FirePOWER – ‘DataPlaneInterface0’ is not receiving and packets

KB ID 0001344 Dtd 11/09/17

Problem

While replacing a FirePOWER Management console, I got this error;

FirePOWER Data Plane Interface0 not recieving any packets

Interface Status
Interface ‘DataPlaneInterface0’ is not receiving any packets

 

Solution

A look a the health monitor showed me the same thing;

FirePOWER Alert Data Plane Interface0 not recieving any packets

Firstly, common sense dictates, that this is a live firewall and traffic is actually flowing though it? In my case the traffic simply needed to be ‘sent though’ the module. Execute the following, (or check for the presence of matching configuration);

access-list ACL-FirePOWER extended permit ip any any
class-map CM-SFR
 match access-list ACL-FirePOWER
 exit
policy-map global_policy 
 class CM-SFR
  sfr fail-open
exit
exit
write mem

Note: Here I’m assuming you want to ‘fail-open’ i.e. not block traffic if the FirePOWER module fails, and you are inspecting ‘inline’ (not passively).

Then apply the cup of coffee rule, and ensure some traffic is sent via the firewall.

FirePOWER Alert fixed

 

Related Articles, References, Credits, or External Links

NA

Author: PeteLong

Share This Post On

2 Comments

  1. The other common cause of this alert that bears mentioning is that the device may be standby in an Active-Standby High Availability (HA) pair.

    Keep up the good work Pete!

    Post a Reply
    • 🙂 Hi Marvin Yes – I didn’t consider that, (need more coffee and less Microsoft jobs!)
      Always a pleasure.
      Pete

      Post a Reply

Submit a Comment

Your email address will not be published. Required fields are marked *