10-17-2018 01:12 AM - edited 03-12-2019 04:13 AM
Hi everyone,
Not long time ago started to see such problem. I'm using the default ASA firewall config (inside is 192.168.42.253/24) and setup the FirePower module to use 192.168.42.203/24. I can ping the FirePower module from my PC and from the ASA's CLI and can connect via SSH.
I've ran "show module" and the sfr module is Up/Up, and I have IP connection with the module from the ASA CLI.
ASDM log from Java console show "Failed to connect to FirePower, continuing without it"
ASA version - 7.6(1)
ASDM version - 9.6(1)
Firepower module version - 6.0.1.4-82
Java version - JRE 1.8.0_181 x86
Help please.
Solved! Go to Solution.
10-25-2018 03:59 AM - edited 10-25-2018 04:00 AM
Yes, that's correct.
...except that you shutdown and uninstall the sfr module in your use case (not ips) and then follow the procedure as written.
You'd start with 6.2.3 (asasfr-5500x-boot-6.2.3-4.img and asasfr-sys-6.2.3-83.pkg) and then patch it to 6.2.3.6 (Cisco_Network_Sensor_Patch-6.2.3.6-37.sh.REL.tar).
Those files can all be found here (entitlement required to download):
https://software.cisco.com/download/home/286283326/type/286277393/release/6.2.3.6
10-17-2018 05:16 AM
Was it working previously? Is it configured for local (ASDM) management?
If it wasn't working previously and this is a first use of the Firepower service module, I'd suggest reimaging it to the current 6.2.3 release and the use ASDM 7.9(2)+.
To check if it is configured for local management, use the command "show module sfr detail".
10-17-2018 12:22 PM - edited 10-17-2018 12:24 PM
Yes, it was working previously, but very long time (about 5-6 months) I didn't connect and check anything because I didn't need to reconfigure.
"Show module sfr detail" gave me "Unable to read details from module sfr". Then I've issued:
conf t
sw-module module sfr reload
After reload the ""Show module sfr detail" gave -
Card type: FirePOWER Services Software Module
Model: ASA5506
Hardware version: N/A
Serial number: JAD203605F4
Firmware version: N/A
Software version: 6.0.1.4-82
MAC Address Range: 00a2.ee92.ed00 to 00a2.ee92.ed00
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc.: Normal Operation
App. version: 6.0.1.4-82
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr:
Mgmt IP addr: 192.168.42.203
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 192.168.42.253
Mgmt web ports: 443
Mgmt TLS enabled: true
But then when I tried again that command I got "Unable to read details from module sfr" till now.
10-17-2018 06:36 AM
Is the management port on the ASA connected to your switch and in the same VLAN as your ASA's data interface that you are connecting to with the ASDM?
10-17-2018 12:26 PM
Management port of the ASA not configured and not connected. For management we use inside interface IP that is in the same VLAN and network as ASDM and FirePOWER.
10-17-2018 08:20 PM
The Firepower module on an ASA 5500-X series requires that you use the physical management interface.
You don't need to configure it in the ASA operating system but the module must use it for management.
10-18-2018 08:12 AM
So, as I understand I should configure management interface on ASA with Firepower IP address (in my case 192.168.42.203) and connect it common switch or I should give some free IP address to management interface of ASA on the same VLAN connect it to the switch but on Firepower set the Management gateway not inside interface of ASA as it now, but that management interface with new IP. Could you please clarify?
10-18-2018 08:20 AM
Please refer to the following link which has a good diagram and additional explanation:
https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html#pgfId-139738
The Firepower module can still use the ASA inside address as its default gateway. The Firepower module is like a VM on the ASA hardware that only has one external interface available: the management interface.
10-22-2018 04:03 AM
So I've checked the connection and yes, everything was correct - management interface of ASA 5506-x is connected to the same switch as inside interface of ASA and they are in the same vlan. Interface of switch is up and line protocol is up (and indicators are blinking). Everything correct so far but still I can't connect to the Firepower through ASDM (FirePOWER tab is missing). Also I've noticed that ASDM shows the Firepower dashboard in the monitoring tab, but the configuration tab of Firepower in configuration tab is missing. Every time when I try to open the ASDM it takes a long time to enter the menu and then for the first 1-2 minutes everything becomes frozen and after when ASDM comes up I see "lost connection to Firewall" in the graphs before graphs start drawing.
10-22-2018 04:07 AM
I remember that in my home lab I had a similar issue where I was not able to get ASDM to connect with the firepower. I think it had something to do with ARP since after I ping the FTD mgmt interface ASDM was able to connect to Firepower. Unfortunately, I had to do this each time I was going to make changes to Firepower (ping firepower mgmt IP, then open up ASDM).
10-22-2018 04:57 AM
Didn't help.
10-22-2018 05:13 AM
Check the output of "show module sfr detail" and see if the module has been configured to be managed by a "DC" (Defense Center - old name for Firepower Management Center).
If it is, then you will first have to "configure manager delete" from the module's cli.
10-22-2018 05:20 AM
As you may see below, DC field is empty:
Card type: FirePOWER Services Software Module
Model: ASA5506
Hardware version: N/A
Serial number: JAD203605F4
Firmware version: N/A
Software version: 6.0.1.4-82
MAC Address Range: 00a2.ee92.ed00 to 00a2.ee92.ed00
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc.: Normal Operation
App. version: 6.0.1.4-82
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr:
Mgmt IP addr: 192.168.42.203
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 192.168.42.253
Mgmt web ports: 443
Mgmt TLS enabled: true
10-22-2018 05:26 AM
Sorry - I didn't scroll back and realize you already provided that information.
Can you confirm the address assigned to the module is unique to it? Also, make sure you have not configured an IP address on the ASA management interface.
10-23-2018 12:38 AM
FirePOWER IP is unique in network and management interface of ASA doesn't have an IP address.
Also I've noticed that show disk on sfr module show 100% full of /var/ , but when I searching that folder in expert mode with ls -lah I couldn't find which folder are so big and show disk-manager gave me 100% full Temporary, Backups and logs.
Could this be an issue of device access in ASDM or this is the another forum topic ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide