<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5506x oldest software version to downgrade while keeping secur in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4847096#M1101113</link>
    <description>&lt;P&gt;What is not working with your monitoring system? There is one such issue I can think of - SNMP polling over site-site VPN. There's a work around for this documented in the release notes here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/release/notes/asarn914.html#reference_xqs_mvp_xhb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/release/notes/asarn914.html#reference_xqs_mvp_xhb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2023 15:59:29 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2023-06-01T15:59:29Z</dc:date>
    <item>
      <title>ASA 5506x oldest software version to downgrade while keeping security</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846035#M1101055</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;I need to downgrade the ASA software version because our monitoring software has an incompatibility with the latest ASA 5506x software version 9.16; however, it works great with version 9.12. My dilemma, is that i don't know how to find out whether or not it would still be ok to use that version without compromising the security of the network.&lt;/P&gt;&lt;P&gt;I can see the latest available software is 9.16(x), so is fair to assume that one is the one with the latest bug and security fixes; however, what is the oldest software version I can downgrade to without compromising security?&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, if I go back say to version 9.8(x), yeah most likely there will be a lot of unpatched security holes, but could i go back to say 9.12(x) and still be ok from the security standpoint?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 02:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846035#M1101055</guid>
      <dc:creator>m4k3rz</dc:creator>
      <dc:date>2023-05-31T02:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846114#M1101060</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1364518"&gt;@m4k3rz&lt;/a&gt; downgrading to an older version such as 9.12 is a backwards step in regard to security, as the latest version of 9.12(4) your hardware supports is 3 years old.&lt;/P&gt;
&lt;P&gt;Have you tried the latest version, 9.16.4 interim - &lt;A href="https://software.cisco.com/download/home/286283326/type/280775065/release/9.16.4%20Interim" target="_blank"&gt;https://software.cisco.com/download/home/286283326/type/280775065/release/9.16.4%20Interim&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Tbh there is no good version of ASA software to use on the ASA 5506-X hardware, the firewall is EOL and has been replaced with the FPR-1010 series which supports the latest versions of ASA software or FTD.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 06:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846114#M1101060</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-31T06:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846536#M1101081</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;I did try the 9.16 interim, but as i mentioned on the initial post, is not working with the monitoring system we use. I've done extensive troubleshooting and can't pin point where the issue lays. That's why I pondered about downgrading to 9.12(x) which is a version that other ASA on our network is using and working fine with the monitoring.&lt;/P&gt;&lt;P&gt;This is the exact ASA 5506x model I am using. Is running Cisco ASA software and not FTD.&lt;BR /&gt;# sh inv&lt;BR /&gt;Name: "Chassis", DESCR: "ASA 5506-X with SW, 8GE Data, 1GE Mgmt, AC"&lt;BR /&gt;PID: ASA5506 , VID: V07 , SN: XYZ&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Could someone please provide the EOL link for the ASA 5506 software? I'd like to see where is the last date for bugs and security fixes releases.&lt;BR /&gt;I've been looking but can only find EOL for hardware&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/security/asa-5506-x-firepower-services/model.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/asa-5506-x-firepower-services/model.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-c51-744797.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-c51-744797.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 14:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846536#M1101081</guid>
      <dc:creator>m4k3rz</dc:creator>
      <dc:date>2023-05-31T14:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846547#M1101082</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1364518"&gt;@m4k3rz&lt;/a&gt; ASA version 9.12 is actually in software maintenance support until Feb 27 2024, but 9.12 hasn't had a software update for 3 years on the 5506-X, so has 3 years worth of security vulnerabilities unpatched. &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-12x-eol.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-12x-eol.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Using 9.12 is a step backwards in regard to security in my view, but I appreciate your position though. I'd still recommend replacing the hardware, you can still use ASA software, 9.19 is the latest version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 15:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846547#M1101082</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-31T15:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846675#M1101093</link>
      <description>&lt;P&gt;Thank you, where did you find out that 9.12 is still in maintenance support until 2024?&lt;/P&gt;&lt;P&gt;also, if that's the case, why it hasn't been receiving updates for bug fixes and security updates for over 3 years?&lt;/P&gt;&lt;P&gt;Thanks Rob&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 19:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846675#M1101093</guid>
      <dc:creator>m4k3rz</dc:creator>
      <dc:date>2023-05-31T19:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846709#M1101098</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1364518"&gt;@m4k3rz&lt;/a&gt; its on the link I provided previously. &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-12x-eol.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-12x-eol.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1685562906005.png" style="width: 669px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/186166iC9838E4F7E8FCC39/image-dimensions/669x107?v=v2" width="669" height="107" role="button" title="RobIngram_0-1685562906005.png" alt="RobIngram_0-1685562906005.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I guess it is Cisco's way to force customers to purchase new hardware, as the 5506-X is very old now. Although they have updated 9.16 more recently. Perhaps log a TAC call with Cisco regarding your issue with 9.16?&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 21:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4846709#M1101098</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-31T21:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4847083#M1101110</link>
      <description>&lt;P&gt;Thanks so much for your help. I'm trying to open a TAC ticket, but is not letting me because the serial number of the device is not linked to any support contract. is there any other way you know of?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 15:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4847083#M1101110</guid>
      <dc:creator>m4k3rz</dc:creator>
      <dc:date>2023-06-01T15:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506x oldest software version to downgrade while keeping secur</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4847096#M1101113</link>
      <description>&lt;P&gt;What is not working with your monitoring system? There is one such issue I can think of - SNMP polling over site-site VPN. There's a work around for this documented in the release notes here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/release/notes/asarn914.html#reference_xqs_mvp_xhb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/release/notes/asarn914.html#reference_xqs_mvp_xhb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 15:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-oldest-software-version-to-downgrade-while-keeping/m-p/4847096#M1101113</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-06-01T15:59:29Z</dc:date>
    </item>
  </channel>
</rss>

