03-12-2020 02:08 AM
Hello.
My ASA 5516-x don't connect firepower.
I launched asdm, asdm is stucked "software completed" about 1-2 mins.
after 1-2mins, asdm boot up, but I can't see firepower panels.
and I clicked "ASA firepower Status", ASDM is stucked constantly, so i needed to kill asdm process.
CLI command "show module sfr details" makes same thing.
I have been installed other ASA 5516-x 2 times, but those ASA 5516-x are connecting to firepower very well.
ASA OS Version, ASDM Version, Firepower are even perfectly same..!!
Still, the ASA 5516-x that I installed earlier is going well...
I tried commands "sw-module module sfr shutdown" "sw-module module sfr reset" "sw-module module sfr reload", but I can't resolve this problem.
How can I resolve this problem?
ASDM is stucked 1-2mins "Software update completed" turn.
After log on ASDM, when loading percent is "80%", stucked 1-2mins.
I can use ASA functions, but when I click Firepower functions, ASDM is stucked forever.
Solved! Go to Solution.
03-16-2020 07:54 AM
Hi,
Ensure you use a version of ASDM that supports FPWR (not sure in which version it came), likewise ensure that ASA can reach the management IP address of FPWR. Look here for reference:
Regards,
Cristian Matei.
03-12-2020 02:10 AM
03-12-2020 02:43 AM
Hi,
You never get an output at the command "show module sfr details"? How about command "show module sfr log console" or just "show module"?
Regards,
Cristian Matei.
03-15-2020 05:10 PM
Yes, I never get an output "show module sfr details"
But I can get an output "show module sfr log console" and "show module"
And, I found that Firepower is not detected in the "show version" output.
<show version>
Cisco Adaptive Security Appliance Software Version 9.8(2)
Firepower Extensible Operating System Version 2.2(2.52)
Device Manager Version 7.9(2)152
Compiled on Sun 27-Aug-17 13:06 PDT by builders
System image file is "disk0:/asa982-lfbff-k8.SPA"
Config file at boot was "startup-config"
Yesco-Firewall up 8 days 18 hours
Hardware: ASA5516, 8192 MB RAM, CPU Atom C2000 series 2416 MHz, 1 CPU (8 cores)
Internal ATA Compact Flash, 8000MB
BIOS Flash M25P64 @ 0xfed01000, 16384KB
Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Number of accelerators: 1
1: Ext: GigabitEthernet1/1 : address is 4ce1.7659.660c, irq 255
2: Ext: GigabitEthernet1/2 : address is 4ce1.7659.660d, irq 255
3: Ext: GigabitEthernet1/3 : address is 4ce1.7659.660e, irq 255
4: Ext: GigabitEthernet1/4 : address is 4ce1.7659.660f, irq 255
5: Ext: GigabitEthernet1/5 : address is 4ce1.7659.6610, irq 255
6: Ext: GigabitEthernet1/6 : address is 4ce1.7659.6611, irq 255
7: Ext: GigabitEthernet1/7 : address is 4ce1.7659.6612, irq 255
8: Ext: GigabitEthernet1/8 : address is 4ce1.7659.6613, irq 255
9: Int: Internal-Data1/1 : address is 4ce1.7659.660b, irq 255
10: Int: Internal-Data1/2 : address is 0000.0001.0002, irq 0
11: Int: Internal-Control1/1 : address is 0000.0001.0001, irq 0
12: Int: Internal-Data1/3 : address is 0000.0001.0003, irq 0
13: Ext: Management1/1 : address is 4ce1.7659.660b, irq 0
14: Int: Internal-Data1/4 : address is 0000.0100.0001, irq 0
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 150 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 4 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 300 perpetual
Total VPN Peers : 300 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total TLS Proxy Sessions : 1000 perpetual
Botnet Traffic Filter : Disabled perpetual
Cluster : Enabled perpetual
Cluster Members : 2 perpetual
VPN Load Balancing : Enabled perpetual
Serial Number: JAD24020KMG
Running Permanent Activation Key: 0xeb24eb75 0x04bcdaed 0xb801e9ac 0x854cc00c 0x0b180a9e
Configuration register is 0x1
Image type : Release
Key Version : A
<show module>
Mod Card Type Model Serial No.
---- -------------------------------------------- ------------------ -----------
1 ASA 5516-X with FirePOWER services, 8GE, AC, ASA5516 JAD24020KMG
sfr FirePOWER Services Software Module ASA5516 JAD24020KMG
Mod MAC Address Range Hw Version Fw Version Sw Version
---- --------------------------------- ------------ ------------ ---------------
1 4ce1.7659.660b to 4ce1.7659.6613 3.3 1.1.15 9.8(2)
sfr 4ce1.7659.660a to 4ce1.7659.660a N/A N/A 6.2.2-81
Mod SSM Application Name Status SSM Application Version
---- ------------------------------ ---------------- --------------------------
sfr ASA FirePOWER Up 6.2.2-81
Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
1 Up Sys Not Applicable
sfr Up Up
And I can get an output "show module sfr log console".
<show module sfr log console>
LILO 24.2 boot:
Loading 6.2.2.........................................................................
BIOS data check successful
[ 0.000000] Initializing cgroup subsys cpuset
[ 0.000000] Initializing cgroup subsys cpu
[ 0.000000] Initializing cgroup subsys cpuacct
[ 0.000000] Linux version 3.10.53sf.cisco-150 (build@ful-sfosbuild01) (gcc version 4.7.1 (GCC) ) #1 SMP PREEMPT Thu Aug 31 19:02:52 UTC 2017
[ 0.000000] Command line: auto BOOT_IMAGE=6.2.2 ro root=fd05 console=ttyS0,9600
[ 0.000000] e820: BIOS-provided physical RAM map:
[ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
[ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
[ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000de5fdfff] usable
[ 0.000000] BIOS-e820: [mem 0x00000000de5fe000-0x00000000de5fffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved
[ 0.000000] NX (Execute Disable) protection: active
[ 0.000000] SMBIOS 2.4 present.
[ 0.000000] Hypervisor detected: KVM
[ 0.000000] No AGP bridge found
[ 0.000000] e820: last_pfn = 0xde5fe max_arch_pfn = 0x400000000
[ 0.000000] PAT not supported by CPU.
[ 0.000000] found SMP MP-table at [mem 0x000fda80-0x000fda8f] mapped at [ffff8800000fda80]
[ 0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
[ 0.000000] init_memory_mapping: [mem 0xde200000-0xde3fffff]
[ 0.000000] init_memory_mapping: [mem 0xdc000000-0xde1fffff]
[ 0.000000] init_memory_mapping: [mem 0x80000000-0xdbffffff]
[ 0.000000] init_memory_mapping: [mem 0x00100000-0x7fffffff]
[ 0.000000] init_memory_mapping: [mem 0xde400000-0xde5fdfff]
[ 0.000000] ACPI: RSDP 00000000000fd840 00014 (v00 BOCHS )
[ 0.000000] ACPI: RSDT 00000000de5fe2b0 00034 (v01 BOCHS BXPCRSDT 00000001 BXPC 00000001)
[ 0.000000] ACPI: FACP 00000000de5fff80 00074 (v01 BOCHS BXPCFACP 00000001 BXPC 00000001)
[ 0.000000] ACPI: DSDT 00000000de5fe2f0 011A9 (v01 BXPC BXDSDT 00000001 INTL 20100528)
[ 0.000000] ACPI: FACS 00000000de5fff40 00040
[ 0.000000] ACPI: SSDT 00000000de5ff620 0091A (v01 BOCHS BXPCSSDT 00000001 BXPC 00000001)
[ 0.000000] ACPI: APIC 00000000de5ff4e0 000A0 (v01 BOCHS BXPCAPIC 00000001 BXPC 00000001)
[ 0.000000] ACPI: HPET 00000000de5ff4a0 00038 (v01 BOCHS BXPCHPET 00000001 BXPC 00000001)
[ 0.000000] No NUMA configuration found
[ 0.000000] Faking a node at [mem 0x0000000000000000-0x00000000de5fdfff]
[ 0.000000] Initmem setup node 0 [mem 0x00000000-0xde5fdfff]
[ 0.000000] NODE_DATA [mem 0xde5fa000-0xde5fdfff]
[ 0.000000] kvm-clock: Using msrs 4b564d01 and 4b564d00
