<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower ASA 2110 completely broken in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696315#M1093793</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt; I'm not sure about interim builds updating FXOS (or not).&lt;/P&gt;
&lt;P&gt;They do only include bug fixes; but ostensibly there could be an FXOS bug that needs to be fixed and Cisco uses an interim ASA build to accomplish that. However, looking at several ASA interim build release notes I didn't notice any that also mention FXOS bug fixes. So I'd be inclined to believe ASA interim builds do not update FXOS.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/web/software/280775065/160837/ASA-9163-Interim-Release-Notes.html" target="_blank"&gt;https://www.cisco.com/web/software/280775065/160837/ASA-9163-Interim-Release-Notes.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 17:43:48 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2022-09-29T17:43:48Z</dc:date>
    <item>
      <title>Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4694410#M1093680</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have 2 x FPR2110-ASA-K9 and I'm trying to set up an active/standby state between them but unfortunately I face a lot of issues.&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Versions :&lt;/U&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cisco Adaptive Security Appliance Software Version 9.8(2)&lt;/LI&gt;
&lt;LI&gt;Firepower Extensible Operating System Version 2.2(2.52)&lt;/LI&gt;
&lt;LI&gt;Device Manager Version 7.8(2)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;1. FXOS CLI is broken (Timed out communicating with DME)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I cannot run (almost) any command through FXOS CLI. I constantly get the error message "Software Error: Exception during execution: [Error: Timed out communicating with DME]". I found some related bugs (especially&amp;nbsp;CSCvs61701 and&amp;nbsp;&lt;SPAN&gt;CSCul61847) but either there is no workaround or the command doesn't exist.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;I wanted to do a fresh install but apparently it needs some commands to be applied on FXOS side... which I can't do.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Ex :&lt;/P&gt;
&lt;PRE&gt;firepower# show eth-uplink&lt;BR /&gt;Software Error: Exception during execution: [Error: Timed out communicating with DME]&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;DME service is set to failed state (which is different compared to crashed state) :&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;firepower(local-mgmt)# show pmon state&lt;BR /&gt;&lt;BR /&gt;SERVICE NAME STATE RETRY(MAX) EXITCODE SIGNAL CORE&lt;BR /&gt;------------ ----- ---------- -------- ------ ----&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;svc_sam_dme failed 4(4) 0 11 yes&lt;/FONT&gt;&lt;BR /&gt;svc_sam_dcosAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_portAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_statsAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_licenseAG running 0(4) 0 0 no&lt;BR /&gt;httpd.sh running 0(4) 0 0 no&lt;BR /&gt;svc_sam_sessionmgrAG running 0(4) 0 0 no&lt;BR /&gt;sam_core_mon running 0(4) 0 0 no&lt;BR /&gt;svc_sam_svcmonAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_serviceOrchAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_appAG running 0(4) 0 0 no&lt;BR /&gt;svc_sam_envAG running 0(4) 0 0 no&lt;/PRE&gt;
&lt;P&gt;Obviously I tried to reboot many many times and nothing changed. Since I cannot upgrade or do a fresh install, what should I do ? Do I miss something ?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. FCM GUI infinite loading&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Firepower Chassis Management GUI is also broken because it shows an infinite loading on the login page, like the "Login" button is grey and it is impossible to click on it. Probably related to the first point. I tried with different computers and browsers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. No route on my routing table (ASA)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I know the conditions that a route needs to match in order to be installed in the routing table. But the thing is that I am currently remotely connected to the firewall but no route seems installed on my routing table :&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;firepower# sh route&lt;BR /&gt;&lt;BR /&gt;[...]&lt;BR /&gt;Gateway of last resort is not set&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;firepower# sh run | i route&lt;BR /&gt;route INSIDE 10.0.0.0 255.0.0.0 10.1.1.1 1&lt;BR /&gt;route MGMT 10.0.0.0 255.0.0.0 10.2.2.2 2&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;/PRE&gt;
&lt;P&gt;It is expected that I don't have a gateway of last resort (because I cant enable the Internet Interface on FXOS side...).&lt;/P&gt;
&lt;P&gt;I suspect this to be my issue when trying to communicate with our License server (On-Prem Manager) because I can't see any request that goes outside the FW when forcing the token or renewing the authentication.&lt;/P&gt;
&lt;P&gt;If you need anything just tell me, thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4694410#M1093680</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-09-28T09:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695175#M1093705</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;does your FW have smartnet? it would be prudent to open a TAC case to resolve your problems.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 05:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695175#M1093705</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2022-09-28T05:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695216#M1093707</link>
      <description>&lt;P&gt;This sound very strange issue. I have worked with FTD-2110 and encounter issue. but this seem to be the strangest one. If you have contract in place with cisco (smartNet) or any PSS with your partner (cisco partner) escalate it to them. So you can get involve the TAC or get the RMA for these appliances.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bug&amp;nbsp;&amp;nbsp;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs61701" target="_blank" rel="noopener"&gt;CSCvs61701&lt;/A&gt; FIPS/trustpoint but in your case you cant access the config due to error you getting.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:24:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695216#M1093707</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T08:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695240#M1093715</link>
      <description>&lt;P&gt;Are these new (out of the box) and behaving this way or have they been reimaged from an earlier working state?&lt;/P&gt;
&lt;P&gt;I've worked with a number of Firepower devices running ASA image and have never seen errors like the ones you cite.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695240#M1093715</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-09-28T09:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695256#M1093723</link>
      <description>&lt;P&gt;We do not have order them so I believe we don't have. How can I make sure ? Can I try to look for it somewhere with serial numbers ?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695256#M1093723</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-09-28T09:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695258#M1093724</link>
      <description>&lt;P&gt;"&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;SPAN&gt; None" .....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I will try to open a case but we need to buy a maintenance contract first.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695258#M1093724</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-09-28T09:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695259#M1093725</link>
      <description>&lt;P&gt;These are brand new Firepower that have never been reimaged.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695259#M1093725</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-09-28T09:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695264#M1093726</link>
      <description>&lt;P&gt;If they are brand new firewall. Just let cisco know they are not fit for purpose due to these issues you encounter. if these arrived within 2 to 4 week. you can raise the issue with cisco or the third party who were involved to bought these appliances. As it stand its not your issue the appliances shipped faulty.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695264#M1093726</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T09:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695268#M1093728</link>
      <description>&lt;P&gt;We ordered them back in November 2021 and we were only able to configure them this month... My supplier don't want/can't open a case.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695268#M1093728</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-09-28T09:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695274#M1093729</link>
      <description>&lt;P&gt;Yes I understand due to project pipe line and other thing inlne. sometime the hardware is just in IT store room. I completely understand this. &lt;BR /&gt;On the other side I guess you have not much options to get these appliances under support with cisco and RMA them. Shame the appliance does not seem to be fit in purpose. And this will postpone all the planning work you was going to under take.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695274#M1093729</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T09:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695322#M1093733</link>
      <description>&lt;P&gt;Obviously, if DME process constantly fails on your appliance, you cannot use CLI or FCM and entire appliance becomes unusable.&lt;/P&gt;&lt;P&gt;You can try to reimage it using ROMMON:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/2100/troubleshoot_fxos/b_2100_CLI_Troubleshoot/b_2100_CLI_Troubleshoot_chapter_011.html#task_ryc_5wm_1jb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/2100/troubleshoot_fxos/b_2100_CLI_Troubleshoot/b_2100_CLI_Troubleshoot_chapter_011.html#task_ryc_5wm_1jb&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This procedure will replace both FXOS and ASA versions. Configuration will be lost. You can try latest ASA 9.16.3 interim which is currently marked goldstar release. This will include FXOS 2.10.1.something. Or you can try older ASA 9.12 and this will include FXOS 2.6.1.something. I wouldn't recommend other versions. BTW, I'm not sure how Cisco updates FXOS when new ASA or FTD version for FP2100/1000 is released and if we have a table somewhere which documents all version pairs. Having this table would help to workaround few known FXOS bugs. Other board members are welcome to comment on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695322#M1093733</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2022-09-28T11:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695910#M1093767</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt; there is a table with the ASA to bundled FXOS version found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65802" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_65802&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 12:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4695910#M1093767</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-09-29T12:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696141#M1093785</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Right, but it doesn't list ASA interims. Only minor versions are listed there. I'm not really sure whether Cisco updates FXOS when ASA interim is released, or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 15:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696141#M1093785</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2022-09-29T15:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696315#M1093793</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1342399"&gt;@tvotna&lt;/a&gt; I'm not sure about interim builds updating FXOS (or not).&lt;/P&gt;
&lt;P&gt;They do only include bug fixes; but ostensibly there could be an FXOS bug that needs to be fixed and Cisco uses an interim ASA build to accomplish that. However, looking at several ASA interim build release notes I didn't notice any that also mention FXOS bug fixes. So I'd be inclined to believe ASA interim builds do not update FXOS.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/web/software/280775065/160837/ASA-9163-Interim-Release-Notes.html" target="_blank"&gt;https://www.cisco.com/web/software/280775065/160837/ASA-9163-Interim-Release-Notes.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 17:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696315#M1093793</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-09-29T17:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696427#M1093799</link>
      <description>&lt;P&gt;Upon some thinking I realized they do update FXOS. For example, let's take a look at famous &lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/722/fn72282.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/722/fn72282.html&lt;/A&gt; and the defect &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84127" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84127&lt;/A&gt;. The defect is fixed in FXOS &lt;SPAN class=""&gt;002.006(001.245)&lt;/SPAN&gt; and ASA &lt;SPAN class=""&gt;009.012(004.039). Compatibility table &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html&lt;/A&gt; shows the following:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;9.12(4)&lt;/TD&gt;&lt;TD&gt;2.6(1.198)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This means that FXOS was updated when interim was released. But it looks like the correspondence between ASA interims and FXOS versions isn't documented in a single place and we need to reverse engineer it from bug toolkit. Typical for Cisco.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 20:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4696427#M1093799</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2022-09-29T20:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower ASA 2110 completely broken</title>
      <link>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4699058#M1093999</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thank you, I will try this ASAP and will let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 08:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-asa-2110-completely-broken/m-p/4699058#M1093999</guid>
      <dc:creator>StephanBretonCNS</dc:creator>
      <dc:date>2022-10-06T08:02:04Z</dc:date>
    </item>
  </channel>
</rss>

