cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
518
Views
2
Helpful
6
Replies

FTD not registering with secondary FMC

blackhat2020
Level 1
Level 1

Hi , i have primary FMC1 working fine with 3 ftd registered to it. i have setup secondary FMC and joined fmc 2 to fmc 1 . it seems that fmc are connected and getting synced but no ftd get registered on FMC-2 so FMC2 shows degraded status because fmc 2 has fewer devices than fmc 1.!

i have check on my 3 ftds with show managers ,there is no sign of FMC2 even in pending state. just nothing

even i checked with Omniquery command and there is noting about FMC 2 ip address at all !

this is happening for all my 3 ftds. i mean no ftd get registered on FMC 2 

i tried tailing the logs files and there is no error about certificate or any thing else 

FMC1 and FMC 2 and all ftds are in same subnet. 

even i tried to change FMC 2 ip address and do the FMC HA proccess again but same result. nothing happens!

so all my ftds are in pending state in FMC 2 but there is nothing on ftds about FMC2

i tried different guides but nothing helped so far. please if any one had such a problem and knows how to fix it share. than you in advance.

6 Replies 6

nspasov
Cisco Employee
Cisco Employee

A few questions here:
What is the version running on the FMCs

  • What is the version running on the FTDs
  • FMC and FTD appliance models
  • Screenshot or copy/past of the exact error that you are getting

Also, have you checked the FMC - HA Thsoot Guide?

Thank you for rating helpful posts!

Thank you for rating helpful posts!

Hi

FMC= 7.3.1

FTD= 7.2.5.1

there is no error except in FMC high availability screen it show my all FTDs in pending state to register on FMC-2. and in ftd only shows fmc 1 as manager there is nothing about fmc 2

7.3.1 is a short term release and is missing the many bug fixes that are included in the more recent 7.4 train releases. If it were my call, I would recommend upgrading to FMC 7.4.2.2 and seeing if the problem is resolved.

hi Marvine, thanks for reply, in this moment with only one active fmc im not sure i can risk to go through upgrade process. i should also add some info that, before this happened, i had a fmc2 that was working ok and with ftds registered to it, but in some point it got broken and stuck in service initiate loop so we broke the ha and installed new fmc 2 with same ip address of old fmc 2 and we saw the problem that ftds not getting registered, and then i tried to change the fmc 2 ip address to something else and new so hopefuly it would resolve the issue but still no luck…! same problem that none if the ftds trying to register with fmc 2… 

How yoh config FMC HA?

Are both FMC behind NAT?

MHM

nspasov
Cisco Employee
Cisco Employee

At this point, it is probably best to engage Cisco TAC

Thank you for rating helpful posts!

Thank you for rating helpful posts!
Review Cisco Networking for a $25 gift card