01-19-2024 01:34 AM
Moring/Afternoon/Evening all
Been given a Firepower 1010 to setup and we are going to be using it with Cisco Defense Orchestrator but i'm having issues with the device being seen by CDO.
This is likely going to be something simple but i've been looking at it all week and now just blinded i feel.
Nothing fancy in the setup... ISP router set static into interface1/1
will have a printer into one of the interfaces and 2 AP's in the POE interfaces and that is pretty much it.
Testing i've connected an AP and a laptop and both get an IP address from DHCP and access the internet fine but... NTP servers cannot be reached, i've tried default and customs.
Trying to link to the CDO (which is currently trying to claim the device) gives the error "failed to resolve cloud services FQDN. Check network connectivity and DNS config and retry".
Added a few pictures, if you need anything else then let me know and i'll grab it.
I do have a case open with Cisco but with the time difference, i'm trying to see if i can get it resolved as it must be something stupid i'm missing. i did ask the tech if it was anything to do with NAT/Access/Static routing but he said it all was fine...
Thanks for any help with this as its driving me insane.
01-19-2024 01:41 AM
failed to resolve cloud services FQDN<<-
can I see show network
show manager
MHM
01-19-2024 02:26 AM
01-19-2024 02:31 AM - edited 01-19-2024 02:31 AM
can you ping these DNS server appear in show network ?
MHM
01-19-2024 02:37 AM
> ping 208.67.222.222
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 208.67.222.222, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
> ping 208.67.220.220
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 208.67.220.220, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/8/10 ms
> ping 2620:119:35::35
Please use 'CTRL+C' to cancel/abort...
Sending 5, 100-byte ICMP Echos to 2620:119:35::35, timeout is 2 seconds:
No route to host 2620:119:35::35
seems like can't ping the last one
01-19-2024 03:48 AM
01-19-2024 04:09 AM - edited 01-19-2024 10:01 AM
that said... now the devices are not getting internet access now... they get an IP address in the DHCP range. CDO can see and has onboarded the FPR1010.
feel like i'm missing something now with routing or access control
01-23-2024 04:21 AM
@MHM Cisco World
any idea's??
got the device back onto CDO using 7.2.5 FTD
Devices are getting an ip address but no internet traffic is going through.
tried changing default action to trust traffic in access control but still no internet traffic.
02-28-2024 06:23 AM
From your show managers output It looks like you are using FDM to manage? Or did you use FDM to onboard to cdFMC and that is now the manager?
Also looking at the tshooting above, I would offer the following advice:
To test MANAGEMENT plane internet access and dns resolution, be it using the management port or the data-plane for management default gateway, use the keyword "system". Without "system", you are testing the data-plane's connectivity.
ping system 8.8.8.8
ping system cisco.com
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide