Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello, Using FTD Version 6.5.0.4 on FPR2110, and managed with FMC. I am trying to access SNMP in LINA via the inside data interface, and it is being denied.The sanitized packet capture below shows an output-interface of "NP Identity Ifc", which I und...
Hello, We are using a pair of Firepower 2110s running FTD version 6.5.0.4, managed with an FMC. Remote VPN with anyconnect has been successfully configured with a split-tunnel arrangement of "tunnel all". An outside/outside NAT rule was added to al...
Hello, We are having issues setting up firepower anyconnect authentication with LDAP/AD. We have a realm setup with our AD servers. We can obtain users/groups from AD with it, and can authenticate into the FMC with AD credentials. However, when it...
I understand from the Cisco documentation that a service-policy applied to an interface on an ASA 5500 series firewall, will override the default global service-policy. However, I am not clear on whether it will override the entire global service-po...
My question is regarding the recent DNS cache poisoning vulnerability (www.doxpara.com), and the use of NAT devices such as the Cisco CSS 11501. This vulnerablity does not exist for some DNS server packages (i.e. DJBNDS), but I have read suggestions...
I also saw the bug referred to by Loebmann and it sounded like the opposite certificate situation. However, the process I followed was the same. I switched the HA roles (using Switch Peer Roles) to make the Secondary FMC active, and then re-install...
Hello again. I upgraded my FMC HA pair to 7.6.6 today to patch the vulnerabilities released this week, and I ran into this issue again. Maybe the patch was released containing the expired certificate? After the upgrade the Primary/Active FMC had t...
I tried a couple more things and managed to fix this, so didn't get around to talking to Cisco TAC. I switched the HA roles and made the secondary FMC (with the valid certificate) the active one, and the primary FMC (with the expired certificate) th...
Yes, VDB 435 (Aug 10th) is installed. I have just made another observation. We have an HA pair of FMCs, and the certificate on the secondary (standby) FMC appears to be updated, while the primary (active) one is expired as already noted. From the ...