cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2018
Views
5
Helpful
10
Replies

FMC IPS Critical Alert

Adnan Khan
Level 4
Level 4

Hi, I am getting an alert on Cisco FMC for IPS. The Snap is attached. Is that normal or we have any fix for that?

1 Accepted Solution

Accepted Solutions

It will stop all interface alerts. Unfortunately you cannot choose among the interfaces to which this Health Monitor applies.

But then FMC isn't really the right tool to monitor your interfaces - an NMS like PRTG, SolarWinds, Prime Infrastructure etc. is better suited for that task.

Later releases of Firepower fix the issue - I'm not sure exactly which one addressed it but it's fixed in the current 6.6 release.

View solution in original post

10 Replies 10

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not an IPS alert, it's a Health monitor alert. We normally see those when you are managing the Firepower service modules in an ASA HA pair. The standby unit will not be seeing any data traffic and thus generate the alert. If that's your case, the alert can be safely ignored.

The only work around for it is to blacklist interface monitoring in the Health Policy.

If you're not seeing it as coming from the standby unit in an HA pair then we have further troubleshooting to do.

Many thanks for your quick valuable response. Could you please share how I can blacklist the interface so the alert should not show up. Your reply is awaited, please.

You're welcome.

In FMC, go to System > Health > Policy and click on the "Interface Status" setting. There you should see an option to disable the checks.

Many thanks again. I will apply and update here the result.

If we do this. Will it stop any other legitimate alerts associated with this interface?

It will stop all interface alerts. Unfortunately you cannot choose among the interfaces to which this Health Monitor applies.

But then FMC isn't really the right tool to monitor your interfaces - an NMS like PRTG, SolarWinds, Prime Infrastructure etc. is better suited for that task.

Later releases of Firepower fix the issue - I'm not sure exactly which one addressed it but it's fixed in the current 6.6 release.

Yes I agreed. Many thanks for your prompt response.

I have configured the email alerts on FMC and getting notifications which are good but I am getting alerts every 5 minutes for this (interface 'dataplaneinterface0' is not receiving any packets). Is there any option if I can change the interval of this interface for regeneration? I plan not to disable this otherwise all legitimate alerts will be disabled as well.

The Health Policy (for all monitored subsytems) runs every 5 minutes by default. You cannot change it per subsystem.

So if you choose not to blacklist the interface events and have your FMC configured to email alerts you will get that email every five minutes. In that case, it may be easier to make an email rule to delete or file the ones with the predictable string in the body.

Thanks, FMC alert features are so limited. Not much control over it.

Review Cisco Networking products for a $25 gift card