cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
178
Views
0
Helpful
2
Replies

FTD 4110 Generating Troubleshoot file - fails firewall

paulgm000
Level 1
Level 1

Hi brains trust.

I am hopping that someone can help with a problem I have with a cluster of four by 4110 firewalls.

The firewalls are running V 7.0.4 FTD and FXOS version: 2.10.1 and have an up-time of just over 3 years (mission critical 24/7 operation).

We have a issue where if a troubleshoot file is generated on any of devices, that device will fail out of the cluster.

The failure appears to coincide with the critical partition on the drive (/ngfw) spiking from 40% - 100%.

Once the file is successfully generated and available for download the drive utilisation goes back to normal and the firewall rejoins the cluster.

Lastly the troubleshoot file is quite large with different units having sizes ranging from 1.5 - 4 gig compressed, 

Any help or advice would be greatly appreciated.

1 Accepted Solution

Accepted Solutions

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

   There are well known issues in this area, when HDD space is scarce, especially in version 7.0 and before. Strongly suggesting to upgrade to a stable 7.4.3 or 7.6.2 with latest patch applied. In here, you can clean the disk from FMC GUI, see following document, or perform the same from CLI via "system support diskcleaner-show" and "system support diskcleaner-run" commands:

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/223160-clear-disk-space-utility-on-fmc-7-7-0.html

Meanwhile, as you're still on this code, use the following document to manually cleanup your disks:

https://community.cisco.com/t5/security-knowledge-base/solution-to-fix-high-unmanaged-disk-usage-on-ngfw-ftd-firewall/ta-p/5285879

Thanks,

Cristian.

    

View solution in original post

2 Replies 2

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

   There are well known issues in this area, when HDD space is scarce, especially in version 7.0 and before. Strongly suggesting to upgrade to a stable 7.4.3 or 7.6.2 with latest patch applied. In here, you can clean the disk from FMC GUI, see following document, or perform the same from CLI via "system support diskcleaner-show" and "system support diskcleaner-run" commands:

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/223160-clear-disk-space-utility-on-fmc-7-7-0.html

Meanwhile, as you're still on this code, use the following document to manually cleanup your disks:

https://community.cisco.com/t5/security-knowledge-base/solution-to-fix-high-unmanaged-disk-usage-on-ngfw-ftd-firewall/ta-p/5285879

Thanks,

Cristian.

    

Hi Christian,

Thank you for the advice.

The firewalls have been up for quite a long time, so well over due for an upgrade.

Given the /ngfw partition is only at 40 - 44 percent at the current time, I think I will plan for an upgrade in the near future.

If I don't get a maintenance window earlier enough I will try the manual cleanup that you have suggested.

Regards

 

Paul

 

Review Cisco Networking for a $25 gift card