01-08-2020 11:21 AM
Hi,
We have two Firepower 4110 units that only have 2 logical interfaces. One is from a Gigamon tap and configured as a passive interfaces and the other is the management interface. We are using these units essentially as out of band IDS units. They had been working just fine until the upgrade to 6.4.0.4. Now after a period of time both of them report in FMC that there are no packets being received on either of the two interfaces. If you connect to the FTD CLI and issue a "show interface" command from clish, the interfaces have no input or output packets. Also, we don't see any syslog being generated by the units indicating that its doing anything. The only way I have found to resolve this is to restart the FTD application from the FXOS Chassis Manager. Bouncing the interfaces within FXOS, FTD, or from the switch side doesn't seem to do anything. I have generated troubleshoot files for both units but they are too large to upload to service now. The odd part is that event management interfaces appear to not be passing traffic, but I can SSH into the IP address on the management interface to get to clish. I have attached screenshots for review. Any assistance in this matter would be greatly appreciated.
Thanks
01-09-2020 02:49 AM
Hello Quintin,
Have you confirmed that the Switch keeps sending the packets?
If yes, this really seems to be a Bug, and it is not filled yet, open a TAC Case and attach the TShoot files.
BR,
Luiz
01-09-2020 09:20 PM
Hi there, a couple of questions:
1. Are the units standalone or setup in H/A?
2. Can you run the following commands and post back the outputs:
show asp drop
!
show asp inspect-dp egress-optimization
!
show blocks
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide