cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
580
Views
0
Helpful
3
Replies

FMC_FTD registration

Dkiptoo
Level 1
Level 1

We have FMC v 7.2.3 currently managing  2 ftd 4145 instances. The management was all well until when i recently discovered that one instance is not visible on the fmc.  Checked manager status on the instance and it shows registration pending as indicated below.  I have also included a snapshot of error messages from the log. Currently the firewall is up and running , it is onlu the management that we cannot do. I have tried workarounds and  the option is to delete manager and add with a new registration key defined on the FMC. I would like to get some clarifications  and any possible workaround because my fear is loosing all policies and configurations earlier pushed via the FMC if I delete and add the manager. We however have the policies already on the FMC. Is there a safer way to bring back the instance to the fmc without any loss on configurations? 

Dkiptoo_0-1761296666426.png

Dkiptoo_1-1761296677840.png

 

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

FMC configuration will not be lost, so you do not need to worry about that.

Make sure path between FTD and FMC there is no blockers and it should be reachable.

try ping each other and see if that works.  have you done any recent upgrades ? what version of FTD ? is the 2 FTD in HA or standalone.

troubleshooting guide :

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215540-configure-verify-and-troubleshoot-firep.html

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

The instance can ping fmc successfully however telneting to portsftunnel port from that instance refuses. No any recent upgrades. Both are running version 7.2.3 then finally the two instances are not in HA. One as perimeter and another as campus. The one not currently visible is the perimeter instance. They both run on 4241 appliance.

May take maintenance window (follow MS polices - reboot and check) recently seen cisco device need to be reboot to fix some issue, it was not the case decade back, but truth is this, another option test it.

check is the device listening the ports :

$ netstat -na | grep 8305

I posted above some troubleshooting, see if the traffic hitting from FMC to FTD ? or vice-versa ?

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card