01-17-2023 07:18 AM
I am just beginning with SecureX and I enabled on the FMC that manages 4 FTD1010's . However after enabling I only see the FMC and 2 out of the 4 managed FTDs in the Securex portal. I was wondering before I bother TAC on this if anyone knows a way to resolve
01-17-2023 08:59 AM
I assume you've clicked the button to "Check for New Devices".
Are these HA pairs by any chance?
01-18-2023 05:45 AM
Hey Marvin yead I did the "Check for new devices" several times no luck. The below FTD's listed on the SSE do not match what the FMC is managing and licensed for which is a total of 4 FTD's. There is a generate token to add new device but I don't know how this is used. It seems like one could manually SSH into an FTD and use the cli somehow to register the device to the portal using the token but that's just my own speculation and have found no doc on its purpose. I opened a TAC so hopefully I get a resolution and will report back what it is.
01-18-2023 05:48 AM
Thanks for the update. Please do let us know what the TAC says.
I have found it frustrating at times to get clear answers regarding some of the cloud-based services. The TAC engineers often don't have the access they need to troubleshoot things going on in the back end and it ends up having to go to Cisco Operations team to resolve.
01-23-2023 03:37 AM
Hey Marvin with my FTD tail site deployments I have management interface configured on the public external G1/1 interface. My event traffic from the Tail sites is successful via NAT into the FMC over TCP\8305 . After working with TAC we eventually discovered link down on the management interface for the devices that are not registering to secure-x (I assume that registration to secure x needs management interface connectivity and will not use the outside configured data management interface ) It appears to be a switch issue most likely negotiation as i am sure with this company these switches are probably unmanaged and 100baseT.
01-23-2023 05:11 AM
Interesting, the SecureX integration troubleshooting document says "Both FMC and FTD need a connection to the SSE URLs on their management interface". I suspect it's a bug/oversight for it not to work on the data interface configured as management.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide