cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3116
Views
35
Helpful
11
Replies

Getting the FMT to communicate with FMC

jdelgado89
Level 1
Level 1

Hello, I am currently in the process of upgrading my ASA Version 9.8 running on a FP 2210. I am currently using the Firepower Migration Tool, it is able to pull down the find no problem from the ASA. However, when I put in the IP for the FMC and Usernamd and Password, I get 

"Blocked
Invalid FMC credentials, Please try again"
 
Now I have tested the creds, I can log into the web portal and I can SSH into the box with them. Any and all advice would be helpful.
 
Thank you
 
11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

Please check the access to the API explorer on your FMC as follows:

Navigate to the following URL: https://<management_center_IP_or_name>:<https_port>/api/api-explorer

Use the same credentials that you are trying with the FMT.

jdelgado89
Level 1
Level 1

Hey Marvin, 

When I go to https://10.10.82.2/api/api-explorer I get:

Not Found

The requested URL /api/api-explorer was not found on this server.

 

I am not aware of any other ports open other 443 and 22. What am I doing wrong or what would you suggest I try next 

 

Thank you

 

  

bharrington
Level 1
Level 1

Hi

 

Was this ever resolved. I am having the same issue even though the FMT did work last week and successfully connected to the FMC.

 

Thanks

Marvin Rhoads
Hall of Fame
Hall of Fame

@bharrington check the console window of the FMT for any errors and share with us please.

jesse.garcia11
Level 1
Level 1

We are having this issue as well. I cannot see any api options in the System>>>Configurations options in the FMC. Can anyone help with this issue if they were able to get it resolved?

 

 

@jesse.garcia11 is the FMC user an Admin level account?

Hi @Marvin Rhoads , yes it is the default admin user account. I also created one as well, and tried that one too. 

That's odd. I've used the migration tool at least 6-7 times on different FMCs and never had that problem.

You might want to open a TAC case using your FMC's support contract to have them look into it.

Ok I will do that. Thanks @Marvin Rhoads . Question. I have created the asa under the logical device in the FMC web interface. Should I have done that? Or will this migration take the asa over and create it for me? We are migrating from ASA5585 ver,Cisco Adaptive Security Appliance Software Version 9.8(4). We are migrating to Cisco Firepower 4115 Security Appliance , ver 2.8.9

bharrington
Level 1
Level 1

I resolved the issue by putting a check on the Enable Rest API checkbox in FMC see attached images.

I see. You interface looks much different then mine. Now I see we have different models as I am in a 4115

Review Cisco Networking products for a $25 gift card