[ 0.000000] kvm-clock: cpu 0, msr 0:de5f9001, boot clock
[ 0.000000] Zone ranges:
[ 0.000000] DMA [mem 0x00001000-0x00ffffff]
[ 0.000000] DMA32 [mem 0x01000000-0xffffffff]
[ 0.000000] Normal empty
[ 0.000000] Movable zone start for each node
[ 0.000000] Early memory node ranges
[ 0.000000] node 0: [mem 0x00001000-0x0009efff]
[ 0.000000] node 0: [mem 0x00100000-0xde5fdfff]
[ 0.000000] ACPI: PM-Timer IO Port: 0xb008
[ 0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x03] lapic_id[0x03] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x04] lapic_id[0x04] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x05] lapic_id[0x05] enabled)
[ 0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
[ 0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
[ 0.000000] IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
[ 0.000000] Using ACPI (MADT) for SMP configuration information
[ 0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000
[ 0.000000] smpboot: Allowing 6 CPUs, 0 hotplug CPUs
[ 0.000000] e820: [mem 0xde600000-0xfeffbfff] available for PCI devices
[ 0.000000] Booting paravirtualized kernel on KVM
[ 0.000000] setup_percpu: NR_CPUS:64 nr_cpumask_bits:64 nr_cpu_ids:6 nr_node_ids:1
[ 0.000000] PERCPU: Embedded 24 pages/cpu @ffff8800de000000 s69568 r8192 d20544 u262144
[ 0.000000] kvm-clock: cpu 0, msr 0:de5f9001, primary cpu clock
[ 0.000000] KVM setup async PF for cpu 0
[ 0.000000] kvm-stealtime: cpu 0, msr de00ba40
[ 0.000000] Built 1 zonelists in Node order, mobility grouping on. Total pages: 898274
[ 0.000000] Policy zone: DMA32
[ 0.000000] Kernel command line: auto BOOT_IMAGE=6.2.2 ro root=fd05 console=ttyS0,9600
[ 0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
[ 0.000000] Checking aperture...
[ 0.000000] No AGP bridge found
[ 0.000000] Memory: 3582304k/3643384k available (4768k kernel code, 392k absent, 60688k reserved, 2399k data, 884k init)
[ 0.000000] Preemptible hierarchical RCU implementation.
[ 0.000000] RCU restricting CPUs from NR_CPUS=64 to nr_cpu_ids=6.
[ 0.000000] NR_IRQS:4352 nr_irqs:728 16
[ 0.000000] Console: colour VGA+ 80x25
[ 0.000000] console [ttyS0] enabled
[ 0.000000] allocated 14680064 bytes of page_cgroup
[ 0.000000] please try 'cgroup_disable=memory' option if you don't want memory cgroups
[ 0.000000] tsc: Detected 2416.666 MHz processor
[ 0.003000] Calibrating delay loop (skipped) preset value.. 4833.33 BogoMIPS (lpj=2416666)
[ 0.004009] pid_max: default: 32768 minimum: 301
[ 0.005076] Security Framework initialized
[ 0.008034] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
[ 0.012027] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
[ 0.014201] Mount-cache hash table entries: 256
[ 0.015285] Initializing cgroup subsys memory
[ 0.016145] Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0
[ 0.016145] Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0
[ 0.016145] tlb_flushall_shift: 6
[ 0.018090] Freeing SMP alternatives: 12k freed
[ 0.020763] ACPI: Core revision 20130328
[ 0.024119] ACPI: All ACPI Tables successfully acquired
[ 0.028266] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
[ 0.029004] smpboot: CPU0: Intel QEMU Virtual CPU version 1.5.0 (fam: 06, model: 02, stepping: 03)
[ 0.033000] Performance Events: unsupported p6 CPU model 2 no PMU driver, software events only.
[ 0.041162] smpboot: Booting Node 0, Processors #1[ 0.003000] kvm-clock: cpu 1, msr 0:de5f9041, secondary cpu clock
[ 0.056048] KVM setup async PF for cpu 1
[ 0.056048] kvm-stealtime: cpu 1, msr de04ba40
#2[ 0.003000] kvm-clock: cpu 2, msr 0:de5f9081, secondary cpu clock
[ 0.072030] KVM setup async PF for cpu 2
[ 0.072030] kvm-stealtime: cpu 2, msr de08ba40
#3[ 0.003000] kvm-clock: cpu 3, msr 0:de5f90c1, secondary cpu clock
[ 0.088047] KVM setup async PF for cpu 3
[ 0.088047] kvm-stealtime: cpu 3, msr de0cba40
#4[ 0.003000] kvm-clock: cpu 4, msr 0:de5f9101, secondary cpu clock
[ 0.104030] KVM setup async PF for cpu 4
[ 0.104030] kvm-stealtime: cpu 4, msr de10ba40
#5 OK
[ 0.003000] kvm-clock: cpu 5, msr 0:de5f9141, secondary cpu clock
[ 0.120082] Brought up 6 CPUs
[ 0.120030] KVM setup async PF for cpu 5
[ 0.120030] kvm-stealtime: cpu 5, msr de14ba40
[ 0.121005] smpboot: Total of 6 processors activated (28999.99 BogoMIPS)
[ 0.124181] devtmpfs: initialized
[ 0.126107] NET: Registered protocol family 16
[ 0.128540] ACPI: bus type PCI registered
[ 0.129372] PCI: Using configuration type 1 for base access
[ 0.156948] bio: create slab <bio-0> at 0
[ 0.159415] ACPI: Added _OSI(Module Device)
[ 0.160009] ACPI: Added _OSI(Processor Device)
[ 0.161030] ACPI: Added _OSI(3.0 _SCP Extensions)
[ 0.162006] ACPI: Added _OSI(Processor Aggregator Device)
[ 0.169236] ACPI: Interpreter enabled
[ 0.170014] ACPI: (supports S0 S5)
[ 0.171004] ACPI: Using IOAPIC for interrupt routing
[ 0.172164] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
[ 0.174438] ACPI: No dock devices found.
[ 0.188566] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff])
[ 0.189304] acpi PNP0A03:00: fail to add MMCONFIG information, can't access extended PCI configuration space under this bridge.
[ 0.190032] PCI host bridge to bus 0000:00
[ 0.191009] pci_bus 0000:00: root bus resource [bus 00-ff]
[ 0.192031] pci_bus 0000:00: root bus resource [io 0x0000-0x0cf7]
[ 0.193008] pci_bus 0000:00: root bus resource [io 0x0d00-0xffff]
[ 0.194000] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff]
[ 0.195007] pci_bus 0000:00: root bus resource [mem 0xde600000-0xfebfffff]
[ 0.207340] pci 0000:00:01.3: quirk: [io 0xb000-0xb03f] claimed by PIIX4 ACPI
[ 0.209027] pci 0000:00:01.3: quirk: [io 0xb100-0xb10f] claimed by PIIX4 SMB
[ 0.296507] acpi PNP0A03:00: ACPI _OSC support notification failed, disabling PCIe ASPM
[ 0.297007] acpi PNP0A03:00: Unable to request _OSC control (_OSC support mask: 0x08)
[ 0.300113] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
[ 0.301652] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
[ 0.303647] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
[ 0.305355] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
[ 0.307112] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
[ 0.309000] ACPI: Enabled 16 GPEs in block 00 to 0F
[ 0.311261] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
[ 0.312007] vgaarb: loaded
[ 0.312674] vgaarb: bridge control possible 0000:00:02.0
[ 0.314693] SCSI subsystem initialized
[ 0.315007] ACPI: bus type ATA registered
[ 0.318041] ACPI: bus type USB registered
[ 0.319435] usbcore: registered new interface driver usbfs
[ 0.320939] usbcore: registered new interface driver hub
[ 0.322540] usbcore: registered new device driver usb
[ 0.324405] pps_core: LinuxPPS API ver. 1 registered
[ 0.325026] pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giometti <giometti@linux.it>
[ 0.328007] PTP clock support registered
[ 0.329260] PCI: Using ACPI for IRQ routing
[ 0.331416] NetLabel: Initializing
[ 0.332005] NetLabel: domain hash size = 128
[ 0.333004] NetLabel: protocols = UNLABELED CIPSOv4
[ 0.334045] NetLabel: unlabeled traffic allowed by default
[ 0.336105] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
[ 0.337042] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
[ 0.338353] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
[ 0.345873] Switching to clocksource kvm-clock
[ 0.347492] pnp: PnP ACPI init
[ 0.348158] ACPI: bus type PNP registered
[ 0.351742] pnp: PnP ACPI: found 8 devices
[ 0.352793] ACPI: bus type PNP unregistered
[ 0.380141] NET: Registered protocol family 2
[ 0.381873] TCP established hash table entries: 32768 (order: 7, 524288 bytes)
[ 0.383831] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
[ 0.385615] TCP: Hash tables configured (established 32768 bind 32768)
[ 0.387295] TCP: reno registered
[ 0.388121] UDP hash table entries: 2048 (order: 4, 65536 bytes)
[ 0.389614] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
[ 0.391441] NET: Registered protocol family 1
[ 0.392979] RPC: Registered named UNIX socket transport module.
[ 0.394441] RPC: Registered udp transport module.
[ 0.395597] RPC: Registered tcp transport module.
[ 0.396756] RPC: Registered tcp NFSv4.1 backchannel transport module.
[ 0.398347] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
[ 0.399818] pci 0000:00:01.0: PIIX3: Enabling Passive Release
[ 0.401259] pci 0000:00:01.0: Activating ISA DMA hang workarounds
[ 0.407238] microcode: CPU0 sig=0x623, pf=0x0, revision=0x1
[ 0.408665] microcode: CPU1 sig=0x623, pf=0x0, revision=0x1
[ 0.410062] microcode: CPU2 sig=0x623, pf=0x0, revision=0x1
[ 0.411470] microcode: CPU3 sig=0x623, pf=0x0, revision=0x1
[ 0.412869] microcode: CPU4 sig=0x623, pf=0x0, revision=0x1
[ 0.414246] microcode: CPU5 sig=0x623, pf=0x0, revision=0x1
[ 0.415860] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
[ 0.419824] HugeTLB registered 2 MB page size, pre-allocated 0 pages
[ 0.421977] VFS: Disk quotas dquot_6.5.2
[ 0.423060] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
[ 0.425753] NFS: Registering the id_resolver key type
[ 0.427047] Key type id_resolver registered
[ 0.428096] Key type id_legacy registered
[ 0.429362] msgmni has been set to 6996
[ 0.432676] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
[ 0.434480] io scheduler noop registered
[ 0.435476] io scheduler deadline registered
[ 0.436618] io scheduler cfq registered (default)
[ 0.439552] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input0
[ 0.441360] ACPI: Power Button [PWRF]
[ 0.448237] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
[ 0.451704] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
[ 0.455478] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 11
[ 0.460464] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 0.485663] 00:05: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
[ 0.510928] 00:06: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
[ 0.514696] Non-volatile memory driver v1.3
[ 0.515750] Linux agpgart interface v0.103
[ 0.517507] [drm] Initialized drm 1.1.0 20060810
[ 0.526194] brd: module loaded
[ 0.530961] loop: module loaded
[ 0.537833] vda: vda1 vda2 vda3 < vda5 vda6 vda7 >
[ 0.543565] Loading iSCSI transport class v2.0-870.
[ 0.551567] scsi0 : ata_piix
[ 0.552886] scsi1 : ata_piix
[ 0.553981] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14
[ 0.555670] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15
[ 0.558111] e100: Intel(R) PRO/100 Network Driver, 3.5.24-k2-NAPI
[ 0.559654] e100: Copyright(c) 1999-2006 Intel Corporation
[ 0.561154] igb: Intel(R) Gigabit Ethernet Network Driver - version 5.0.3-k
[ 0.562890] igb: Copyright (c) 2007-2013 Intel Corporation.
[ 0.564384] Fusion MPT base driver 3.04.20
[ 0.565428] Copyright (c) 1999-2008 LSI Corporation
[ 0.566646] Fusion MPT SPI Host driver 3.04.20
[ 0.567874] Fusion MPT FC Host driver 3.04.20
[ 0.569144] Fusion MPT SAS Host driver 3.04.20
[ 0.570700] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
[ 0.572355] ehci-pci: EHCI PCI platform driver
[ 0.573574] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
[ 0.575231] uhci_hcd: USB Universal Host Controller Interface driver
[ 0.577087] usbcore: registered new interface driver usblp
[ 0.578555] usbcore: registered new interface driver usb-storage
[ 0.580268] i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,12
[ 0.583631] serio: i8042 KBD port at 0x60,0x64 irq 1
[ 0.584880] serio: i8042 AUX port at 0x60,0x64 irq 12
[ 0.586712] mousedev: PS/2 mouse device common for all mice
[ 0.589263] rtc_cmos 00:00: RTC can wake from S4
[ 0.590688] input: AT Translated Set 2 keyboard as /devices/platform/i8042/serio0/input/input1
[ 0.593766] rtc_cmos 00:00: rtc core: registered rtc_cmos as rtc0
[ 0.595610] rtc_cmos 00:00: alarms up to one day, 114 bytes nvram, hpet irqs
[ 0.597587] i2c /dev entries driver
[ 0.598927] md: raid1 personality registered for level 1
[ 0.601214] device-mapper: ioctl: 4.24.0-ioctl (2013-01-15) initialised: dm-devel@redhat.com
[ 0.603339] cpuidle: using governor ladder
[ 0.604943] hidraw: raw HID events driver (C) Jiri Kosina
[ 0.611689] usbcore: registered new interface driver usbhid
[ 0.613089] usbhid: USB HID core driver
[ 0.614189] ipip: IPv4 over IPv4 tunneling driver
[ 0.615979] TCP: cubic registered
[ 0.616823] Initializing XFRM netlink socket
[ 0.618149] NET: Registered protocol family 10
[ 0.619569] NET: Registered protocol family 17
[ 0.620717] Key type dns_resolver registered
[ 0.622602] registered taskstats version 1
[ 0.624365] console [netcon0] enabled
[ 0.625288] netconsole: network logging started
[ 0.710051] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100
[ 0.711568] ata1.00: 6291456 sectors, multi 16: LBA48
[ 0.713627] ata1.00: configured for MWDMA2
[ 0.714709] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100
[ 0.716845] ata2.00: configured for MWDMA2
[ 0.725171] scsi 0:0:0:0: Direct-Access ATA QEMU HARDDISK 1.5. PQ: 0 ANSI: 5
[ 0.727845] sd 0:0:0:0: [sda] 6291456 512-byte logical blocks: (3.22 GB/3.00 GiB)
[ 0.728252] sd 0:0:0:0: Attached scsi generic sg0 type 0
[ 0.729304] scsi 1:0:0:0: CD-ROM QEMU QEMU DVD-ROM 1.5. PQ: 0 ANSI: 5
[ 0.733892] sd 0:0:0:0: [sda] Write Protect is off
[ 0.734463] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
[ 0.734465] cdrom: Uniform CD-ROM driver Revision: 3.20
[ 0.735788] sr 1:0:0:0: Attached scsi generic sg1 type 5
[ 0.739375] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
[ 0.742628] sda: sda1
[ 0.743998] sd 0:0:0:0: [sda] Attached SCSI disk
[ 1.213262] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/serio1/input/input2
[ 1.216097] md: Waiting for all devices to be available before autodetect
[ 1.217746] md: If you don't use raid, use raid=noautodetect
[ 1.219700] md: Autodetecting RAID arrays.
[ 1.220730] md: Scanned 0 and added 0 devices.
[ 1.221847] md: autorun ...
[ 1.222564] md: ... autorun DONE.
[ 1.225604] EXT3-fs (vda5): mounted filesystem with ordered data mode
[ 1.227236] VFS: Mounted root (ext3 filesystem) readonly on device 253:5.
[ 1.228938] kjournald starting. Commit interval 5 seconds
[ 1.229480] devtmpfs: mounted
[ 1.231311] Freeing unused kernel memory: 884k freed
INIT: version 2.88 booting
cat: /proc/cmdline: No such file or directory
cat: /proc/cmdline: No such file or directory
Mounting proc file system... [ OK ]
Mounting sys file system... [ OK ]
Starting udev [ 1.386819] udevd (790): /proc/790/oom_adj is deprecated, please use /proc/790/oom_score_adj instead.
[ 1.389336] udevd version 124 started
[ 1.405129] tsc: Refined TSC clocksource calibration: 2416.664 MHz
[ 1.479262] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M
[ 1.492665] FDC 0 is a S82078B
[ 1.497952] sfpacket: module license 'Proprietary' taints kernel.
[ 1.499891] Disabling lock debugging due to kernel taint
[ 1.503550] Sourcefire Bridging Packet Driver - version 6.0.0
[ 1.505138] Copyright (c) 2004-2010 Sourcefire, Inc.
[ 1.510449] SFPacket Inter-VM Shared Memory Driver - version 6.0.0
[ 1.512892] Copyright (c) 2014 Cisco Systems, Inc.
[ 1.520587] KVM_IVSHMEM: Major device number is: 247
[ 1.522333] KVM_IVSHMEM: Probing for KVM_IVSHMEM Device
[ 1.524689] KVM_IVSHMEM: result is 0
[ 1.526103] KVM_IVSHMEM: iomap base = 0x18446683600578412544
[ 1.528182] KVM_IVSHMEM: ioaddr = fc000000 ioaddr_size = 16777216
[ 1.529918] SFIVMSHM info: Registered device 'kvm_ivshmem'.
[ 1.531366] KVM_IVSHMEM: Registered with the SFIVMShm driver.
[ 1.532874] KVM_IVSHMEM: irq = 11 regaddr = febf1000 reg_size = 256
Activating all swap files/partitions...
[ 1.709596] Adding 1000444k swap on /dev/vda2. Priority:-1 extents[ OK ]s:1000444k
Mounting root file system in read-only mode... [ OK ]
Checking file systems...
e2fsck 1.42.9 (28-Dec-2013)
3D-6.2.2: clean, 20181/244320 files, 217838/976384 blocks
e2fsck 1.42.9 (28-Dec-2013)
e2fsck 1.42.9 (28-Dec-2013)
BOOT: clean, 51/24096 files, 24171/96256 blocks
/Volume: clean, 1736227/5554176 files, 4793836/22186412 blocks [ OK ]
Remounting root file system in read-write mode...
[ 1.841418] EXT3-fs (vda5): using internal journal [ OK ]
Mounting remaining file systems...
[ 1.849609] kjournald starting. Commit interval 5 seconds
[ 1.850205] EXT3-fs (sda1): using internal journal
[ 1.850207] EXT3-fs (sda1): mounted filesystem with ordered data mode
[ 1.857238] kjournald starting. Commit interval 5 seconds
[ 1.857493] EXT3-fs (vda7): using internal journal
[ 1.857496] EXT3-fs (vda7): mounted filesystem with ordered data mo[ OK ]
Removing /var/run/* and /var/lock/subsys/* [ OK ]
Removing /var/sf/run/*
Removing /tmp/cgi* files
Removing temporary files
Creating new /var/run/utmp... [ OK ]
Removing possible /etc/nologin /fastboot and /forcefsck... [ OK ]
Removing dhcp lock files... [ OK ]
/etc/rc.d/rcsysinit.d/S51udev_retry: line 35: log_info_msg: command no[ OK ]
Setting clock... [ OK ]
Initializing kernel random number generator... [ OK ]
Saving dmesg boot log [ OK ]
Loading fuse module failed!
Bringing up the loopback interface...
Upping interface lo [ OK ]
Configuring address the lo interface... [ OK ]
Configuring hostname to firepower [ OK ]
Configuring IPv6 address the lo interface... [ OK ]
Disable IPv6 default route [ OK ]
Configuring hostname to firepower [ OK ]
Configuring Static Routes
Starting ntp server [ OK ]
Writing hosts file [ OK ]
verify_fsic(start)
Running file integrity checks...
FIPS mode is disabled. Skip verifying file integrity
Setting kernel paramaters [ OK ]
INIT: Entering runlevel: 3
Starting system log daemon... [ OK ]
Starting cron daemon... [ OK ]
Adding swapfile /Volume/.swaptwo
[ 5.040294] Adding 2324440k swap on /Volume/.swaptwo. Priority:-2 extents:638 across:3172160k
Flushing all current IPv4 rules and user defined chains: [ 5.861733] ip_tables: (C) 2000-2006 Netfilter Core Team
...success
Clearing all current IPv4 rules and user defined chains: ...success
Applying iptables firewall rules:
Flushing chain `PREROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Flushing chain `POSTROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
[ 5.898944] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
Applying rules successed
Flushing all current IPv6 rules and user defined chains: [ 5.965981] ip6_tables: (C) 2000-2006 Netfilter Core Team
...success
Clearing all current IPv6 rules and user defined chains: ...success
Applying ip6tables firewall rules:
Flushing chain `PREROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Flushing chain `POSTROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Applying rules successed
Upping interface eth0 [ OK ]
Setting MTU... [ OK ]
Configuring DNS server: [8.8.8.8] [example.net]
List DNS server: [8.8.8.8] [example.net] [ OK ]
Writing out ntp server [ OK ]
Configuring address the eth0 interface... [ OK ]
Configuring IPv4 default route 10.10.112.1 for IP 10.10.112.99/255.255[ OK ]n eth0
Configuring hostname to firepower [ OK ]
Unconfiguring IPv6 [ OK ]
Configuring Static Routes
Starting ntp server [ OK ]
Writing hosts file [ OK ]
Interface disabled, downing [ OK ]
Starting portmap... [ OK ]
Starting nscd...
