cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2416
Views
10
Helpful
1
Replies

FMC validation errors

johnlloyd_13
Level 9
Level 9

hi,

i was able to add a ASA 5525-X sensor in FMC but i'm unable to add/tick licenses (grayed out) and saw this error:

Initial policy deployment not started due to validation errors. For details, redeploy manually

> show managers 
Type                      : Manager
Host                      : 172.20.x.x
Registration              : Completed

i got enough URL filtering, malware, etc licenses for this sensor but not sure why FMC doesn't let me add them and push the access policy. see attached photo.

note this ASA 5525-X is not yet in production and only got 'management' interface and FP module both using same IP subnet and able they both able to ping/reach FMC. not sure if ASA needs to have other 'interfaces' working and operational.

i also saw this and not sure if it's bug related.

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/relnote/firepower-system-release-notes-version-600.html

In some cases, if you do not select the required licenses for a device prior to device
registration, the system generates an Initial policy deployment not started due to
validation errors. For details, redeploy manually message. For more information on the
correct licenses to select for your device, see the Licensing the FireSIGHT System chapter
of the Firepower Management Center Configuration Guide . (CSCuw85743)


can someone advise if ASA sensor (specifically its 'interfaces) needs to be in production for it to be able to add/tick licenses and push access policies? do i need to reboot ASA or FP and see if it helps?

1 Reply 1

Alex Pfeil
Level 7
Level 7

It seems that the device will show up as red if the service-policy is not applied on the ASA. This is due to packets not being sent to the Firepower virtual appliance. It is possible to successfully deploy to the device without the service-policy being applied.  The device being in the FMC showing up as red can be confusing.

 

Please rate helpful posts. 

Review Cisco Networking for a $25 gift card