cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
11446
Views
5
Helpful
11
Replies

ASA 5506 Sourcefire module stuck in Recovery

rfpatterson
Level 4
Level 4

I executed these steps:

  1. debug module-boot
  2. sw-module module sfr recover configure image disk0:/file_path
  3. ciscoasa# sw-module module sfr recover boot

The debug says it is complete, however it never gets past recover mode.  Here is the debug:

 

ASA-FP# sw-module module sfr recover configure image disk0:asasfr-5500x-boot-5$

ASA-FP# sw-module module sfr recover boot

 

Module sfr will be recovered. This may erase all configuration and all data

on that device and attempt to download/install a new image for it. This may take

several minutes.

 

Recover module sfr? [confirm]

Recover issued for module sfr.

ASA-FP# Mod-sfr 0> ***

Mod-sfr 1> *** EVENT: Creating the Disk Image...

Mod-sfr 2> *** TIME: 13:25:58 EDT Oct 9 2015

Mod-sfr 3> ***

Mod-sfr 4> ***

Mod-sfr 5> *** EVENT: The module is being recovered.

Mod-sfr 6> *** TIME: 13:25:58 EDT Oct 9 2015

Mod-sfr 7> ***

Mod-sfr 8> ***

Mod-sfr 9> *** EVENT: Disk Image created successfully.

Mod-sfr 10> *** TIME: 13:27:42 EDT Oct 9 2015

Mod-sfr 11> ***

Mod-sfr 12> ***

Mod-sfr 13> *** EVENT: Start Parameters: Image: /mnt/disk0/vm/vm_1.img, ISO: -cdrom /mnt/disk0/

Mod-sfr 14> asasfr-5500x-boot-5.4.1-211.img, Num CPUs: 3, RAM: 2292MB, Mgmt MAC: 80:E0:1D:7D:53

Mod-sfr 15> :BB, CP MAC: 00:00:00:02:00:01, HDD: -drive file=/dev/sda,cache=none,if=virtio, Dev

Mod-sfr 16> ***

Mod-sfr 17> *** EVENT: Start Parameters Continued: RegEx Shared Mem: 0MB, Cmd Op: r, Shared Mem

Mod-sfr 18>  Key: 8061, Shared Mem Size: 16, Log Pipe: /dev/ttyS0_vm1, Sock: /dev/ttyS1_vm1, Me

Mod-sfr 19> m-Path: -mem-path /hugepages

Mod-sfr 20> *** TIME: 13:27:43 EDT Oct 9 2015

Mod-sfr 21> ***

Mod-sfr 22> Status: Mapping host 0x2aab3a800000 to VM with size 16777216

Mod-sfr 23> Warning: vlan 0 is not connected to host network

Mod-sfr 24> ISOLINUX 3.73 2009-01-25  Copyright (C) 1994-2008 H. Peter Anvin

Mod-sfr 25>                    Cisco SFR-BOOT-IMAGE and CX-BOOT-IMAGE for SFR - 5.4.1

Mod-sfr 26>     (WARNING: ALL DATA ON DISK 1 WILL BE LOST)

Mod-sfr 27> Loading bzImage..........................................................

Mod-sfr 28> Loading initramfs.gz...............................................................

Mod-sfr 29> ...................................................................................

Mod-sfr 30> ...................................................................................

Mod-sfr 31> ...................................................................................

Mod-sfr 32> ...................................................................................

Mod-sfr 33> ...................................................................................

Mod-sfr 34> ...................................................................................

Mod-sfr 35> ...................ready.

Mod-sfr 36> [    0.000000] BIOS EBDA/lowmem at: 0009fc00/0009fc00

Mod-sfr 37> [    0.000000] Initializing cgroup subsys cpuset

Mod-sfr 38> [    0.000000] Initializing cgroup subsys cpu

Mod-sfr 39> [    0.000000] Linux version 2.6.28.10.x86-target-64 (build@cel64build.esn.sourcefi

Mod-sfr 40> re.com) (gcc version 4.3.3 (MontaVista Linux Sourcery G++ 4.3-292) ) #1 SMP PREEMPT

Mod-sfr 41>  Mon Feb 2 00:15:14 EST 2015

Mod-sfr 42> [    0.000000] Command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IMAGE=bzIm

Mod-sfr 43> age

Mod-sfr 44> [    0.000000] KERNEL supported cpus:

Mod-sfr 45> [    0.000000]   Intel GenuineIntel

Mod-sfr 46> [    0.000000]   AMD AuthenticAMD

Mod-sfr 47> [    0.000000]   Centaur CentaurHauls

Mod-sfr 48> [    0.000000] PAT WC disabled due to known CPU erratum.

Mod-sfr 49> [    0.000000] BIOS-provided physical RAM map:

Mod-sfr 50> [    0.000000]  BIOS-e820: 0000000000000000 - 000000000009fc00 (usable)

Mod-sfr 51> [    0.000000]  BIOS-e820: 000000000009fc00 - 00000000000a0000 (reserved)

Mod-sfr 52> [    0.000000]  BIOS-e820: 00000000000f0000 - 0000000000100000 (reserved)

Mod-sfr 53> [    0.000000]  BIOS-e820: 0000000000100000 - 000000008f3fe000 (usable)

Mod-sfr 54> [    0.000000]  BIOS-e820: 000000008f3fe000 - 000000008f400000 (reserved)

Mod-sfr 55> [    0.000000]  BIOS-e820: 00000000feffc000 - 00000000ff000000 (reserved)

Mod-sfr 56> [    0.000000]  BIOS-e820: 00000000fffc0000 - 0000000100000000 (reserved)

Mod-sfr 57> [    0.000000] DMI 2.4 present.

Mod-sfr 58> [    0.000000] last_pfn = 0x8f3fe max_arch_pfn = 0x3ffffffff

Mod-sfr 59> [    0.000000] init_memory_mapping: 0000000000000000-000000008f3fe000

Mod-sfr 60> [    0.000000] last_map_addr: 8f3fe000 end: 8f3fe000

Mod-sfr 61> [    0.000000] RAMDISK: 7dbe4000 - 7ffff3a6

Mod-sfr 62> [    0.000000] ACPI: RSDP 000FD900, 0014 (r0 BOCHS )

Mod-sfr 63> [    0.000000] ACPI: RSDT 8F3FE3E0, 0034 (r1 BOCHS  BXPCRSDT        1 BXPC        1

Mod-sfr 64> [    0.000000] ACPI: FACP 8F3FFF80, 0074 (r1 BOCHS  BXPCFACP        1 BXPC        1

Mod-sfr 65> [    0.000000] ACPI: DSDT 8F3FE420, 11A9 (r1   BXPC   BXDSDT        1 INTL 20100528

Mod-sfr 66> [    0.000000] ACPI: FACS 8F3FFF40, 0040

Mod-sfr 67> [    0.000000] ACPI: SSDT 8F3FF740, 07F7 (r1 BOCHS  BXPCSSDT        1 BXPC        1

Mod-sfr 68> [    0.000000] ACPI: APIC 8F3FF610, 0088 (r1 BOCHS  BXPCAPIC        1 BXPC        1

Mod-sfr 69> [    0.000000] ACPI: HPET 8F3FF5D0, 0038 (r1 BOCHS  BXPCHPET        1 BXPC        1

Mod-sfr 70> [    0.000000] No NUMA configuration found

Mod-sfr 71> [    0.000000] Faking a node at 0000000000000000-000000008f3fe000

Mod-sfr 72> [    0.000000] Bootmem setup node 0 0000000000000000-000000008f3fe000

Mod-sfr 73> [    0.000000]   NODE_DATA [0000000000001000 - 0000000000005fff]

Mod-sfr 74> [    0.000000]   bootmap [000000000000b000 -  000000000001ce7f] pages 12

Mod-sfr 75> [    0.000000] (6 early reservations) ==> bootmem [0000000000 - 008f3fe000]

Mod-sfr 76> [    0.000000]   #0 [0000000000 - 0000001000]   BIOS data page ==> [0000000000 - 00

Mod-sfr 77> 00001000]

Mod-sfr 78> [    0.000000]   #1 [0000006000 - 0000008000]       TRAMPOLINE ==> [0000006000 - 00

Mod-sfr 79> 00008000]

Mod-sfr 80> [    0.000000]   #2 [0000200000 - 0000ae86dc]    TEXT DATA BSS ==> [0000200000 - 00

Mod-sfr 81> 00ae86dc]

Mod-sfr 82> [    0.000000]   #3 [007dbe4000 - 007ffff3a6]          RAMDISK ==> [007dbe4000 - 00

Mod-sfr 83> 7ffff3a6]

Mod-sfr 84> [    0.000000]   #4 [000009fc00 - 0000100000]    BIOS reserved ==> [000009fc00 - 00

Mod-sfr 85> 00100000]

Mod-sfr 86> [    0.000000]   #5 [0000008000 - 000000b000]          PGTABLE ==> [0000008000 - 00

Mod-sfr 87> 0000b000]

Mod-sfr 88> [    0.000000] found SMP MP-table at [ffff8800000fdac0] 000fdac0

Mod-sfr 89> [    0.000000] Zone PFN ranges:

Mod-sfr 90> [    0.000000]   DMA      0x00000000 -> 0x00001000

Mod-sfr 91> [    0.000000]   DMA32    0x00001000 -> 0x00100000

Mod-sfr 92> [    0.000000]   Normal   0x00100000 -> 0x00100000

Mod-sfr 93> [    0.000000] Movable zone start PFN for each node

Mod-sfr 94> [    0.000000] early_node_map[2] active PFN ranges

Mod-sfr 95> [    0.000000]     0: 0x00000000 -> 0x0000009f

Mod-sfr 96> [    0.000000]     0: 0x00000100 -> 0x0008f3fe

Mod-sfr 97> [    0.000000] ACPI: PM-Timer IO Port: 0xb008

Mod-sfr 98> [    0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)

Mod-sfr 99> [    0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)

Mod-sfr 100> [    0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)

Mod-sfr 101> [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])

Mod-sfr 102> [    0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])

Mod-sfr 103> [    0.000000] IOAPIC[0]: apic_id 0, version 0, address 0xfec00000, GSI 0-23

Mod-sfr 104> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)

Mod-sfr 105> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)

Mod-sfr 106> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)

Mod-sfr 107> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)

Mod-sfr 108> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)

