11-11-2020 06:23 AM - edited 11-11-2020 06:27 AM
I am trying to activate my smart licenses, but I have the following message, I think it is a configuration error, but I could not understand what it is, my firepower 2130 has ping to tools.cisco.com.
Solved! Go to Solution.
11-11-2020 09:47 AM
The address must be reachable from the management interface. Try "ping system tools.cisco.com" to confirm that.
Also, the gateway mentioned in your screen shot error message would be whatever is configured as the default route for the data interface. Try "show route" to confirm that.
11-11-2020 09:47 AM
The address must be reachable from the management interface. Try "ping system tools.cisco.com" to confirm that.
Also, the gateway mentioned in your screen shot error message would be whatever is configured as the default route for the data interface. Try "show route" to confirm that.
03-02-2021 01:00 AM
Hello everyone,
this is my first post in this forum
I lose my mind - Im struggling with the most basic things and hope to get some clarifications/guidance in this thread. I recently bought a FIREPOWER 1010 and try to get the box started. However, I have the same issue as described in this thread I cannot activate my smart licenses because "Gateway cannot be reached through port Ethernet1/1 named “outside”.
To my physical cable connections:
my router (Telekom Speedport pro 192.168.1.2) and port1 of my firepower are connected via a Zyxel GS-1900 48HP (192.168.1.101) Switch (I also tried to connect it directly - didn t work either).
In the IP router table i can see the firepower under 192.168.1.114. However, I cannot ping this IP nor can i ping from the inside (CLI from 192.168.1.1) to the outside.
In the attachment you see the routes I have set so far.
Does anyone know what Iam missing?
Kind regards
Sandro
03-02-2021 04:18 AM - edited 03-02-2021 04:19 AM
It looks like you have the 192.168.1.0/24 network defined on both the inside and outside. Those need to be on different subnets.
Also, you haven't shared the management setup ("show network" from the cli).
03-02-2021 12:02 PM
Hi Marvin,
many thanks for your quick response.
Im sorry i don t know how to upload screenshots other than in the word document i have uploaded in my previous post. Are you able to open it?
So you are saying my gateway (router), switch (eg 192.168.1.0/24) and so on need to be on another subnet than the firepower (inside eg 192.168.45.0/24). But in this case I should be able to access the internet via the management port, right? Im just asking because even there I have the same error.
Kind regards,
Sandro
03-07-2021 04:59 AM
03-07-2021 06:33 PM
Each interface of the firewall must be in a different subnet. You have the inside and outside interfaces in the same subnet. Since outside appears to be DHCP-addressed, you must change your inside subnet from the default 192.168.1.0/24 to something unique.
The getting started guide for these devices is really quite thorough and should be followed, adjusting to suit your conditions.
03-08-2021 05:01 AM
thank you so much !!! That was the trick!!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide