cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9613
Views
9
Helpful
26
Replies

Smart License usage is out of compliance.

MedTiti92
Level 1
Level 1

Hi Guys, i have this issues "Smart License usage is out of compliance." ... what is the solution of this error 

MedTiti92_0-1667978937307.png

Thanks !

1 Accepted Solution

Accepted Solutions

Try this please:

1) Go into the FMC CLI into expert mode

2) Type "sudo su -" and type in the password

3) Issue the command "rm /etc/sf/gch/call_home_ca"

4) Issue the command "pmtool restartbyid sla"

5) Issue the command "pmtool restartbyid CloudAgent"

6) Wait a couple of minutes and check the registration again.

View solution in original post

26 Replies 26

balaji.bandi
Hall of Fame
Hall of Fame

Looks like it was registered a long time in 2020 ( what happens when you click  re-authorise )

First, i would log in to the portal and check the License and any alerts related to the License.

Second, if all that is good, I will troubleshoot  - is the FMC able to reach the smart license Server ? (follow below guide)

https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/215838-fmc-and-ftd-smart-license-registration-a.html#anc6

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Are you saying log into Smart license portal?

@CiscoPurpleBelt give us some context to your question or start a new thread.

MedTiti92
Level 1
Level 1

Yes i logged to the portail and i see this in the portal : 

MedTiti92_0-1667985899280.png

 

check the details it will give you more information - check your oder or purchase  ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Try this please:

1) Go into the FMC CLI into expert mode

2) Type "sudo su -" and type in the password

3) Issue the command "rm /etc/sf/gch/call_home_ca"

4) Issue the command "pmtool restartbyid sla"

5) Issue the command "pmtool restartbyid CloudAgent"

6) Wait a couple of minutes and check the registration again.

@Aref Alsouqi @marvin 

I have exact same issue for an FMC but my version is 7.0.2. Have you seen similar issue for 7.0.2 FMC ?

Did you try the above suggested steps and they didn't work?

@Aref Alsouqi 

I did not try this as version is more than 6.5 since was thinking version wise it not affect. Do you think is a worth try , I still have the Expired Root CA in the Trusted CA store of FMC.

Marvin Rhoads
Hall of Fame
Hall of Fame

If you are running an older release, you need to update it to allow FMC to accept the newer certificates that Cisco has been using for some time now.

https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html

@Marvin RhoadsI'm using 6.5.0 in FMC, manage two FTD(6.3.0) ... 

@Aref Alsouqi are will be some impact in the production with thoses command

Thanks !

No impact AFAIK. The issue would be related to a change from Cisco side of a trusted certificate. The steps I provided should fix the issue, however, if that doesn't help please follow the instructions of the "Firepower - Manual Certificate Update" in the link @Marvin Rhoads provided. Please remember to issue the command "pmtool restartbyid CloudAgent" which is not documented on that link I think. If you don't issue this additional command you would need to wait for the FMC to trigger the synch again which I don't know how long it would take.

MedTiti92
Level 1
Level 1

is it a problem of licence expired or just an update of FMC & FTD

Marvin Rhoads
Hall of Fame
Hall of Fame

It's (usually) not a problem of license being expired but rather the FMC not trusting the updated certificates being used by Cisco.

If you are running 6.5.0 managing 6.3.0 devices I strongly recommend you evaluate your operations as the version are quite out of date and subject to a lot of bugs and lacking features included in the more current releases.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card