- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2016 04:16 AM - edited 03-12-2019 06:03 AM
Hello! I have a lot of problems with firepower and can not to configure it. I have an error on sensor. What it si mean? Help me please!
Solved! Go to Solution.
- Labels:
-
NGIPS
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 04:08 AM
Hello Team,
As i guessed the issue is with the communication channels in the sensor.
Sftunnel is the main communication channel between the FMC and sensor.
Here you can see the service is down and thus you cannot push upgrade as well as cannot reapply the AC policy.
Please try restarting the service by elevate as root user.
pmtool enablebyid sftunnel
Verify the status once again.
If its still down, please try resatrting the same.
pmtool restartbyid sftunnel
Rate if this answer helps you.
Regards
Jetsy

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 11:53 PM
Hello Team,
Glad to know that it worked well.
Feel free to use Cisco Support forums.
Kindly Rate and mark the answers correct if you feel my posts helped you .
Regards
jetsy

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2016 10:07 AM
Hi,
What hardware model is this ?
By error are you referring to the green light on the warning icon (Triangle with exclamation) ?
Thanks,
Pujita
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-27-2016 11:05 PM
model 7100,yes- what is mean - green light on the warning icon?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2016 02:42 AM
I have Fatal RPC Error when i try to apply device changes.What it is mean?
I have Defense Center running software version: 5.4.1.7
And if I login to Sensor I see Sourcefire Linux OS v5.3.0 (build 63). May be it is problem? How I can update sensor if it posible? Thank you!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2016 07:24 AM
Hello,
I see you are using FP7000 series on v5.3.x and the same is managed via FMC running 5.4.1.7. I see a compatibility issue here and we should first fix this issue.
Please upgrade to 5.4.0.6 or higher, in order to manage via FMC running 5.4.1.7.
Attaching compatibility table for your reference.
Here is more about the same :
http://www.cisco.com/c/en/us/td/docs/security/firesight/5408/relnotes/FireSIGHT-System-Release-Notes-version5408-and-5417.html#pgfId-649471
Thanks & Regards,
Pujita
Please rate this post and mark answered if it helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2016 07:59 AM
THANK YOU!!! I try to do that! I neet to update from my fire power sensor from v5.3.0 ti 5.4!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2016 09:56 AM
Hi,
Yes, you will need to update it from 5.3.0 to 5.4.0.6
The upgrade path will be:
1: Upgrade to 5.3.0
2: Upgrade to 5.3.0.1
3: Upgrade to 5.4.0
4: Upgrade to 5.4.0.6
Thanks,
Pujita
Rate the post if it helps.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-28-2016 11:21 PM
Hello Team,
Whenever you upgrade, please refer the release notes.
- FireSIGHT System Release Notes, Version 5.4.0.6 and Version 5.4.1.5
http://www.cisco.com/c/en/us/td/docs/security/firesight/5406/relnotes/FireSIGHT-System-Release-Notes-version5406-and-5415.html
- FireSIGHT System Release Notes, Version 5.4
http://www.cisco.com/c/en/us/td/docs/security/firesight/540/relnotes/FireSIGHT-System-Release-Notes-v5-4.html
- Sourcefire 3D System Release Notes, Version 5.3.0.1:
http://www.cisco.com/c/dam/en/us/td/docs/security/sourcefire/3d-system/53/Sourcefire_3D_System_5301_Release_Notes.pdf
- Sourcefire 3D System User Guide, Version 5.3.0
http://www.cisco.com/c/dam/en/us/td/docs/security/sourcefire/3d-system/53/Sourcefire_3D_System_User_Guide_v53.pdf
Rate if this post helps you.
Regards
Jetsy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 12:05 AM
Ok! I try and see in firesight that i have version -5.3.0.3. And I find that the system offers me to update the device -Sourcefire 3D Device S3 Patch 5.3.0.8-15. I try to update but it is faild.
Now I download update Sourcefire 3D Device S3 Patch 5.3.0.4 and trying to install it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 12:39 AM
Unfortunately I have problems! (My version 5.3.0.3)
1.If i try ti install updates From FireSight - it is faild.
2.If i try ti upload updates from archive (5.3.0.4-9.sh)- Upload failed: Update package is corrupt.
3.I try to upload 5.4.0-763 - is uploaded and I try to install it - it is faild too.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 01:20 AM
Hello Team,
It looks like some communication issues are there.
To verify it can you try reapplying the policies once to see if it will be successful or not. If its not successful , please check if there is any RPC timeouts are there or connectivity issues exist.
Regards
Jetsy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 03:34 AM
O! There is no problem with connections beetween FireSight and Sensor. both see each other. But they in difference vlan. May be problem with it?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 03:34 AM
Does the policy reapply was fine ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 03:45 AM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-29-2016 03:49 AM
Hello Team,
Can you see if the patch got pushed to the device by checking /var/sf/Upgrade Directory of the desired version.
If it didnt even get pushed verify the following from sensor CLI :-
pmtool status |grep sftunnel
pmtool status |grep SFData
Regards
Jetsy