Mod-sfr 109> [    0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000

Mod-sfr 110> [    0.000000] Using ACPI (MADT) for SMP configuration information

Mod-sfr 111> [    0.000000] SMP: Allowing 3 CPUs, 0 hotplug CPUs

Mod-sfr 112> [    0.000000] Allocating PCI resources starting at 90000000 (gap: 8f400000:6fbfc0

Mod-sfr 113> 00)

Mod-sfr 114> [    0.000000] PERCPU: Allocating 53248 bytes of per cpu data

Mod-sfr 115> [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages

Mod-sfr 116> : 576247

Mod-sfr 117> [    0.000000] Policy zone: DMA32

Mod-sfr 118> [    0.000000] Kernel command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IM

Mod-sfr 119> AGE=bzImage

Mod-sfr 120> [    0.000000] Initializing CPU#0

Mod-sfr 121> [    0.000000] PID hash table entries: 4096 (order: 12, 32768 bytes)

Mod-sfr 122> [    0.000000] TSC: Unable to calibrate against PIT

Mod-sfr 123> [    0.000000] TSC: HPET/PMTIMER calibration failed.

Mod-sfr 124> [    0.000000] Marking TSC unstable due to could not calculate TSC khz

Mod-sfr 125> [    0.000000] Console: colour VGA+ 80x25

Mod-sfr 126> [    0.000000] console [ttyS0] enabled

Mod-sfr 127> [    0.000000] allocated 23592960 bytes of page_cgroup

Mod-sfr 128> [    0.000000] please try cgroup_disable=memory option if you don't want

Mod-sfr 129> [    0.000000] Checking aperture...

Mod-sfr 130> [    0.000000] No AGP bridge found

Mod-sfr 131> [    0.000000] Memory: 2244276k/2347000k available (4733k kernel code, 388k absent

Mod-sfr 132> , 102336k reserved, 2572k data, 544k init)

Mod-sfr 133> [    0.000000] HPET: 3 timers in total, 0 timers will be used for per-cpu timer

Mod-sfr 134> [    0.001999] Calibrating delay loop... 1056.76 BogoMIPS (lpj=528384)

Mod-sfr 135> [    0.028995] Security Framework initialized

Mod-sfr 136> [    0.031995] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)

Mod-sfr 137> [    0.038994] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)

Mod-sfr 138> [    0.040993] Mount-cache hash table entries: 256

Mod-sfr 139> [    0.042993] Initializing cgroup subsys ns

Mod-sfr 140> [    0.043993] Initializing cgroup subsys cpuacct

Mod-sfr 141> [    0.044993] Initializing cgroup subsys memory

Mod-sfr 142> [    0.045993] CPU: L1 I cache: 32K, L1 D cache: 32K

Mod-sfr 143> [    0.047992] CPU: L2 cache: 4096K

Mod-sfr 144> [    0.048992] CPU 0/0x0 -> Node 0

Mod-sfr 145> [    0.049992] ACPI: Core revision 20080926

Mod-sfr 146> [    0.053991] Setting APIC routing to flat

Mod-sfr 147> [    0.058991] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1

Mod-sfr 148> [    0.069989] CPU0: Intel QEMU Virtual CPU version 1.5.0 stepping 03

Mod-sfr 149> [    0.072988] Booting processor 1 APIC 0x1 ip 0x6000

Mod-sfr 150> [    0.000999] Initializing CPU#1

Mod-sfr 151> [    0.000999] Calibrating delay loop... 1249.28 BogoMIPS (lpj=624640)

Mod-sfr 152> [    0.000999] CPU: L1 I cache: 32K, L1 D cache: 32K

Mod-sfr 153> [    0.000999] CPU: L2 cache: 4096K

Mod-sfr 154> [    0.000999] CPU 1/0x1 -> Node 0

Mod-sfr 155> [    0.106983] CPU1: Intel QEMU Virtual CPU version 1.5.0 stepping 03

Mod-sfr 156> [    0.110983] Booting processor 2 APIC 0x2 ip 0x6000

Mod-sfr 157> [    0.000999] Initializing CPU#2

Mod-sfr 158> [    0.000999] Calibrating delay loop... 1249.28 BogoMIPS (lpj=624640)

Mod-sfr 159> [    0.000999] CPU: L1 I cache: 32K, L1 D cache: 32K

Mod-sfr 160> [    0.000999] CPU: L2 cache: 4096K

Mod-sfr 161> [    0.000999] CPU 2/0x2 -> Node 0

Mod-sfr 162> [    0.145977] CPU2: Intel QEMU Virtual CPU version 1.5.0 stepping 03

Mod-sfr 163> [    0.150977] Brought up 3 CPUs

Mod-sfr 164> [    0.151976] Total of 3 processors activated (3555.32 BogoMIPS).

Mod-sfr 165> [    0.155976] net_namespace: 1280 bytes

Mod-sfr 166> [    0.158975] NET: Registered protocol family 16

Mod-sfr 167> [    0.162975] ACPI: bus type pci registered

Mod-sfr 168> [    0.165974] PCI: Using configuration type 1 for base access

Mod-sfr 169> [    0.208968] ACPI: Interpreter enabled

Mod-sfr 170> [    0.210967] ACPI: (supports S0 S5)

Mod-sfr 171> [    0.212967] ACPI: Using IOAPIC for interrupt routing

Mod-sfr 172> [    0.226965] ACPI: No dock devices found.

Mod-sfr 173> [    0.228965] ACPI: PCI Root Bridge [PCI0] (0000:00)

Mod-sfr 174> [    0.236963] pci 0000:00:01.3: quirk: region b000-b03f claimed by PIIX4 ACPI

Mod-sfr 175> [    0.238963] pci 0000:00:01.3: quirk: region b100-b10f claimed by PIIX4 SMB

Mod-sfr 176> [    0.284956] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)

Mod-sfr 177> [    0.287956] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)

Mod-sfr 178> [    0.291955] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)

Mod-sfr 179> [    0.294955] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)

Mod-sfr 180> [    0.297954] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)

Mod-sfr 181> [    0.303953] SCSI subsystem initialized

Mod-sfr 182> [    0.306953] usbcore: registered new interface driver usbfs

Mod-sfr 183> [    0.308952] usbcore: registered new interface driver hub

Mod-sfr 184> [    0.310952] usbcore: registered new device driver usb

Mod-sfr 185> [    0.313952] PCI: Using ACPI for IRQ routing

Mod-sfr 186> [    0.324000] cfg80211: Using static regulatory domain info

Mod-sfr 187> [    0.326000] cfg80211: Regulatory domain: US

Mod-sfr 188> [    0.328000]     (start_freq - end_freq @ bandwidth), (max_antenna_gain, max_eirp)

Mod-sfr 189> [    0.330000]     (2402000 KHz - 2472000 KHz @ 40000 KHz), (600 mBi, 2700 mBm)

Mod-sfr 190> [    0.332000]     (5170000 KHz - 5190000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)

Mod-sfr 191> [    0.334000]     (5190000 KHz - 5210000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)

Mod-sfr 192> [    0.336000]     (5210000 KHz - 5230000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)

Mod-sfr 193> [    0.338000]     (5230000 KHz - 5330000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)

Mod-sfr 194> [    0.340000]     (5735000 KHz - 5835000 KHz @ 40000 KHz), (600 mBi, 3000 mBm)

Mod-sfr 195> [    0.342000] cfg80211: Calling CRDA for country: US

Mod-sfr 196> [    0.344000] NetLabel: Initializing

Mod-sfr 197> [    0.346000] NetLabel:  domain hash size = 128

Mod-sfr 198> [    0.348000] NetLabel:  protocols = UNLABELED CIPSOv4

Mod-sfr 199> [    0.350000] NetLabel:  unlabeled traffic allowed by default

Mod-sfr 200> [    0.352000] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0

Mod-sfr 201> [    0.355000] hpet0: 3 comparators, 64-bit 100.000000 MHz counter

Mod-sfr 202> [    0.363162] pnp: PnP ACPI init

Mod-sfr 203> [    0.364902] ACPI: bus type pnp registered

Mod-sfr 204> [    0.373117] pnp: PnP ACPI: found 9 devices

Mod-sfr 205> [    0.375853] ACPI: ACPI bus type pnp unregistered

Mod-sfr 206> [    0.390113] bus: 00 index 0 io port: [0x00-0xffff]

Mod-sfr 207> [    0.392654] bus: 00 index 1 mmio: [0x000000-0xffffffffffffffff]

Mod-sfr 208> [    0.396124] NET: Registered protocol family 2

Mod-sfr 209> [    0.408163] IP route cache hash table entries: 131072 (order: 8, 1048576 bytes)

Mod-sfr 210> [    0.418293] TCP established hash table entries: 524288 (order: 11, 8388608 byte

Mod-sfr 211> s)

Mod-sfr 212> [    0.430272] TCP bind hash table entries: 65536 (order: 8, 1048576 bytes)

Mod-sfr 213> [    0.434109] TCP: Hash tables configured (established 524288 bind 65536)

Mod-sfr 214> [    0.438086] TCP reno registered

Mod-sfr 215> [    0.444206] NET: Registered protocol family 1

Mod-sfr 216> [    0.447125] checking if image is initramfs... it is

Mod-sfr 217> [    6.518130] Freeing initrd memory: 36972k freed

Mod-sfr 218> [    6.569185] Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter

Mod-sfr 219>  Oruba

Mod-sfr 220> [    6.588064] HugeTLB registered 2 MB page size, pre-allocated 0 pages

Mod-sfr 221> [    6.593576] VFS: Disk quotas dquot_6.5.1

Mod-sfr 222> [    6.595689] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)

Mod-sfr 223> [    6.605316] msgmni has been set to 4455

Mod-sfr 224> [    6.612220] alg: No test for stdrng (krng)

Mod-sfr 225> [    6.615153] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 252

Mod-sfr 226> [    6.618853] io scheduler noop registered

Mod-sfr 227> [    6.620963] io scheduler anticipatory registered

Mod-sfr 228> [    6.623461] io scheduler deadline registered

Mod-sfr 229> [    6.625704] io scheduler cfq registered (default)

Mod-sfr 230> [    6.628422] LTT : ltt-relay init

Mod-sfr 231> [    6.631109] ltt-control init

Mod-sfr 232> [    6.662473] LTT : ltt-kprobes init

Mod-sfr 233> [    6.664400] pci 0000:00:00.0: Limiting direct PCI/PCI transfers

Mod-sfr 234> [    6.667440] pci 0000:00:01.0: PIIX3: Enabling Passive Release

Mod-sfr 235> [    6.670447] pci 0000:00:01.0: Activating ISA DMA hang workarounds

Mod-sfr 236> [    6.678607] pci_hotplug: PCI Hot Plug PCI Core version: 0.5

Mod-sfr 237> [    6.686734] processor ACPI_CPU:00: registered as cooling_device0

Mod-sfr 238> [    6.690758] processor ACPI_CPU:01: registered as cooling_device1

Mod-sfr 239> [    6.694508] processor ACPI_CPU:02: registered as cooling_device2

Mod-sfr 240> [    6.745499] Non-volatile memory driver v1.2

Mod-sfr 241> [    6.747732] Linux agpgart interface v0.103

Mod-sfr 242> [    6.751051] [drm] Initialized drm 1.1.0 20060810

Mod-sfr 243> [    6.753517] Serial: 8250/16550 driver4 ports, IRQ sharing enabled

Mod-sfr 244> ÿ[    7.006452] serial8250: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A

Mod-sfr 245> [    7.258458] serial8250: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A

Mod-sfr 246> [    7.266612] 00:06: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A

Mod-sfr 247> [    7.271074] 00:07: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A

Mod-sfr 248> [    7.276159] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M

Mod-sfr 249> [    7.291444] FDC 0 is a S82078B

Mod-sfr 250> [    7.317314] brd: module loaded

Mod-sfr 251> [    7.328490] loop: module loaded

Mod-sfr 252> [    7.330818] Intel(R) Gigabit Ethernet Network Driver - version 1.2.45-k2

Mod-sfr 253> [    7.334212] Copyright (c) 2008 Intel Corporation.

Mod-sfr 254> [    7.337304] pcnet32.c:v1.35 21.Apr.2008 tsbogend@alpha.franken.de

Mod-sfr 255> [    7.340979] e100: Intel(R) PRO/100 Network Driver, 3.5.23-k6-NAPI

Mod-sfr 256> [    7.344061] e100: Copyright(c) 1999-2006 Intel Corporation

Mod-sfr 257> [    7.348056] sky2 driver version 1.22

Mod-sfr 258> [    7.353036] console [netcon0] enabled

Mod-sfr 259> [    7.354877] netconsole: network logging started

Mod-sfr 260> [    7.358495] input: Macintosh mouse button emulation as /devices/virtual/input/i

Mod-sfr 261> nput0

Mod-sfr 262> [    7.365941] Loading iSCSI transport class v2.0-870.

Mod-sfr 263> [    7.375699] Driver 'sd' needs updating - please use bus_type methods

Mod-sfr 264> [    7.379516] Driver 'sr' needs updating - please use bus_type methods

Mod-sfr 265> [    7.387492] scsi0 : ata_piix

Mod-sfr 266> [    7.391492] scsi1 : ata_piix

Mod-sfr 267> [    7.394664] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14

Mod-sfr 268> [    7.398007] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15

Mod-sfr 269> [    7.555320] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100

Mod-sfr 270> [    7.558496] ata1.00: 6291456 sectors, multi 16: LBA48

Mod-sfr 271> [    7.562297] ata1.00: configured for MWDMA2

Mod-sfr 272> [    7.718432] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100

Mod-sfr 273> [    7.722448] ata2.00: configured for MWDMA2

Mod-sfr 274> [    7.726963] isa bounce pool size: 16 pages

Mod-sfr 275> [    7.728428] scsi 0:0:0:0: Direct-Access     ATA      QEMU HARDDISK    1.5. PQ:

Mod-sfr 276> 0 ANSI: 5

Mod-sfr 277> [    7.733798] sd 0:0:0:0: [sda] 6291456 512-byte hardware sectors: (3.22 GB/3.00

Mod-sfr 278> GiB)

Mod-sfr 279> [    7.737586] sd 0:0:0:0: [sda] Write Protect is off

Mod-sfr 280> [    7.741046] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'

Mod-sfr 281> t support DPO or FUA

Mod-sfr 282> [    7.744505] sd 0:0:0:0: [sda] 6291456 512-byte hardware sectors: (3.22 GB/3.00

Mod-sfr 283> GiB)

Mod-sfr 284> [    7.748396] sd 0:0:0:0: [sda] Write Protect is off

Mod-sfr 285> [    7.750876] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'

Mod-sfr 286> t support DPO or FUA

Mod-sfr 287> [    7.755364]  sda: unknown partition table

Mod-sfr 288> [    7.761433] sd 0:0:0:0: [sda] Attached SCSI disk

Mod-sfr 289> [    7.765315] sd 0:0:0:0: Attached scsi generic sg0 type 0

Mod-sfr 290> [    7.770345] scsi 1:0:0:0: CD-ROM            QEMU     QEMU DVD-ROM     1.5. PQ:

Mod-sfr 291> 0 ANSI: 5

Mod-sfr 292> [    7.777328] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray

Mod-sfr 293> [    7.780375] Uniform CD-ROM driver Revision: 3.20

Mod-sfr 294> [    7.785706] sr 1:0:0:0: Attached scsi generic sg1 type 5

Mod-sfr 295> [    7.791309] Fusion MPT base driver 3.04.07

Mod-sfr 296> [    7.793519] Copyright (c) 1999-2008 LSI Corporation

Mod-sfr 297> [    7.795993] Fusion MPT SPI Host driver 3.04.07

Mod-sfr 298> [    7.798893] Fusion MPT FC Host driver 3.04.07

Mod-sfr 299> [    7.801803] Fusion MPT SAS Host driver 3.04.07

Mod-sfr 300> [    7.806451] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver

Mod-sfr 301> [    7.810308] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver

Mod-sfr 302> [    7.814054] uhci_hcd: USB Universal Host Controller Interface driver

Mod-sfr 303> [    7.818692] usbcore: registered new interface driver usblp

Mod-sfr 304> [    7.821487] Initializing USB Mass Storage driver...

Mod-sfr 305> [    7.824998] usbcore: registered new interface driver usb-storage

Mod-sfr 306> [    7.827794] USB Mass Storage support registered.

Mod-sfr 307> [    7.830759] usbcore: registered new interface driver libusual

Mod-sfr 308> [    7.834894] PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,1

Mod-sfr 309> [    7.841445] serio: i8042 KBD port at 0x60,0x64 irq 1

Mod-sfr 310> [    7.844551] serio: i8042 AUX port at 0x60,0x64 irq 12

Mod-sfr 311> [    7.852993] mice: PS/2 mouse device common for all mice

Mod-sfr 312> [    7.861470] rtc_cmos 00:01: RTC can wake from S4

Mod-sfr 313> [    7.864335] input: AT Translated Set 2 keyboard as /devices/platform/i8042/seri

Mod-sfr 314> o0/input/input1

Mod-sfr 315> [    7.865148] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0

Mod-sfr 316> [    7.865148] rtc0: alarms up to one day, 114 bytes nvram, hpet irqs

Mod-sfr 317> [    7.865929] i2c /dev entries driver

Mod-sfr 318> [    7.867791] md: raid1 personality registered for level 1

Mod-sfr 319> [    7.880892] device-mapper: ioctl: 4.14.0-ioctl (2008-04-23) initialised: dm-dev

Mod-sfr 320> el@redhat.com

Mod-sfr 321> [    7.885043] cpuidle: using governor ladder

Mod-sfr 322> [    7.887189] cpuidle: using governor menu

Mod-sfr 323> [    7.889424] No iBFT detected.

Mod-sfr 324> [    7.907995] usbcore: registered new interface driver hiddev

Mod-sfr 325> [    7.912219] usbcore: registered new interface driver usbhid

Mod-sfr 326> [    7.914857] usbhid: v2.6:USB HID core driver

Mod-sfr 327> [    7.918409] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11

Mod-sfr 328> [    7.920969] virtio-pci 0000:00:04.0: PCI INT A -> Link[LNKD] -> GSI 11 (level,

Mod-sfr 329> high) -> IRQ 11

Mod-sfr 330> [    7.927488] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10

Mod-sfr 331> [    7.930856] virtio-pci 0000:00:05.0: PCI INT A -> Link[LNKA] -> GSI 10 (level,

Mod-sfr 332> high) -> IRQ 10

Mod-sfr 333> [    7.938651] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 11

Mod-sfr 334> [    7.942086] virtio-pci 0000:00:07.0: PCI INT A -> Link[LNKC] -> GSI 11 (level,

Mod-sfr 335> high) -> IRQ 11

Mod-sfr 336> [    7.948686]  vda: vda1 vda2 vda3 < vda5 vda6 vda7 >

Mod-sfr 337> [    7.964043] Advanced Linux Sound Architecture Driver Version 1.0.18rc3.

Mod-sfr 338> [    7.973312] ALSA device list:

Mod-sfr 339> [    7.974949]   No soundcards found.

Mod-sfr 340> [    7.976759] Netfilter messages via NETLINK v0.30.

Mod-sfr 341> [    7.979604] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)

Mod-sfr 342> [    7.983256] ctnetlink v0.93: registering with nfnetlink.

Mod-sfr 343> [    7.987257] IPv4 over IPv4 tunneling driver

Mod-sfr 344> [    7.991258] ip_tables: (C) 2000-2006 Netfilter Core Team

Mod-sfr 345> [    7.993887] TCP cubic registered

Mod-sfr 346> [    7.995714] Initializing XFRM netlink socket

Mod-sfr 347> [    7.999255] NET: Registered protocol family 10

Mod-sfr 348> [    8.003264] lo: Disabled Privacy Extensions

Mod-sfr 349> [    8.007258] tunl0: Disabled Privacy Extensions

Mod-sfr 350> [    8.011258] ip6_tables: (C) 2000-2006 Netfilter Core Team

Mod-sfr 351> [    8.014386] IPv6 over IPv4 tunneling driver

Mod-sfr 352> [    8.017431] sit0: Disabled Privacy Extensions

Mod-sfr 353> [    8.021257] NET: Registered protocol family 17

Mod-sfr 354> [    8.025256] RPC: Registered udp transport module.

Mod-sfr 355> [    8.026916] RPC: Registered tcp transport module.

