion Events menu.

Could you please navigate me, what do I have to check to see incoming events?

Thank you. 

19 Replies 19

@zmutlu I assume you've enabled logging on all the rules you've configured?

From the CLI of the FTD run the command, system support firewall-engine-debug filter on your test PC IP address, generate traffic to confirm traffic is routed through the FTD and which rule the traffic matched.

did you success register the FTD into FMC ?

FTD registered in FMC successfully.

> sftunnel-status

can you share this  

You need all of the info or exact info, for example PEER INFO, RUN STATUS?

only peer INFO 

Here is info in attached file.

sw_version 7.0.5
	sw_build 72
	Management Interfaces: 1
	eth0 (control events) 00.00.00.00,
	Peer channel Channel-A is valid  type (CONTROL), using 'managemen', connected to '00.00.00.00' via '00.00.00.00'
	Peer channel Channel-B is valid  type (EVENT), using 'managemen', connected to '00.00.00.00' via '00.00.00.00'

You are not register this FW to FMC 
the IP is not appear!!! 

I removed original IP with 00.00.00.00

OK I get it 
now show time in FTD and check the time in FMC are both same ?

Yes, time is the same on both.

security intelligence event <<- can check this see if traffic is BLK by any security policy 

There are no records at all.

Review Cisco Networking for a $25 gift card