cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8736
Views
5
Helpful
21
Replies

ASA 5506 ASDM can't connect to Firepower module

Javid_B
Level 1
Level 1

Hi everyone, 

Not long time ago started to see such problem. I'm using the default ASA firewall config (inside is 192.168.42.253/24) and setup the FirePower module to use 192.168.42.203/24. I can ping the FirePower module from my PC and from the ASA's CLI and can connect via SSH. 

I've ran "show module" and the sfr module is Up/Up, and I have IP connection with the module from the ASA CLI. 

ASDM log from Java console show "Failed to connect to FirePower, continuing without it"

ASA version - 7.6(1)

ASDM version - 9.6(1)

Firepower module version - 6.0.1.4-82

Java version - JRE 1.8.0_181 x86

Help please.

1 Accepted Solution

Accepted Solutions

Yes, that's correct.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.html#pgfId-1485825

 

...except that you shutdown and uninstall the sfr module in your use case (not ips) and then follow the procedure as written.

 

You'd start with 6.2.3 (asasfr-5500x-boot-6.2.3-4.img and asasfr-sys-6.2.3-83.pkg) and then patch it to 6.2.3.6 (Cisco_Network_Sensor_Patch-6.2.3.6-37.sh.REL.tar).

 

Those files can all be found here (entitlement required to download):

 

https://software.cisco.com/download/home/286283326/type/286277393/release/6.2.3.6

View solution in original post

21 Replies 21

Marvin Rhoads
Hall of Fame
Hall of Fame

Was it working previously? Is it configured for local (ASDM) management?

 

If it wasn't working previously and this is a first use of the Firepower service module, I'd suggest reimaging it to the current 6.2.3 release and the use ASDM 7.9(2)+.

 

To check if it is configured for local management, use the command "show module sfr detail".

Yes, it was working previously, but very long time (about 5-6 months) I didn't connect and check anything because I didn't need to reconfigure.

"Show module sfr detail" gave me "Unable to read details from module sfr". Then I've issued:

conf t

sw-module module sfr reload

After reload the ""Show module sfr detail" gave -

Card type: FirePOWER Services Software Module

Model: ASA5506

Hardware version: N/A

Serial number: JAD203605F4

Firmware version: N/A

Software version: 6.0.1.4-82

MAC Address Range: 00a2.ee92.ed00 to 00a2.ee92.ed00

App. name: ASA FirePOWER

App. Status: Up

App. Status Desc.: Normal Operation

App. version: 6.0.1.4-82

Data Plane Status: Up

Console session: Ready

Status: Up

DC addr:    

Mgmt IP addr: 192.168.42.203

Mgmt Network mask: 255.255.255.0

Mgmt Gateway: 192.168.42.253

Mgmt web ports: 443

Mgmt TLS enabled: true

 

But then when I tried again that command I got "Unable to read details from module sfr" till now.

Is the management port on the ASA connected to your switch and in the same VLAN as your ASA's data interface that you are connecting to with the ASDM?

--
Please remember to select a correct answer and rate helpful posts

Management port of the ASA not configured and not connected. For management we use inside interface IP that is in the same VLAN and network as ASDM and FirePOWER.

The Firepower module on an ASA 5500-X series requires that you use the physical management interface.

 

You don't need to configure it in the ASA operating system but the module must use it for management.

So, as I understand I should configure management interface on ASA with Firepower IP address (in my case 192.168.42.203) and connect it common switch or I should give some free IP address to management interface of ASA on the same VLAN connect it to the switch but on Firepower set the Management gateway not inside interface of ASA as it now, but that management interface with new IP. Could you please clarify?

Please refer to the following link which has a good diagram and additional explanation:

 

https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html#pgfId-139738

 

The Firepower module can still use the ASA inside address as its default gateway. The Firepower module is like a VM on the ASA hardware that only has one external interface available: the management interface.

So I've checked the connection and yes, everything was correct - management interface of ASA 5506-x is connected to the same switch as inside interface of ASA and they are in the same vlan. Interface of switch is up and line protocol is up (and indicators are blinking). Everything correct so far but still I can't connect to the Firepower through ASDM (FirePOWER tab is missing). Also I've noticed that ASDM shows the Firepower dashboard in the monitoring tab, but the configuration tab of Firepower in configuration tab is missing. Every time when I try to open the ASDM it takes a long time to enter the menu and then for the first 1-2 minutes everything becomes frozen and after when ASDM comes up I see "lost connection to Firewall" in the graphs before graphs start drawing.

I remember that in my home lab I had a similar issue where I was not able to get ASDM to connect with the firepower.  I think it had something to do with ARP since after I ping the FTD mgmt interface ASDM was able to connect to Firepower.  Unfortunately, I had to do this each time I was going to make changes to Firepower (ping firepower mgmt IP, then open up ASDM).

--
Please remember to select a correct answer and rate helpful posts

Didn't help.

Check the output of "show module sfr detail" and see if the module has been configured to be managed by a "DC" (Defense Center - old name for Firepower Management Center).

 

If it is, then you will first have to "configure manager delete" from the module's cli.

As you may see below, DC field is empty:

 

Card type: FirePOWER Services Software Module

Model: ASA5506

Hardware version: N/A

Serial number: JAD203605F4

Firmware version: N/A

Software version: 6.0.1.4-82

MAC Address Range: 00a2.ee92.ed00 to 00a2.ee92.ed00

App. name: ASA FirePOWER

App. Status: Up

App. Status Desc.: Normal Operation

App. version: 6.0.1.4-82

Data Plane Status: Up

Console session: Ready

Status: Up

DC addr:    

Mgmt IP addr: 192.168.42.203

Mgmt Network mask: 255.255.255.0

Mgmt Gateway: 192.168.42.253

Mgmt web ports: 443

Mgmt TLS enabled: true

Sorry - I didn't scroll back and realize you already provided that information.

 

Can you confirm the address assigned to the module is unique to it? Also, make sure you have not configured an IP address on the ASA management interface.

 

FirePOWER IP is unique in network and management interface of ASA doesn't have an IP address.

Also I've noticed that show disk on sfr module show 100% full of /var/ , but when I searching that folder in expert mode with ls -lah I couldn't find which folder are so big and show disk-manager gave me 100% full Temporary, Backups and logs. 

Could this be an issue of device access in ASDM or this is the another forum topic ?

Review Cisco Networking products for a $25 gift card