cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5812
Views
5
Helpful
11
Replies

FTD 1010 local management (FDM) registration failing

Travis-Fleming
Level 1
Level 1

I've got a brand spankin new FTD 1010 device. I'm managing via FDM. I can ping 8.8.8.8 and get out to the internet from the device. However when I try to register the device via the smart licenses we purchased I keep getting an error. Any easy troubleshooting things I could be missing?

 

I can ping 8.8.8.8

I can ping 104.113.23.234 (software.cisco.com)

I changed my access control rules to allow all temporarily

I re-created my token on the smart license site

 

I would open a TAC case but our coverage odly enough does not start until November 1st.

1 Accepted Solution

Accepted Solutions

I found it. I had a Doh! Moment. My route to the internal networks was fat-fingered. Thanks guys.

View solution in original post

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

Are you pinging from the management interface (e.g. using "ping system" command from the cli)?

Does your device have DNS setup so that you can do the ping using FQDN and not P address?

Is there a web proxy server in your environment?

nspasov
Cisco Employee
Cisco Employee

What is the error that you are getting when trying to register with the smart licensing server? Also, as Marvin pointed out, can you post the output from ping system software.cisco.com

Thank you for rating helpful posts!

Thanks guys for the reply. I was thinking DNS as well. I'm thinking I have something setup wrong for that, but not sure what it could be. Below is my ping output, and my "show network", which shows I have 8.8.8.8 as my dns server, and I can ping 8.8.8.8. Also at the very bottom is the error output trying to register.

 

> ping system software.cisco.com
ping: unknown host software.cisco.com
> ping 8.8.8.8
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 10/12/20 ms

 

> show network
===============[ System Information ]===============
Hostname : at-buia-ftd01
DNS Servers : 8.8.8.8
Management port : 8305
IPv4 Default route
Gateway : 10.10.69.1

==================[ management0 ]===================
State : Enabled
Channels : Management & Events
Mode : Non-Autonegotiation
MDI/MDIX : Auto/MDIX
MTU : 1500
MAC Address : 7C:21:0E:B6:56:00
----------------------[ IPv4 ]----------------------
Configuration : Manual
Address : 10.10.69.2
Netmask : 255.255.255.0
Broadcast : 10.10.69.255
----------------------[ IPv6 ]----------------------
Configuration : Disabled

===============[ Proxy Information ]================
State : Disabled
Authentication : Disabled

 

The device was unable to connect to the Smart Licensing server. This might indicate a gateway problem for the management interface. Please select Evaluation Mode for now. Then, after completing setup, go to Device > System Settings > Management Interface and verify the management address and gateway configuration. There must be a path from the management IP address to the Internet to complete Smart License registration. You can then go to Device > Smart License and try registering again.

When you ping without the system keyword it will use the global routing table of the device to determine the egress interface. You need to always use "ping system" to force the unit to use the management interface and its configured gateway.

You can also switch into expert mode and use nslookup to check for successful DNS resolution.

Yeah same result there can't resolve. 

 

admin@at-buia-ftd01:/$ nslookup software.cisco.com
;; connection timed out; no servers could be reached

I found it. I had a Doh! Moment. My route to the internal networks was fat-fingered. Thanks guys.

Great! Glad you were able to resolve your own problem. Also, thank you for taking the time to come back and post the resolution. 

Now, since your issue is resolved, you should mark the thread as "answered" :)

Thank you for rating helpful posts!

Hi can you please explain what was the prob? I have the same 

@Deathshar please share the results of the troubleshooting steps you have already taken.

i have connected the management port with a cable to our switch with static and dhcp on the ip config of the managment port,  i have changed the dns servers of the 1010, i have configured again the nat and access rules. still the same i can ping 8.8.8.8 have internet but cant from the box resolve the cisco url to register the device.

i cant understand what he means on the answer about the routes to internal networks 

 

Does "show network" from the cli indicate the expected DNS servers and gateway are in place for your 1010 management interface?

Review Cisco Networking for a $25 gift card