cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1587
Views
0
Helpful
8
Replies

FTD can´t be added to FMC

masoudkavehie
Level 1
Level 1

hi 

actually im trying to add FTD To FMC but im got this error !!

Verify the following and retry:
- Device is configured to be managed by this Firepower Management Center
- Device hostname/IP is accurate; Firepower Management Center and device have connectivity
- Device Registration Key is correct
- Use NAT ID if either FMC or Device is behind NAT
- Time on FMC and Device is in sync

i have checked all of these notes and ive got this error in log file 

SSL_renegotiate error: 1: error:00000001:lib(0):func(0):reason(1)
Apr 23 11:09:43 firepower SF-IMS[19945]: [20758] sftunneld:sf_ssl [ERROR] Connect:SSL handshake failed
Apr 23 11:09:43 firepower SF-IMS[19945]: [20758] sftunneld:sf_ssl [WARN] SSL Verification status: ok

 

how could i solve this problem !!! thanks 

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

Check the system time/date on both ends and ensure they are showing the same date and hour.

i've checked  both of them with date command and it was ok ,same

balaji.bandi
Hall of Fame
Hall of Fame

is this a new setup? what is FMC and FTD, have you checked the compatibility?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

yes this is a new setup .its compatible .

what is the FMC and FTD version 

Can you remove both sides and try again.

 

- Use NAT ID if either FMC or Device is behind NAT

 

Explain more and with IP address, do you have small diagram of this ?

 

 

follow the troubleshooting guide :

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215540-configure-verify-and-troubleshoot-firep.html

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

the version both of them is 6.4 

i did it . i removed them and reinstalled but im getting this error again .

i don't khow .every thing is true in my openion and i check verything .

Is there a specific reason for 6.4? At least when I run into problems (and typically also without problems) I would try the Cisco recommended release which is 7.0.1 at the moment.

ok then 6.4 is quite old (but I did not see any issue when I had setup in the same version of FTD and FMC on the same version), can you uplift anything about 6.7 (cisco suggests now 7.0 or 7.01) - since you mentioned new setup. easy to upgrade.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card