03-24-2023 10:00 AM
Hi,
Was wondering is someone could assist me. We have 2 ASA 5516-X FirePower appliances, I upgraded them to the lasted ASA and ASMD images but due to LDAP certification based authentication error had to roll back the changes (another issue for another time). The issue I am facing now is that for one of the ASAs, I am no longer able to access it via ASDM nor can I navigate to it via HTTP, I can only access it via CLI (putty).
If I reboot the ASA, I get a very small window where I can connect to it via ASDM (and navigate to the admin portal via HTTP) but after 10secs, connection seizes and times out.
I have checked that aaa is configured correct by comparing to working ASA - I have also checked that HTTP/ASDM management through outside and inside interface are correct.
Finally, the running config hasnt been modified during upgrade and rollback so stumped at to what has happened.
Any help/suggestion would be greatly appreciated.
Thanks
03-25-2023 08:21 AM
what is the ASA Code running now and upgrade to ? (which was failed)
what logs do you see on the ASA when you try to connect o ASDM?
Is this HA ?
03-26-2023 01:56 AM
03-26-2023 03:40 AM
Get more information from you the party to address this correctly.
03-26-2023 11:27 AM
03-26-2023 12:57 PM
friend there is ASDM image and there is ASA image and both must be compatibility otherwise it not work
Cisco Secure Firewall ASA Compatibility - Cisco
03-26-2023 03:19 PM
03-26-2023 03:40 PM
Asa# verify flash:/asdm-7141-48.bin
Asa# show asdm image
Check the image and check if asa use right image or not
03-27-2023 12:41 AM
@MHM Cisco World - ran those commands on both ASAs
asdm is running from disk0 (again this is inherited setup and worked fine since implementation). verified and asa is using the right one. As mentioned in OP, if i reboot the appliance, for a 30sec window i can connect to asa via both webadmin and asdm but then connection drops as if host/destination cant be found. Its almost as if the host address changes - is there a way to see ASDM connection logs via CLI?
03-27-2023 03:53 AM
debug http 255
debug asdm history 255
03-27-2023 05:23 AM
Thanks for those commands see below:
http output:
<asaappliance>(config)# HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
HTTP: Periodic admin session check (idle-timeout = 1200, session-timeout = 0)
Will provide ASDM output asap.
However, debugging the above error i happened upon this article.
https://community.cisco.com/t5/network-security/asa5505-asdm-won-t-launch/td-p/2360302/page/3
Thanks
03-27-2023 10:51 PM
@MHM Cisco World - sorry for the delay - ran that command for ASDM but go no response from the appliance. I will have to reboot OOH and see if i can get result then.
04-02-2023 03:41 PM
@MHM Cisco World - ran the debug asdm command - no response from the appliance. What I did do is check what resources are being called when I try to connect to the web admin portal - please see results in attached image - based on that information - seems that those components cant be found and therefore call to access cannot be fulfilled. I have even tried to changed ASDM to version asdm7151-150.bin - same issue. Any ideas? Ty.
04-14-2023 08:51 AM
Bro, seems some of ASDM modules not running. Did you check the firewall in case of any restriction?
09-10-2023 11:29 AM
@Max Jobs - sorry for lack of attention to this, had another project take precedence. So ASDM is working again - dont know how but the consistent trend was connectivity timeouts/packet drops. Going to try upgrade FW of ASA again - this time applying interim upgrades.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide