06-09-2023 01:56 AM
Hello,
I` am using FMC 7.0.5, connected Firepower 1120.
Test PC connected to Inside port of Firepower IPS, Outside port watching to the Internet, policy (logging configured) and routing configured. I can connect from the Internet to Test PC which is inside network, but I can not see any incoming connections In Analysis-Connections-Events and when I' am trying to ping 8.8.8.8 From Test PC which is inside this information is available in Connection Events and Intrusion Events menu.
Could you please navigate me, what do I have to check to see incoming events?
Thank you.
06-09-2023 02:00 AM - edited 06-09-2023 02:21 AM
@zmutlu I assume you've enabled logging on all the rules you've configured?
From the CLI of the FTD run the command, system support firewall-engine-debug filter on your test PC IP address, generate traffic to confirm traffic is routed through the FTD and which rule the traffic matched.
06-09-2023 02:28 AM
did you success register the FTD into FMC ?
06-09-2023 02:31 AM
FTD registered in FMC successfully.
06-09-2023 02:35 AM
> sftunnel-status
can you share this
06-09-2023 02:39 AM
You need all of the info or exact info, for example PEER INFO, RUN STATUS?
06-09-2023 03:06 AM
only peer INFO
06-09-2023 02:51 AM
06-09-2023 03:09 AM
sw_version 7.0.5
sw_build 72
Management Interfaces: 1
eth0 (control events) 00.00.00.00,
Peer channel Channel-A is valid type (CONTROL), using 'managemen', connected to '00.00.00.00' via '00.00.00.00'
Peer channel Channel-B is valid type (EVENT), using 'managemen', connected to '00.00.00.00' via '00.00.00.00'
You are not register this FW to FMC
the IP is not appear!!!
06-09-2023 03:13 AM
I removed original IP with 00.00.00.00
06-09-2023 03:24 AM
OK I get it
now show time in FTD and check the time in FMC are both same ?
06-09-2023 03:31 AM
Yes, time is the same on both.
06-09-2023 03:49 AM
security intelligence event <<- can check this see if traffic is BLK by any security policy
06-09-2023 03:52 AM
There are no records at all.
06-09-2023 04:12 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide