Cisco Firepower 1010 Getting Started Manual page 154

Hide thumbs Also See for Firepower 1010:
Table of Contents

Advertisement

Troubleshoot Management Connectivity on a Data Interface
When you use a data interface for FMC management instead of using the dedicated Management interface,
you must be careful about changing the interface and network settings for the FTD in FMC so you do not
disrupt the connection. If you change the management interface type after you add the FTD to the FMC (from
data to Management, or from Management to data), if the interfaces and network settings are not configured
correctly, you can lose management connectivity.
This topic helps you troubleshoot the loss of management connectivity.
View management connection status
In FMC, check the management connection status on the Devices > Device Management > Device >
Management > FMC Access Details > Connection Status page.
At the FTD CLI, enter the sftunnel-status-brief command to view the management connection status.
You can also use sftunnel-status to view more complete information.
See the following sample output for a connection that is down; there is no peer channel "connected to"
information, nor heartbeat information shown:
> sftunnel-status-brief
PEER:10.10.17.202
Registration: Completed.
Connection to peer '10.10.17.202' Attempted at Mon Jun 15 09:21:57 2020 UTC
Last disconnect time : Mon Jun 15 09:19:09 2020 UTC
Last disconnect reason : Both control and event channel connections with peer went down
See the following sample output for a connection that is up, with peer channel and heartbeat information
shown:
> sftunnel-status-brief
PEER:10.10.17.202
Peer channel Channel-A is valid type (CONTROL), using 'eth0', connected to '10.10.17.202'
via '10.10.17.222'
Peer channel Channel-B is valid type (EVENT), using 'eth0', connected to '10.10.17.202'
via '10.10.17.222'
Registration: Completed.
IPv4 Connection to peer '10.10.17.202' Start Time: Wed Jun 10 14:27:12 2020 UTC
Heartbeat Send Time: Mon Jun 15 09:02:08 2020 UTC
Heartbeat Received Time: Mon Jun 15 09:02:16 2020 UTC
View the FTD network information
At the FTD CLI, view the Management and FMC access data interface network settings:
show network
> show network
===============[ System Information ]===============
Hostname
DNS Servers
Management port
IPv4 Default route
Gateway
IPv6 Default route
Gateway
======================[ br1 ]=======================
State
Cisco Firepower 1010 Getting Started Guide
152
Firepower Threat Defense Deployment with a Remote FMC
: 5516X-4
: 208.67.220.220,208.67.222.222
: 8305
: data-interfaces
: data-interfaces
: Enabled

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents