1. Display real time log on FMC or FTD: pigtail for example: pigtail | grep 192.168.2.20 pigtail | grep sftunnel 2. Restart communication channel manage_procs.pl run it from the sensor only, run it from FMC will reset all sensors' channel. This scripts are nice to be used when the FMC and FTD have communication problems like heartbeats are not received, policy deployment is failing or events are not received > expert ************************************************************** NOTICE - Shell access will be deprecated in future releases and will be replaced with a separate expert mode CLI. ************************************************************** admin@FTD:~$ sudo su Password: root@FTD:/home/admin# manage_procs.pl **************** Configuration Utility ************** 1 Reconfigure Correlator 2 Reconfigure and flush Correlator 3 Restart Comm. channel 4 Update routes 5 Reset all routes 6 Validate Network 0 Exit *****
1. Phase I proposal mismatch Run show crypto isakmp sa Initiator: MM_WAIT_MSG2 Responder: No info Most likely this is phase1 proposal mismatch, verify IKEv1 policy, other symptoms: Initiator log: Information Exchange processing failed All configured IKE versions failed to establish the tunnel Initiator debug: Received an un-encrypted NO_PROPOSAL_CHOSEN notify message, dropping Responder log: Error processing payload: Payload ID Responder debug: All SA proposals found unacceptable 2. IKE version mismatch: Run show crypto isakmp sa no info at both initiator and responder Initiator log: Removing peer from correlator table failed, no match! Reason: User Requested All configured IKE versions failed to establish the tunnel Initiator debug: Oakley begin quick mode PHASE 1 COMPLETED IKE Initiator sending 1st QM pkt Removing peer from correlator table failed, no match! Session is being torn down. Reason: User Requested Responder log: Tunnel Rejected: Conflicting protocols specified
Chassis FXOS and FTD share same management IP (default 192.168.45.45) Chassis FXOS (192.168.45.45) and ASA ()use different management IP although on same physical interface. SSH to FXOS/FTD are on FTD CLI prompt, go to FXOS using the connect fxos command Console to Chassis is on FXOS CLI prompt, go to FTD using the connect ftd command The Firepower 1100 does not support the FXOS Firepower Chassis Manager; only a limited CLI is supported for troubleshooting purposes. The Firepower 2100 runs an underlying operating system called the Firepower eXtensible Operating System (FXOS). If you run ASA on Firepower 2100, ASA can be in the following modes: Appliance mode (the default after ASA 9.13)—Appliance mode lets you configure all settings in the ASA. Only advanced troubleshooting commands are available from the FXOS CLI. See the FXOS troubleshooting guide for more information. Firepower Chassis Manager is not supported . ciscoasa# connect fxos [admin] Connecting to fxos. Connected
Comments
Post a Comment