1 科普:
what is FMC
full name is Firepower Management Center, 是思科FirePower防火墙的统一管理平台.
能管理ASA不?
no,只能管理FTD模式的墙。这里的FTD包括物理机firepower系列运行的FTD,以及FTDv(虚拟化版本)
本次背景
当前1台FMC因为存在问题,需要将配置迁移到1台新建的FMC上。
经过与思科tac确认,由于恢复了相同的配置,可能会使得smart account中出现2个相同的license占用警告,建议是在新FMC上恢复配置后,将老FMC上的Smart License reset掉,老的FMC就不再消耗smart license。
2 实际操作
2.1 license status before the operation
it’s smart license registered
2.2 执行如下命令,切换为evaluation mode
- expert mode
- sudo su
- /var/sf/bin/reset_licenses.pl
>
> expert
admin@firepower:~$ sudo su
Password:
Last login: Fri Nov 15 02:12:43 UTC 2024 on pts/0
root@firepower:/Volume/home/admin# /var/sf/bin/reset_licenses.pl
********************* Caution ****************************
Going to reset the licenses. This will bring back the system into evaluation mode.
**********************************************************
Are you sure you want to continue (Y/N) y
License reset initiated.. putting to eval mode.
Disabling Smart Agent... at /usr/local/sf/lib/perl/5.24.4/SF/SmartAgentManager.pm line 10357.
Enabling Smart Agent... at /usr/local/sf/lib/perl/5.24.4/SF/SmartAgentManager.pm line 10385.
waiting for SLA to come up at /usr/local/sf/lib/perl/5.24.4/SF/SmartAgentManager.pm line 10403.
URL fitlering capability disabled on all devices - reload Cloud Agent (Active FMC) at /usr/local/sf/lib/perl/5.24.4/SF/LicenseCaps.pm line 1200.
Disable URLFiltering, Updates, UserPreference, queryVendors at /usr/local/sf/lib/perl/5.24.4/SF/Cloud/Support.pm line 1438.
Commenting call to disableConfigURLFiltering as fix for CSCvb16413 at /usr/local/sf/lib/perl/5.24.4/SF/Cloud/Support.pm line 1439.
Use of uninitialized value in numeric ne (!=) at /usr/local/sf/lib/perl/5.24.4/SF/EODataHandler/CloudConfig.pm line 84.
Use of uninitialized value in numeric ne (!=) at /usr/local/sf/lib/perl/5.24.4/SF/EODataHandler/CloudConfig.pm line 84.
activateDeactiveURLFiltering is called with enabled set to 2
No Caps passed to setCapabilities at /usr/local/sf/lib/perl/5.24.4/SF/LicenseCaps.pm line 1016.
Failed to load data: File not found at /usr/local/sf/lib/perl/5.24.4/SF/PeerManager/Util.pm line 96.
in file path: /var/tmp/device_connection.json at /usr/local/sf/lib/perl/5.24.4/SF/PeerManager/Util.pm line 115.
License has successfully reseted to Eval mode.
root@firepower:/Volume/home/admin#
root@firepower:/Volume/home/admin#
2.3 执行完成后,再次确认license状态
已经变成Evaluation Mode