cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3108
Views
0
Helpful
8
Replies

FMC 7.1 Policy Search not working

ida71
Level 1
Level 1

I was advised by TAC to upgrade some v7.0.1 2140's to v7.1 to bypass some Snort2+3 Bugs.

This obviously involved upgrading the appliance FMC 1600 to v7.1 first, which went fine, but now when I open a Policy, the search bar function does not work. By that I mean if I type something in the search box that I can see on the screen below in a rule, it returns 0 results. Even if I open search & pick a specific item, like SRC or Service it still returns 0 results which is NOT helpful.

 

I have tried using Chrome & Firefox browsers, so it does not appear to be browser related.

 

Any insights ?

 

Thanks

8 Replies 8

cbond2399
Level 1
Level 1

We are also seeing this issue on 7.1.0.1 (build 28), we just recently upgrade because of an issue cisco tac recommended (failed deployment at 83% snort 3 issue). Which is now fixed with this update but now can not search policy rules.

Cisco TAC fixed the search issue for me by restarting the SQL DB services. You might try rebooting the FMC's might have the same effect. We have FMC1600 appliances in HA mode, after both have been rebooted twice, once at upgrade & once since, they are working better, still slow & pretty crap IMO, but better than before the second set of reboots.

can you please share the steps to restart the SQL DB services.

I would share if I had the info, the restart was performed by a TAC engineer in the course of her diagnostics, I did not note the sequence, as she was trying many things before she found the fix.  But it is run as root using pmtool, you can read about that here https://dependencyhell.net/2021/ftd-process-management

This is the commands

You need log into the FMC as root.

rm -r /var/opt/CSCOpx/MDC/search/

pmtool restartbyid DCCSM

 

can you please share the steps to restart the SQL DB services.

 

cbond2399
Level 1
Level 1

oh, interesting thanks. I will test that out tonight and see if it will fix our issue. 

so the reboot did not fix my issue, I am going to put a tac ticket in to see what they can do. 

Review Cisco Networking for a $25 gift card