cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
14315
Views
9
Helpful
26
Replies

Smart License usage is out of compliance.

MedTiti92
Level 1
Level 1

Hi Guys, i have this issues "Smart License usage is out of compliance." ... what is the solution of this error 

MedTiti92_0-1667978937307.png

Thanks !

26 Replies 26

MedTiti92
Level 1
Level 1

Thanks Guys ! like @Marvin Rhoads said, it is about FMC not trusting certificates being used by Cisco .. 

itninjas
Level 1
Level 1

Is there any other way to update FMC end certificate except from updating full FMC (and devices) to new version? One and only reason is that we use Cisco User Agent which will disappear after update as Identity source (Support for Cisco Firepower User Agent is deprecated and will be removed in a future release, which is our AD. And we would not like to buy ICE just for this. 

@itninjas yes - please read the field notice link I provided on 11/09/2022. It has a section specifically titled "Firepower - Manual Certificate Update".

Thank you for your quick response!

I did manual cert update for FMC. In document you refer it is under Firepower - Manual Certificate Update. I did backed up old cert and pasted new one you provided. Afterward I run command pmtool restartbyid sla

Sadly, still I have same issue. 

itninjas_0-1708348132473.png

Is there any other suggestion to try? Except of calling support...

Thank you!

Please try the steps listed under "Verify HTTPS (TCP 443) access from FMC to tools.cisco.com" in this document: https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/215838-fmc-and-ftd-smart-license-registration-a.html#anc4

Thank you for rapid answer. 

I tried both HTTPS and DNS verification. It work no problem but status is all the same

itninjas_0-1708349593780.png

 

Please also include the curl test option. That one is the best for certificate check.

Here is all :

itninjas_0-1708351603218.png

 

So all your connectivity looks good. Can you share exactly what license shows as non-compliant. If you are using FMC with ASA Firepower appliances, then only PAK-based licenses should matter. Are you managing FTD devices that use Smart licenses? Does your licensing portal show that FMC as compliant or not?

If you have license but it's not showing up as registered in the smart licensing portal, try to de-register and re-register your FMC using a new token.

Hello Marvin,

I am managing FTD's in HA thru Smart Licenses. I do have base, FMCv and AnyConnect Pus bundle license. I did de-registered and again registered FMC with new token. 

Well that did solved problem! So thank you for your awesome and patient assistance.

GarageLand42
Level 1
Level 1

I have the same "Out of Compliance" message regarding my Smart License Status - Usage Authorization.  

Can't I just click on "Re-Authorize", and are there any prerequisites?  

@GarageLand42 "Re-Authorize" may not work, especially if the original token is no longer valid. That's why re-registering with the new token is a more reliable solution. Also, it is a good opportunity to verify your access to the Smart account and check what the status is at that end, validate the licesne availability etc.

Review Cisco Networking for a $25 gift card