cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7651
Views
10
Helpful
7
Replies

ASA 5506-X SourceFire Update

Rodrigo Gurriti
Level 6
Level 6

 

Hi,

Has anyone updated SF on a 5506-X? I just got two out of the box and tried to update and I get this error:


Task Status Your task Installing Cisco Network Sensor Patch version: 5.4.1.1-23 (Local Install) failed at Wed Jun 10 21:11:20 2015
Update Installation Failed : [55%] Fatal error: Error running script 800_post/001_reinstall_sru.sh

 

The IOS running on the ASA was 9.3.3 and 9.4.1 and both times it failed. The update starts and then the SF goes Unresponsive and I have to do a manual reload and then I see the error.

Right now the 3D Device running software version: 5.4.1 and this update was a patch Cisco_Network_Sensor_Patch-5.4.1.1-23.sh

 

The image here shows the device stuck in "running"

 

Thank you,

Rod

 

7 Replies 7

Rodrigo Gurriti
Level 6
Level 6

OK found the problem.

In a nutshell the update takes too long and the module goes to a Unresponsive state and stay that way for 30min then it comes back.

I thought the updated had failed, because the module was unresponsive for more then 20min, then I reloaded the module. After it booted up I got the error msg on the asdm.

Turns out that the 5506 takes around 30 min to upgrade. The module goes for about 30min unresponsive then it comes back! Never thought a 30mb upgrade would take this long that is the why i reloaded the module.

Cya

How did you apply the patch?

The process for applying patches using ASDM is detailed in the User Guide.

Please see this direct link.

so mine has been non responsive for an hour can I check on the task in the CLI via ssh?

Thanks

Yes. GO into the FirePOWER service module cli and switch to expert mode.

Then "cd /var/log/sf".

Look for the folder with the name of youpatch and cd into it.

Then "tail status.log".

If you wwant to watch for updates in real time, then "tail -f status.log".

cisco should really ship new device with 6.x...

I think I'm on my 5th upgrade.. and still have more to do.

I guess I should have just did a reload rather than 8 upgrades...

Thanks..

I feel stupid because now it says 5.4.1.1 is running, when this morning it says 5.4.1 was running.

 

Did I actually upgrade?  I had all the failures that Rodrigo had with many of the same reasons.  I let it go and finally I see this is different.

 

Why is it marked as 5.4.1.2-23 sensor patch but indicate 5.4.1.1 installed and running if it did in fact complete installation?  Shouldn't these version numbers match, or am I being a little quixotic?

 

I am using an ASA 5506-X

 

Thank you for any kind souls which can shed light on this.  I am a total noob!

Review Cisco Networking for a $25 gift card