Mod-sfr 356> [    8.031108] registered taskstats version 1

Mod-sfr 357> [    8.125760] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/s

Mod-sfr 358> erio1/input/input2

Mod-sfr 359> [    9.543210] Sending DHCP and RARP requests ., OK

Mod-sfr 360> [   10.161328] IP-Config: Got DHCP answer from 0.0.0.0, my address is 192.168.10.1

Mod-sfr 361> 01

Mod-sfr 362> [   10.173277] IP-Config: Complete:

Mod-sfr 363> [   10.175341]      device=eth1, addr=192.168.10.101, mask=255.255.255.0, gw=192.1

Mod-sfr 364> 68.10.2,

Mod-sfr 365> [   10.179964]      host=192.168.10.101, domain=, nis-domain=(none),

Mod-sfr 366> [   10.183083]      bootserver=0.0.0.0, rootserver=0.0.0.0, rootpath=

Mod-sfr 367> [   10.186725] Freeing unused kernel memory: 544k freed

Mod-sfr 368> INIT: version 2.86 booting

Mod-sfr 369> [   10.446791] udevd version 124 started

Mod-sfr 370> Please wait: booting...

Mod-sfr 371> mount: sysfs already mounted or /sys busy

Mod-sfr 372> mount: according to mtab, sysfs is already mounted on /sys

Mod-sfr 373> Starting udev [   10.949268] udev: renamed network interface eth0 to cplane

Mod-sfr 374> [   10.962321] end_request: I/O error, dev fd0, sector 0

Mod-sfr 375> [   10.979259] udev: renamed network interface eth1 to eth0

Mod-sfr 376> [   11.535307] end_request: I/O error, dev fd0, sector 0

Mod-sfr 377> INIT: Entering runlevel: 5

Mod-sfr 378> Starting OpenBSD Secure Shell server: sshd

Mod-sfr 379>   generating ssh RSA key...

Mod-sfr 380>   generating ssh DSA key...

Mod-sfr 381> done.

Mod-sfr 382> Starting Advanced Configuration and Power Interface daemon: acpid.

Mod-sfr 383> acpid: starting up with proc fs

Mod-sfr 384> acpid: opendir(/etc/acpi/events): No such file or directory

Mod-sfr 385> starting Busybox inetd: inetd... done.

Mod-sfr 386> Starting ntpd: done

Mod-sfr 387> Starting syslogd/klogd: done

Mod-sfr 388>

Cisco FirePOWER Services Boot Image 5.4.1

 

ASA-FP# sh mod sfr

 

Mod  Card Type                                    Model              Serial No.

---- -------------------------------------------- ------------------ -----------

sfr Unknown                                      N/A                JAD192502N6

 

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    

---- --------------------------------- ------------ ------------ ---------------

sfr 80e0.1d7d.53bb to 80e0.1d7d.53bb  N/A          N/A         

 

Mod  SSM Application Name           Status           SSM Application Version

---- ------------------------------ ---------------- --------------------------

 

Mod  Status             Data Plane Status     Compatibility

---- ------------------ --------------------- -------------

sfr Recover            Not Applicable       

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

That is expected. Next you have to:

session sfr console

...and then login (admin / Admin123).

You should get a prompt like:

asasfr-boot>

Run "setup" to but basic bootstrap parameters (ip address, hostname etc.) on the partially initialized module.

Then install the System Software image using the system install command:

asasfr-boot> system install [noconfirm] url


Include the noconfirm option if you do not want to respond to confirmation messages. Use an HTTP, HTTPS, or FTP URL; if a username and password are required, you will be prompted for them. the URL should include the package (pkg) with the full SFR installation package image.


When the installation is complete, the system reboots. Allow 10 or more minutes for application component installation and for the ASA FirePOWER services to start.

The show module sfr command output should show all processes as Up.

View solution in original post

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

That is expected. Next you have to:

session sfr console

...and then login (admin / Admin123).

You should get a prompt like:

asasfr-boot>

Run "setup" to but basic bootstrap parameters (ip address, hostname etc.) on the partially initialized module.

Then install the System Software image using the system install command:

asasfr-boot> system install [noconfirm] url


Include the noconfirm option if you do not want to respond to confirmation messages. Use an HTTP, HTTPS, or FTP URL; if a username and password are required, you will be prompted for them. the URL should include the package (pkg) with the full SFR installation package image.


When the installation is complete, the system reboots. Allow 10 or more minutes for application component installation and for the ASA FirePOWER services to start.

The show module sfr command output should show all processes as Up.

Hello,

I am having issues with this module. It seems that it gets stuck. I have a ASA5515 running version 9.4.1 and trying to boot image: asasfr-5500x-boot-5.4.0-763.img

Here is the debug:

FW-N1(config)# sw-module module sfr recover boot

Module sfr will be recovered. This may erase all configuration and all data

on that device and attempt to download/install a new image for it. This may take

several minutes.

Recover module sfr? [confirm]

Recover issued for module sfr.

FW-N1(config)# Mod-sfr 24> ***

Mod-sfr 25> *** EVENT: Creating the Disk Image...

Mod-sfr 26> *** TIME: 11:22:57 CST Dec 18 2015

Mod-sfr 27> ***

Mod-sfr 28> ***

Mod-sfr 29> *** EVENT: The module is being recovered.

Mod-sfr 30> *** TIME: 11:22:57 CST Dec 18 2015

Mod-sfr 31> ***

Mod-sfr 32> ***

Mod-sfr 33> *** EVENT: Disk Image created successfully.

