在由防火牆裝置管理器(FDM)管理的兩台Firepower 1150裝置之間的高可用性(HA)配置失敗。 配置過程未成功完成,導致無法建立HA配對。
主裝置上的FDM UI顯示:

次要FTD裝置顯示:

主FTD CLI:
> show app-sync-history
================================APP SYNC HISTORY================================
--------------------------------------------------------------------------------
App Sync Time: 10:11:10 UTC Aug 07 2026
Role: Active Unit
App Sync Status: FAILURE
Failed Phase: WaitRemoteConfigApply
Failure Reason: Cluster App Un Archive failure on Standby/Slave Unit Node Id: 1 FDM validation failure - Active and Standby Nodes cannot have different cloud regions. Need to do App/Sensor Configuration Rollback App/Sensor config apply fails on following slave nodes:1 App sync application failed on standby with reason=FDM validation failure - Active and Standby Nodes cannot have different cloud regions.
輔助FTD CLI:
device# show failover
Failover Off (pseudo-Standby)
Failover unit Secondary
Failover LAN Interface: failover-link Ethernet1/1 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 2 of 1288 maximum
MAC Address Move Notification Interval not set
failover replication http
> show app-sync-history
================================APP SYNC HISTORY================================
--------------------------------------------------------------------------------
App Sync Time: 10:11:06 UTC Aug 07 2026
Role: Standby Unit
App Sync Status: FAILURE
Failed Phase: OnBoxValidators
Failure Reason: FDM validation failure - Active and Standby Nodes cannot have different cloud regions.
--------------------------------------------------------------------------------
device# show failover history
==========================================================================
From State To State Reason
==========================================================================
08:45:29 UTC Aug 7 2026
Not Detected Disabled No Error
10:10:49 UTC Aug 7 2026
Disabled Negotiation Set by the config command
(failover)
10:10:50 UTC Aug 7 2026
Negotiation Cold Standby Detected an Active peer
10:10:52 UTC Aug 7 2026
Cold Standby App Sync Detected an Active peer
10:11:39 UTC Aug 7 2026
App Sync Disabled CD App Sync error
FDM validation failure - Active and Standby Nodes cannot have different cloud regions.. Check app-sync-history CLI for details
==========================================================================
兩部Firepower 1150 FTD裝置。其他硬體平台也受到影響。
FTD軟體版本7.2.8。其他軟體版本也受到影響。
兩台FTD裝置均由FDM管理並在思科雲服務中註冊。
解決方案涉及在兩個防火牆之間協調雲服務註冊狀態。
主要雲服務已在美國地區註冊:

輔助雲服務已在歐盟地區註冊:

在這種情況下,使用者決定註冊輔助防火牆(FW2)以與主防火牆(FW1)相符。
使用與FW1(美國地區)相同的雲區域將FW2註冊到思科雲服務。
在FW2 FDM介面中,導航到Device > System Settings > Cloud Services,然後註銷雲服務:

然後,將FW2註冊到FW1使用的同一區域:

當兩台裝置顯示相同的雲註冊狀態後,請恢復HA配置:

在輔助裝置的CLI中,您會看到:
>
Detected an Active mate
Secondary: Switching to Ok for reason Detected an Active peer.
幾分鐘後:
device# show failover state
State Last Failure Reason Date/Time
This host - Secondary
Standby Ready None
Other host - Primary
Active None
====Configuration State===
Sync Done - STANDBY
====Communication State===
Mac set
通常,兩台裝置必須在同一思科雲服務區域中註冊,或者根本不能同時註冊兩台。
根本原因是兩個Firepower 1150裝置之間的思科雲服務註冊狀態不匹配。如果一個節點已雲註冊,而另一個節點未註冊或註冊到其他區域,FDM會阻止HA應用同步。此驗證可確保HA對中的兩台裝置維持一致的雲連線和功能可用性。
具體的技術原因在於FW1註冊到Cisco Cloud Services US區域,而FW2註冊到EU區域,導致HA對形成處於不相容狀態。
| 修訂 | 發佈日期 | 意見 |
|---|---|---|
1.0 |
07-Aug-2026
|
初始版本 |