09-21-2022 12:48 AM
We have a HA pair of ASA 5508-X configured as active/standby and installed FirePower on each device.
In FMC, we get the error "Interface 'DataplaneInterface0' is not receiving any packets" for the standby device as below.
Do you have any other approach/ideas to resolve the issue?
Thank you in advance.
09-21-2022 01:30 AM
The standby unit not receiving any packets/traffic, the detail is that this alert is normal. Although we know that the ASA's are in HA, the SFR modules are registered separately in the FMC, for this reason the FMC does not know that these modules[Firepower] are part of an HA.
The module [Firepower] installed on the standby ASA is not processing traffic, which is why this alert appears.
If you want to eliminate this alert, you need to disable interface monitoring, inside health policy.
09-21-2022 01:59 AM
Thank you for your answer. I have a few question.
Will we find the same alert on the Primary device if there is a failover?
Do we need to manually edit the interface monitoring all the time?
09-21-2022 02:32 AM
Correct. We run number of HA pair firewall. is there is specific ask for it why you want to disable/edit the monitoring. as mentioned @Rakshith MN ASA sfr sensor is not seen as HA pair by the FMC point of view. however, if the failover triggered manually or due to network issue the active asa sfr will in service and standby will show you again no data received.
09-21-2022 09:18 PM
Thank you @Sheraz.Salim @Rakshith MN ,
Do I need to disable the monitoring on both(Primary/Secondary)?
09-21-2022 09:48 PM
I have double check if you disable the interface monitoring. It will disable it for your both firewalls.
Here look this document step by step instructions how to disable the data interface monitoring for each single device/HA pair.
09-22-2022 01:02 AM
@Sheraz.Salim Thank you for your support.
09-21-2022 01:46 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCur52789
M.
09-21-2022 02:01 AM
Thank you for your answer.
According to the bug CSCur52789, don't we have a solution to fix it?
09-21-2022 02:34 AM
The bug mentioned your unit ASA-5508-X so no work around is provided. also to make your aware these ASA boxes are gong end of life. something you might consider near future to upgrade to FTD-1001 or 2100 models
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide