<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which ASA Software Version to Use? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/which-asa-software-version-to-use/m-p/2155978#M358674</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the ASA I use are using a software between 8.4(1) and 8.4(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the software 9.1(1) has had for example some NAT configurations that cause problems for people. That is also one reason why I havent updated some of our ASAs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be honest I havent run into or identified that many bugs in our environment. Also one thing that probably minimizes our risk to bump into a bug is that we use multilple ASA firewalls for different purposes (Firewalling/NAT and VPN separately)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest recomendation I have heard has been 8.4(5) but to be honest as soon as I heard that I was told elsewhere that people were running into major problems using this software. So I guess it comes down to what you configure/use on the ASA in question and for example if you are using Failover or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im probably still going to wait some time for some newer releases before I upgrade our devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One reason the 9.1(1) might not be shown at the top is that the software 9.0(2) is newer than 9.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: Actually there seems to be a release 9.1(1)4 which is newer than 9.0(2). Under the 9.1.1 Interim. I guess it must have some bugfixes related to the 9.1(1) software. Doh I must be blind you already mentioned this &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Apr 2013 20:21:30 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-04-08T20:21:30Z</dc:date>
    <item>
      <title>Which ASA Software Version to Use?</title>
      <link>https://community.cisco.com/t5/network-security/which-asa-software-version-to-use/m-p/2155977#M358673</link>
      <description>&lt;P&gt;A few questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Is there a rhyme or reason on what is posted on CCO under the "Latest Releases" header? Right now, it has 9.0.2.ED, 8.4.5.ED and 8.2.5.ED listed (but not 9.1.1.ED).&amp;nbsp; Instead, 9.1.1.ED is listed further below under "All Releases".&amp;nbsp; Is this Cisco's way saying don't use 9.1.1.ED?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; I've gone through the release notes of all of them, and frankly, they all seem to have show stopper bugs.&amp;nbsp; Right now, we're trying to upgrade a pair of firewalls from 8.2 to modern software.&amp;nbsp; Previously an attempt was made to go to 9.1.1.ED (released Dec 2012) and the customer had strange problems (certain apps would stop working) after a few hours so they reverted&amp;nbsp; back to 8.2.&amp;nbsp; The fact that 9.1.1.ED is buried under "All Releases" concerns me.&amp;nbsp; There's a 9.1.1 Interim release (from&amp;nbsp; March 2013) that I'm considering using.&amp;nbsp; Of course, there are 85 bugs fixed in that Interim release and none of them really match the symptoms the customer experienced.&amp;nbsp; Should I use this Interim release?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Maybe I should go down to 9.0.2.ED (released Feb 2013)?&amp;nbsp; Maybe much older releases?&amp;nbsp; BTW, this is just a simple ASA5520 with plenty of RAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why are there so many bugs?&amp;nbsp; I could spend an eternity going through all of them.&amp;nbsp; &lt;SPAN __jive_emoticon_name="angry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/1/1/134114-9-1-1-not-there.png" alt="9-1-1-not-there.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/which-asa-software-version-to-use/m-p/2155977#M358673</guid>
      <dc:creator>ds6123</dc:creator>
      <dc:date>2019-03-12T01:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Which ASA Software Version to Use?</title>
      <link>https://community.cisco.com/t5/network-security/which-asa-software-version-to-use/m-p/2155978#M358674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the ASA I use are using a software between 8.4(1) and 8.4(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the software 9.1(1) has had for example some NAT configurations that cause problems for people. That is also one reason why I havent updated some of our ASAs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be honest I havent run into or identified that many bugs in our environment. Also one thing that probably minimizes our risk to bump into a bug is that we use multilple ASA firewalls for different purposes (Firewalling/NAT and VPN separately)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latest recomendation I have heard has been 8.4(5) but to be honest as soon as I heard that I was told elsewhere that people were running into major problems using this software. So I guess it comes down to what you configure/use on the ASA in question and for example if you are using Failover or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im probably still going to wait some time for some newer releases before I upgrade our devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One reason the 9.1(1) might not be shown at the top is that the software 9.0(2) is newer than 9.1(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: Actually there seems to be a release 9.1(1)4 which is newer than 9.0(2). Under the 9.1.1 Interim. I guess it must have some bugfixes related to the 9.1(1) software. Doh I must be blind you already mentioned this &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Apr 2013 20:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/which-asa-software-version-to-use/m-p/2155978#M358674</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-08T20:21:30Z</dc:date>
    </item>
  </channel>
</rss>