Mod-sfr 34> *** TIME: 11:25:36 CST Dec 18 2015

Mod-sfr 35> ***

Mod-sfr 36> ***

Mod-sfr 37> *** EVENT: Start Parameters: Image: /mnt/disk0/vm/vm_3.img, ISO: -cdrom /mnt/disk0/

Mod-sfr 38> asasfr-5500x-boot-5.4.0-763.img, Num CPUs: 2, RAM: 3730MB, Mgmt MAC: 24:E9:B3:92:56

Mod-sfr 39> :7F, CP MAC: 00:00:00:04:00:01, HDD: -drive file=/dev/md0,cache=none,if=virtio, Dev

Mod-sfr 40> ***

Mod-sfr 41> *** EVENT: Start Parameters Continued: RegEx Shared Mem: 0MB, Cmd Op: r, Shared Mem

Mod-sfr 42>  Key: 8061, Shared Mem Size: 16, Log Pipe: /dev/ttyS0_vm3, Sock: /dev/ttyS1_vm3, Me

Mod-sfr 43> m-Path: -mem-path /hugepages

Mod-sfr 44> *** TIME: 11:25:36 CST Dec 18 2015

Mod-sfr 45> ***

Mod-sfr 46> Status: Mapping host 0x2aab94600000 to VM with size 16777216

Mod-sfr 47> Warning: vlan 0 is not connected to host network

After that I don't get any more information. I have waited about an hour an nothing. Any ideas?

Paul,

What's the current output from the ASA cli when you type:

show module

FW-N1(config)# sh module

Mod  Card Type                                    Model              Serial No.

---- -------------------------------------------- ------------------ -----------

   0 ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5515            FCH1744JJBC

ips Unknown                                      N/A                FCH1744JJBC

cxsc Unknown                                      N/A                FCH1744JJBC

sfr Unknown                                      N/A                FCH1744JJBC

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version     

---- --------------------------------- ------------ ------------ ---------------

   0 24e9.b392.5681 to 24e9.b392.5688  1.0          2.1(9)8      9.4(1)

ips 24e9.b392.567f to 24e9.b392.567f  N/A          N/A          

cxsc 24e9.b392.567f to 24e9.b392.567f  N/A          N/A          

sfr 24e9.b392.567f to 24e9.b392.567f  N/A          N/A          

Mod  SSM Application Name           Status           SSM Application Version

---- ------------------------------ ---------------- --------------------------

ips Unknown                        No Image Present Not Applicable

cxsc Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility

---- ------------------ --------------------- -------------

   0 Up Sys             Not Applicable        

ips Unresponsive       Not Applicable        

cxsc Unresponsive       Not Applicable        

sfr Recover            Not Applicable        

Mod  License Name   License Status  Time Remaining

---- -------------- --------------- ---------------

ips IPS Module     Disabled        perpetual     

OK - when you

session sfr console

...what prompt do you get?

We would expect 

asasfr-boot>

...whereupon we can run setp as I noted above.

If you don't get that, a TAC case ma be in order for more detailed interactive troubleshooting.

I only get this:

FW-N1# session sfr console

Opening console session with module sfr.

Connected to module sfr. Escape character sequence is 'CTRL-^X'.

If I hit enter nothing happens. I will try to open a TAC case

Thanks

Just to let you know. This is a new installation. Before we had ASA CX on that SSD. It was uninstalled successfully. Should I install SFR version 5.3.1 before installing 5.4.0?

Funny I was just going to ask / suggest an uninstallation of the module.

I recently imaged one and used  asasfr-5500x-boot-5.4.1-211.img - that got me to thinking. You mentioned you are trying to install asasfr-5500x-boot-5.4.0-763.img.

I looked up the release notes and the 5506-X is only supported as of 5.4.1. That's almost certainly your issue.

See this reference:

http://www.cisco.com/c/en/us/td/docs/security/firesight/541/relnotes/FireSIGHT-System-Release-Notes-version541.html#pgfId-459427

..where Cisco states:

"Note: To use the ASA FirePOWER module on the ASA5506-X, ASA506H-X, ASA5506W-X, ASA5508-X, and ASA5516-X devices, you must install the Version 5.4.1 image. See the Cisco ASA FirePOWER Module Quick Start Guide for more information on deploying and installing the module."

I would recommend you uninstall the module and start over with the compatible boot image.

My ASA is a 5515. I just used 5.3.1 and it worked. 

Now I need to installed Firesight version 5.3 or 5.4 will work?

Oh sorry - I was going off the thread we've hijacked and didn't double check that bit of your original post.

A similar issues exists though. See the compatibility guide here:

http://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#reference_964C63B709B24CFF83DC1BB991F68CFB

It tells us the 5515-X is not supported on 5.4.1.x - only 5.3.x, 5.4.0.x and 6.0 (which is pretty new). Still, that 5.4.0 boot image should have worked for you.

Anyhow, if you have 5.3.1 working, you're making good progress. I'd go ahead and put the system image on it now and register to your FireSIGHT Management Center.

Assuming FireSIGHT is at the latest 5.4 patch level (currently 5.4.1.4), I'd then upgrade the ASA modules to their latest 5.x patch level - currently 5.4.0.5.

rfpatterson
Level 4
Level 4

Thanks.  That fixed my problem. 

 

 

Review Cisco Networking products for a $25 gift card