软件升级后,安全防火墙威胁防御(FTD)集群数据节点无法加入集群。观察到以下症状:
1. show cluster history的输出显示设备从DATA_NODE_CONFIG转换到DISABLED状态时的“配置复制失败”错误消息:
> show cluster history
…
09:52:55 UTC May 8 2026
DISABLED ELECTION Enabled from CLI
09:52:55 UTC May 8 2026
ELECTION ONCALL Event: Cluster unit unit-1-1 state
is CONTROL_NODE
09:52:55 UTC May 8 2026
ONCALL DATA_NODE_COLD Received cluster control message
09:52:55 UTC May 8 2026
DATA_NODE_COLD DATA_NODE_APP_SYNC Client progression done
09:54:39 UTC May 8 2026
DATA_NODE_APP_SYNC DATA_NODE_CONFIG Data node application configuration sync done
09:54:53 UTC May 8 2026
DATA_NODE_CONFIG DISABLED Configuration replication failed
2.文件/mnt/disk0/cluster_trace.log*包含与key命令的配置复制失败和集群转换到DISABLED状态相关的消息:
May 08 09:54:50.538 [INFO]start to monitor Port-channel47
May 08 09:54:50.538 [DBUG]Send CCP message to all: CCP_MSG_HWIDB_STATE
May 08 09:54:50.568 [INFO]start to monitor Ethernet1/5
May 08 09:54:50.568 [DBUG]Send CCP message to all: CCP_MSG_HWIDB_STATE
May 08 09:54:50.738 [CRIT]Config syncing failure: context single_vf, line 1027, CLI " key>".
May 08 09:54:50.748 [DBUG]Send event (PROGRESSION_FAILURE, n/a, n/a, 94350991600520) to FSM. Current state DATA_NODE_CONFIG
May 08 09:54:50.748 [INFO]cluster_fsm_disable: The clustering re-enable timer is stopped.
May 08 09:54:50.748 [DBUG]Send CCP message to all: CCP_MSG_QUIT from unit-2-1 for reason CLUSTER_QUIT_REASON_RETIREMENT
May 08 09:54:50.748 [DBUG]Send event (CONTROL_NODE_GONE, n/a, n/a, 94350991600224) to FSM. Current state DISABLED
3.文件/ngfw/var/log/ASAconsole.log*还包含与key命令的配置复制失败和集群转换到DISABLED状态相关的消息:
2026-05-08 09:49:51 Detected Cluster Control Node.
2026-05-08 09:50:01 Beginning configuration replication from Control Node.
…
2026-05-08 09:50:02 livecore enabled
2026-05-08 09:50:02 ........................
2026-05-08 09:50:02 key
2026-05-08 09:50:02 ^
2026-05-08 09:50:02 ERROR: % Input should be less than 64 characters at '^' marker.
2026-05-08 09:50:02 *** Output from config line 1027, " key..."
2026-05-08 09:50:02
2026-05-08 09:50:02 Failed configuration replication from Control Node.
2026-05-08 09:50:02 Cluster disable is performing cleanup..done.
2026-05-08 09:50:04 Unit unit-2-1 is quitting due to system failure for 3 time(s) (last failure is Internal clustering error). Rejoin will be attempted after 20 minutes.
在多实例集群部署中具有FTD的Firepower 4145。在多实例或本机模式部署中在Firepower 4100/9300上运行的群集也会受到影响。
FTD集群由FMC管理。
FTD软件版本从7.6.2升级到7.6.4。其他源或目标软件版本也可能受到影响。
最初,群集密钥配置为64个字符长度的字符串。根据Secure FXOS for Firepower 4100/9300 CLI或机箱管理器(FCM)配置指南中的“逻辑设备”部分,集群密钥是长度为1到63个字符的ASCII字符串。因此,使用FCM用户界面逻辑设备设置,集群密钥长度减少到少于64个字符。
虽然已记录集群密钥的最大长度限制,但是在FXOS软件级别(FXOS CLI或FCM)不会强制执行该限制。允许用户使用超过数量的字符配置集群密钥。尽管字符数已达到最大值,但设备仍可以在7.6.2版中加入集群。但是,升级后,软件将强制验证导致无法加入集群的密钥长度。这是未记录的行为更改。这些症状在内部复制并记录在Cisco Bug ID CSCwn53819中。
此外,作为复制工作的一部分,提交了Cisco Bug ID CSCwu3563和Cisco Bug ID CSCwu3553,以分别跟踪FCM和FXOS CLI上缺少集群密钥长度验证的情况。
Cisco Bug ID CSCwn53819
Cisco Bug ID CSCwu35563
Cisco Bug ID CSCwu35553
| 版本 | 发布日期 | 备注 |
|---|---|---|
1.0 |
14-May-2026
|
初始版本 |