<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827001#M1033192</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I would recommend you using fail-open mode so that if the module goes down the traffic still continues to pass. Also check the status of the module when the issue happens before disabling the service-policy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also if the status of the module is up , you can check the connection events and see if the trafic is being blocked. Are there of any signs of oversubscription on the module&amp;nbsp; as in do you have a lot of traffic passing through the SFR module.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2015 05:12:55 GMT</pubDate>
    <dc:creator>Aastha Bhardwaj</dc:creator>
    <dc:date>2015-11-26T05:12:55Z</dc:date>
    <item>
      <title>Firepower module in 5512-X denying all traffic (failing closed) after 6.0 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2826998#M1033181</link>
      <description>&lt;P&gt;Are there any known reasons as to why a firepower module would lock up fail-closed ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've seen this happen to both a 5512-X and a 5525-X, the firepower module becomes locked up and the only way to allow traffic is to switch the service policy off in the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2826998#M1033181</guid>
      <dc:creator>mythosmc1</dc:creator>
      <dc:date>2019-03-12T12:49:40Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2826999#M1033185</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These are the three modes on which you can set the ASA:&lt;/P&gt;
&lt;P&gt;The fail-close keyword sets the ASA to block all traffic if the ASA FirePOWER module is unavailable.&lt;BR /&gt;The fail-open keyword sets the ASA to allow all traffic through, uninspected, if the module is unavailable.&lt;BR /&gt;Specify monitor-only to send a read-only copy of traffic to the module, i.e. inline tap mode. If you do not include the keyword, the traffic is sent in inline mode. Be sure to configure consistent policies on the ASA and the ASA FirePOWER. See ASA FirePOWER Inline Tap Monitor-Only Mode for more information.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If the firepower module goes down then yes the traffic will be dropped.But when you say locked up what do you exactly mean ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check the status of the module by the command : show module sfr detail&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also let me know the version of ASA and SFR .&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 02:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2826999#M1033185</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-11-26T02:58:25Z</dc:date>
    </item>
    <item>
      <title>This was happening on both 5</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827000#M1033190</link>
      <description>&lt;P&gt;This was happening on both 5.4.1.1-33 as well as version 6&lt;/P&gt;
&lt;P&gt;I am having trouble understanding what you mean with monitor-only mode; Are you recommending me to use that?&lt;/P&gt;
&lt;P&gt;I am not entirely sure if the module is locked up, but some event happens and firepower begins to block all outgoing traffic until the service policy is disabled&lt;/P&gt;
&lt;P&gt;I have since rebooted the module, so this output is probably useless:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Result of the command: "show module sfr detail"&lt;/P&gt;
&lt;P&gt;Getting details from the Service Module, please wait...&lt;/P&gt;
&lt;P&gt;Card Type: FirePOWER Services Software Module&lt;BR /&gt;Model: ASA5512&lt;BR /&gt;Hardware version: N/A&lt;BR /&gt;Serial Number: FCH1902JC39&lt;BR /&gt;Firmware version: N/A&lt;BR /&gt;Software version: 6.0.0-1005&lt;BR /&gt;MAC Address Range: b0aa.7796.5920 to b0aa.7796.5920&lt;BR /&gt;App. name: ASA FirePOWER&lt;BR /&gt;App. Status: Up&lt;BR /&gt;App. Status Desc: Normal Operation&lt;BR /&gt;App. version: 6.0.0-1005&lt;BR /&gt;Data Plane Status: Up&lt;BR /&gt;Console session: Ready&lt;BR /&gt;Status: Up&lt;BR /&gt;DC addr: 172.16.x.zzz&amp;nbsp;&lt;BR /&gt;Mgmt IP addr: 172.16.x.xxx&amp;nbsp;&lt;BR /&gt;Mgmt Network mask: 255.255.255.0 &lt;BR /&gt;Mgmt Gateway: 172.16.x.yyy&amp;nbsp;&lt;BR /&gt;Mgmt web ports: 443 &lt;BR /&gt;Mgmt TLS enabled: true&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 03:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827000#M1033190</guid>
      <dc:creator>mythosmc1</dc:creator>
      <dc:date>2015-11-26T03:53:04Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827001#M1033192</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I would recommend you using fail-open mode so that if the module goes down the traffic still continues to pass. Also check the status of the module when the issue happens before disabling the service-policy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also if the status of the module is up , you can check the connection events and see if the trafic is being blocked. Are there of any signs of oversubscription on the module&amp;nbsp; as in do you have a lot of traffic passing through the SFR module.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 05:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827001#M1033192</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-11-26T05:12:55Z</dc:date>
    </item>
    <item>
      <title>After some browsing on here I</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827002#M1033195</link>
      <description>&lt;P&gt;After some browsing on here I am hoping it has something to do with this bug,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://tools.cisco.com/bugsearch/bug/CSCut39253/?reffering_site=dumpcr&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have 3 clients with firepower, only one of them is without this issue.. and I beleive the one that doesn't have any issues isnt using&amp;nbsp;AMP/file protection features&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This seems like a pretty serious 'bug' is there anywhere I can sign up for bulletins for these types of issues?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 16:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827002#M1033195</guid>
      <dc:creator>mythosmc1</dc:creator>
      <dc:date>2015-11-26T16:37:17Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827003#M1033198</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes , if on the bug you click on save bug you will get subscribed to it and you will get an option to get notifications based on it on weekly or monthly basis.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 01:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827003#M1033198</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-12-01T01:29:56Z</dc:date>
    </item>
    <item>
      <title>I have this problem too. I</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827004#M1033200</link>
      <description>&lt;P style="text-align: left;"&gt;I have this problem too. I have the service-policy set to fail-open, though it isn't working as expected. The SFR module still states it is up / up and normal operation, however no traffic is passed when inline.&lt;/P&gt;
&lt;P style="text-align: left;"&gt;A reboot of the module fixes it temporarily. Or setting the service policy to monitor-only (this resumes traffic flow through the ASA but the firepower module doesn't log any of the traffic)&lt;/P&gt;
&lt;P style="text-align: left;"&gt;I can't find any syslogs at the time of the failure. Are there some debugs I can run? It generally lasts between a day and a week before failing again.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 06:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-in-5512-x-denying-all-traffic-failing-closed/m-p/2827004#M1033200</guid>
      <dc:creator>Jarrad Thomas</dc:creator>
      <dc:date>2016-04-08T06:30:34Z</dc:date>
    </item>
  </channel>
</rss>

