Manually Roll Back the configuration if the Cloud-Delivered Firewall Management Center loses Connectivity

Use this task to restore management connectivity when a configuration change deployed from the Cloud-Delivered Firewall Management Center affects network connectivity and you need to roll back to the last-deployed configuration.

If you use a data interface on the Firewall Threat Defense for manager access and deploy a configuration change from the Cloud-Delivered Firewall Management Center that affects network connectivity, you can roll back the configuration on the Firewall Threat Defense to the last-deployed configuration to restore management connectivity. Afterward, update the configuration settings in Cloud-Delivered Firewall Management Center to maintain network connectivity, and re-deploy. You can use the rollback feature even if you do not lose connectivity; it is not limited to this troubleshooting situation.

Alternatively, you can enable auto rollback of the configuration if you lose connectivity after a deployment; see Edit deployment settings.

See these guidelines:

  • Only the previous deployment is available locally on the Firewall Threat Defense; you cannot roll back to any earlier deployments.

  • Rollback is supported for high availability but not supported for clustering deployments.

  • Rollback is not supported immediately after high availability creation.

  • The rollback only affects configurations that you can set in the Cloud-Delivered Firewall Management Center. For example, the rollback does not affect any local configuration related to the dedicated Management interface, which you can only configure at the Firewall Threat Defense CLI. Note that if you changed data interface settings after the last Cloud-Delivered Firewall Management Center deployment using the configure network management-data-interface command, and then you use the rollback command, those settings will not be preserved; they will roll back to the last-deployed Cloud-Delivered Firewall Management Center settings.

  • UCAPL/CC mode cannot be rolled back.

  • Out-of-band SCEP certificate data that was updated during the previous deployment cannot be rolled back.

  • During the rollback, connections will drop because the current configuration will be cleared.

Procedure


Step 1

At the Firewall Threat Defense CLI, roll back to the previous configuration.

configure policy rollback

Note

For a high availability pair, this command is allowed only on the active unit.

After the rollback, the Firewall Threat Defense notifies the Cloud-Delivered Firewall Management Center about the successful completion. The deployment screen In the Cloud-Delivered Firewall Management Center displays a banner indicating that the configuration was rolled back.

Note

If the rollback fails and the Cloud-Delivered Firewall Management Center management is restored, refer to https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw-virtual/215258-troubleshooting-firepower-threat-defense.html for common deployment problems. In some cases, the rollback may fail after the Cloud-Delivered Firewall Management Center management access is restored. Resolve any Cloud-Delivered Firewall Management Center configuration issues and redeploy from the Cloud-Delivered Firewall Management Center.

Example:

For the Firewall Threat Defense that uses a data interface for manager access:

> configure policy rollback

The last deployment to this FTD was on June 1, 2020 and its status was Successful.
Do you want to continue [Y/N]?

Y

Rolling back complete configuration on the FTD. This will take time.
.....................
Policy rollback was successful on the FTD.
Configuration has been reverted back to transaction id: 
Following is the rollback summary:
...................
....................
>

Example:

For Firewall Threat Defenses in a high availability pair that use a data interface for Cloud-Delivered Firewall Management Center access:

> configure policy rollback

Checking Eligibility ....
============= DEVICE DETAILS =============
Device Version: 7.2.0
Device Type: FTD
Device Mode: Offbox
Device in HA: true
Is HA disabled: false
HA state: active - standby ready
==========================================
Device is eligible for policy rollback
Do you want to continue [YES/NO]?

YES

Starting rollback...
    Preparing policy configuration on the device.           Status: success
    Applying updated policy configuration on the device.    Status: success
    Applying Lina File Configuration on the device.         Status: success
    Applying Lina Configuration on the device.              Status: success
    Commit Lina Configuration.                              Status: success
    Commit Lina File Configuration.                         Status: success
    Commit Lina File Configuration.                         Status: success
=================================================================
POLICY ROLLBACK STATUS: SUCCESS
=================================================================
>

Step 2

Check that the management connection was reestablished.

In Cloud-Delivered Firewall Management Center, check the management connection status on the Connection Status page. Navigate to Devices > Device Management and then navigate to Management area under the Devices tab. Then in the Manager Access - Configuration Details screen, click Connection Status.

At the Firewall Threat Defense CLI, enter the sftunnel-status-brief command to view the management connection status.

If it takes more than 10 minutes to reestablish the connection, you should troubleshoot the connection. See Troubleshoot Management Connectivity on a Data Interface.