<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA: 9.4(1) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755711#M1026213</link>
    <description>&lt;P&gt;ASA: 9.4(1)&lt;/P&gt;
&lt;P&gt;sfr: 5.4.0.2-33&lt;/P&gt;
&lt;P&gt;DC: 5.4.1.1&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 19:05:36 GMT</pubDate>
    <dc:creator>CRadoumis</dc:creator>
    <dc:date>2015-11-13T19:05:36Z</dc:date>
    <item>
      <title>SFR module stopped passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755703#M1026201</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I've had a serious problem over the past few days. One of my Firepower modules in a active/standby inline fail-open set of ASA5525-Xs stopped passing traffic on two occasions, immediate solution was to fail over to the standby 5525 but failing back to the primary 5525 stopped traffic once more.&lt;/P&gt;&lt;P&gt;I'm certain it's the Firepower module that's causing the problem.&amp;nbsp;I've got a selective ACL sending some internal subnets to the module, skipping others and an ANY ANY at the end. Those subnets skipped by the ACL are reachable, the one sent to the module are not.&lt;/P&gt;&lt;P&gt;During the outage my Defence Center doesn't show anything out of the ordinary. I'm running 5.4.0.3-37 on the modules and 5.4.1.2 on the DC.&lt;/P&gt;&lt;P&gt;First question would be if anyone has heard of this before? And second if there is some way for me to trouble shoot this further?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755703#M1026201</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2019-03-12T12:45:55Z</dc:date>
    </item>
    <item>
      <title>What version of ASA code are</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755704#M1026202</link>
      <description>&lt;P&gt;What version of ASA code are you currently running?&lt;/P&gt;&lt;P&gt;I have had this happen with the file policy configured with the "Inspect Archives" option checked. &lt;A href="https://tools.cisco.com/bugsearch/bug/CSCut39253/?reffering_site=dumpcr"&gt;https://tools.cisco.com/bugsearch/bug/CSCut39253/?reffering_site=dumpcr&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have also had this happen with an ASA configured with the in the monitor-only mode: &lt;A href="https://tools.cisco.com/quickview/bug/CSCus15229"&gt;https://tools.cisco.com/quickview/bug/CSCus15229 &lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've had pretty good luck with ASA code 9.4.1 and the most recent updates of both the FirePOWER Sensor code and FireSIGHT management code.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Sep 2015 14:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755704#M1026202</guid>
      <dc:creator>Justin Walker</dc:creator>
      <dc:date>2015-09-19T14:19:05Z</dc:date>
    </item>
    <item>
      <title>Hi Justin.Very interesting</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755705#M1026204</link>
      <description>&lt;P&gt;Hi Justin.&lt;/P&gt;&lt;P&gt;Very interesting reading. A verified bug matching a problem is always promising. Since reading this I've promptly disabled the "Inspect Archive" option. I'm running ASA version 9.3(3) by the way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: Since disabling the Inspect Archive feature I haven't had any more lock ups. There is also a 5.4.0.4 release for the SFR modules that promises to fixhe bug but I haven't updated yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2015 05:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755705#M1026204</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2015-10-07T05:37:34Z</dc:date>
    </item>
    <item>
      <title>Hi Fredik, Have you got NFE</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755706#M1026206</link>
      <description>&lt;P&gt;Hi Fredik,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you got NFE port Down in the alarms? it happens to me and a reboot helped me over it.&amp;nbsp; I had been&amp;nbsp; through a troubleshooting proccess with a TAC Ing and found out major problems with our hardware itself.&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wilson&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 20:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755706#M1026206</guid>
      <dc:creator>wigevicisco</dc:creator>
      <dc:date>2015-10-19T20:39:24Z</dc:date>
    </item>
    <item>
      <title>HiI can't say I recognize</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755707#M1026208</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I can't say I recognize that message. My logs at the time the problems occurred were pretty silent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 07:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755707#M1026208</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2015-10-20T07:41:13Z</dc:date>
    </item>
    <item>
      <title>I have had this problem twice</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755708#M1026210</link>
      <description>&lt;P&gt;I have had this problem twice now on two different ASAs without as inspection policy, and in inline fail-open mode. A reboot did solve the problem but I haven't found the reason for the failure, nor a non disruptive solution.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 09:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755708#M1026210</guid>
      <dc:creator>CRadoumis</dc:creator>
      <dc:date>2015-11-13T09:10:32Z</dc:date>
    </item>
    <item>
      <title>Hi all.</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755709#M1026211</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;
&lt;P&gt;I've also had this problem with archive inspection (bug id CSCut39253) and I solved it upgrading both sfr and firesight management center with latest release (5.4.0.4 for sfr and 5.4.1.3 for firesight management center). Upgrading only sfr to latest release didn't solve the problem for me.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;After this upgrade, I enabled archive inspection and no other hang happened on our sistems (6 sfr module)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Danilo&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 09:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755709#M1026211</guid>
      <dc:creator>Danilo Molini</dc:creator>
      <dc:date>2015-11-13T09:28:05Z</dc:date>
    </item>
    <item>
      <title>What version of ASA, SFR and</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755710#M1026212</link>
      <description>&lt;P&gt;What version of ASA,&amp;nbsp;SFR and DC do you use?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 09:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755710#M1026212</guid>
      <dc:creator>Danilo Molini</dc:creator>
      <dc:date>2015-11-13T09:30:57Z</dc:date>
    </item>
    <item>
      <title>ASA: 9.4(1)</title>
      <link>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755711#M1026213</link>
      <description>&lt;P&gt;ASA: 9.4(1)&lt;/P&gt;
&lt;P&gt;sfr: 5.4.0.2-33&lt;/P&gt;
&lt;P&gt;DC: 5.4.1.1&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 19:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sfr-module-stopped-passing-traffic/m-p/2755711#M1026213</guid>
      <dc:creator>CRadoumis</dc:creator>
      <dc:date>2015-11-13T19:05:36Z</dc:date>
    </item>
  </channel>
</rss>

