06-09-2023 01:56 AM
Hello,
I` am using FMC 7.0.5, connected Firepower 1120.
Test PC connected to Inside port of Firepower IPS, Outside port watching to the Internet, policy (logging configured) and routing configured. I can connect from the Internet to Test PC which is inside network, but I can not see any incoming connections In Analysis-Connections-Events and when I' am trying to ping 8.8.8.8 From Test PC which is inside this information is available in Connection Events and Intrusion Events menu.
Could you please navigate me, what do I have to check to see incoming events?
Thank you.
06-09-2023 05:14 AM
I`ve checked the link you`ve sent, added categories as shown there, deployed configuration to FTD. After created traffic to Test PC and from it, still no any records in Security Intelligence Events.
06-09-2023 09:52 AM
We have had several instances where this issue has presented itself. We fixed this by upgrading the FMC and subsequently FTD to a newer version (I would suggest the starred version listed in the downloads page on cisco.com)
11-21-2023 10:33 AM
we have fmc at 7.2.5 and ftd at 7.0.4 version. Do we need upgrade we face similar issue here
11-22-2023 05:22 AM
There's no issue managing FTD 7.0.4 with FMC 7.2.5 - they are quite compatible.Sometimes upgrades fix broken processes and cuase the issue to resolve "magically". However, this problem (assuming you have a registered device with ACP events properly set to log to FMC) usually is a result of some sort of database or process error. As such, it is best to troubleshoot it with the assistance of Cisco TAC.
06-09-2023 02:28 AM
@Rob Ingram I did that you propose to confirm traffic is routed through the FTD, yes, I can see traffic between on FTD.
Logging is on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide