09-25-2014 09:39 AM - edited 03-12-2019 05:35 AM
I am failing to register my ASA with Sourcefire module. I see in the V DC that the syslog says it connected to the module successfully, but fails to authenticate
“sftunneld:sf_ssl [WARN] VerifyConnect:Failed to authenticate or to be authenticated by peer”
10-01-2014 06:33 AM
Verify that the key being used to configure the manager on the SFR module and the key entered when registering the SFR Module as a Device in Defense Center are the same.
01-28-2015 03:37 AM
Dear all,
I had to open a TAC about this. The problem was that, after a forced power reload of the ASAs, a file "sftunnel.conf" got corrupted. It seems that this file is responsible for the the communication service between the Manager and the SFR. If the service is down then the SFR does not listen on TCP/8305. So the TAC engineer stopped the service, deleted the corrupted file, recreated it and restarted the service. All these from the expert CLI mode of the SFR.
01-28-2015 04:18 AM
Thanks a lot for information Michael.
Do you remember the process to recreate that file?
01-28-2015 05:02 AM
Hello Oleg,
I logged the TAC engineer's session so here it is (see attached tac_session_log.txt). Though, you will need the root password to be able to perform what he did.
He sent me the text file sftunnel.conf (included in sftunnel.zip), browsed in /etc/sf/ and created the file named sftunnel.conf with vi editor, where he copy-pasted the text from the file he had sent me.
I hope that helps.
01-28-2015 05:10 AM
Great.
It's working!)
I had exactly the same issue.
Thanks a lot.
02-07-2015 12:17 AM
It did not worked for me. I get access denied at on one point of the process. If i reimage the module, will that help? Or i will have yhe same issue?
02-07-2015 04:36 AM
I re-imaged my module after suffering this problem and afterwards it worked perfectly.
02-07-2015 09:24 AM
I will do that as well, on Monday and let you know of the results!
02-07-2015 09:35 AM
Hello.
Can anyone try to deny youtube.com by using sfr?
I did such test that fail for me because it's not blocking when I try to access site using Internet Explorer.
02-09-2015 10:12 AM
You are rigth!!!!
it is working now as well!!!
06-11-2015 11:50 AM
This fixed my problem. Straight up awesome! Thanks!
07-28-2015 01:07 PM
Had the same issue. Followed the instructions on how to edit in VI then pasted the attached sftunnel.conf and saved. Module registered instantly.
Thanks
11-14-2014 04:51 AM
When I try to configure the manager on the ASA SFR, it returns the following error:
"Communication channel for management interface is not configured!"
01-23-2015 08:53 AM
Hi Michael,
Did you figure this one out?
I get exactly the same on my ASA SFR.
"Communication channel for management interface is not configured!"
Thanks
John
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide