cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
696
Views
0
Helpful
5
Replies

FWSM coming up without full config after a reboot

Thomas Cotton
Level 1
Level 1

We have a customer who has 4 x 'WS-SVC-FWM-1' modules installed within 2 x 6513 chassis. The FWSMs are all running version 3.1(16) with failover group 1 and 2 enabled.

After a few recent planned and un-planned power outages the FWSMs have come up without a full configuration. Is this a common fault? If so it there any kind of workaround that can be implemented?

5 Replies 5

Jennifer Halim
Cisco Employee
Cisco Employee

Normally if the FWSM doesn't come up with full config, most likely reason is it is not saved into memory when changes happens.

Also another possible reason is the configuration doesn't get replicated to the standby unit.

To ensure that config gets replicated and save correctly, pls issue:

wr standby

wr mem

That will ensure that config gets replicated to the standby unit, and once replication is complete, you issue wr mem, so it gets saved into both FWSM.

Hi Jennifer,

I can confirm both modules had their config saved after the first outage but the problem still re-occured. Is there anything else to watch out for?

Since you have failover group configured, I believe you have multiple context configured.

Which part of the config is missing after the reload?

How many context do you have configured and how big is the configuration?

Is it consistently missing the same part of the configuration?

Thomas Cotton
Level 1
Level 1

Hi,

Please see the below extract from a recent FWSM auidt by one of ours TDAs:

Each time the config has been lost it's been seemingly random parts that have vanished. The VPNs have to be re-created manually to bring it back to service. These FWSMs sit behind Bombguard hardware devices.

Thanks

What is the VPN configuration doing on the FWSM? to manage the FWSM itself, or something else?

Review Cisco Networking for a $25 gift card