mkdir: created directory '/var/run/nscd' [ OK ]
Setting video params
setterm: cannot (un)set powersave mode: Inappropriate ioctl for device
Loading fuse module failed!
Generating public/private rsa1 key pair.
Saving key "/etc/ssh/ssh_host_key" failed: unknown or unsupported key [ OK ]
Starting , please wait......complete. [ OK ]
Starting xinetd:
Not reconfigurating
Thu Mar 12 08:30:34 UTC 2020
Starting MySQL...
Pinging mysql
Pinging mysql, try 1
Pinging mysql, try 2
Found mysql is running
Running initializeObjects...
Stopping MySQL...
Killing mysqld with pid 3249
Wait for mysqld to exit\c
done
Thu Mar 12 08:30:55 UTC 2020
Warning: speed or duplex not found in config file for eth0, using defaults...
modprobe: FATAL: Module ipmi_si not found in directory /lib/modules/3.10.53sf.cisco-150
Starting Cisco ASA5516, please wait...No PM running!
...started.
Mar 12 08:30:59 firepower SF-IMS[3626]: [3626] init script:system [INFO] pmmon Setting affinity to 4,5...
pid 3620's current affinity list: 0-5
pid 3620's new affinity list: 4,5
Mar 12 08:30:59 firepower SF-IMS[3628]: [3628] init script:system [INFO] pmmon The Process Manager is not running...
Mar 12 08:30:59 firepower SF-IMS[3629]: [3629] init script:system [INFO] pmmon Starting the Process Manager...
Mar 12 08:30:59 firepower SF-IMS[3630]: [3630] pm:pm [INFO] Using model number 72M
firepower login: [ 33.791481] SFHS[3631] - kvm_ivshmem: Set max latency to 0 msecs (0 jiffies)
[ 34.168425] tun: Universal TUN/TAP device driver, 1.6
[ 34.169763] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
[ 34.212516] SFIVMSHM info: Initializing Channel 0 Client Descriptor Base...
[ 34.214818] SFIVMSHM info: Initializing Channel 1 Client Descriptor Base...
[ 34.217241] SFIVMSHM info: Initializing packet buffer pool...
[ 34.219380] SFIVMSHM info: Initializing packet buffer pool done!
[ 34.607223] IPv6: ADDRCONF(NETDEV_UP): tun1: link is not ready
[ 34.862786] SFIVMSHM info: Shared Memory start addr = ffffc90000800000 size = 16777216
[ 34.864810] SFIVMSHM info: magicNum = 0x2a1337 version = 3 asa_state = INIT_COMPLETE ips_state = INIT_COMPLETE lineStatus = 1 mode = 0 totalSize = 16777216
[ 34.868236] SFIVMSHM info: Channel Info ch_count = 2
[ 34.869489] SFIVMSHM info: Channel Info #0: [TS pool_offset = 0 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.872160] SFIVMSHM info: Channel Info #0: [FS pool_offset = 36288 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.875295] SFIVMSHM info: Channel Info #1: [TS pool_offset = 72576 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.878362] SFIVMSHM info: Channel Info #1: [FS pool_offset = 108864 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.881080] SFIVMSHM info: Packet Buffer pools [server start=147456 count=6902 size=14135296] [client start=14282752 count=1218 size=2494464] [pktbuf_size = 2048]
[ 34.885494] SFIVMSHM info: Allocated 165648 bytes for the array of 6902 IvmShm Buffers.
[ 34.888890] SFIVMSHM info: [3670]: Ring kvm_ivshmem - RX/TX thread created and started (ffff8800d8ac11c0)
[ 34.891918] SFIVMSHM info: [3670]: Ring kvm_ivshmem - Done with index -1 and rval 0
[ 35.395621] IPv6: ADDRCONF(NETDEV_CHANGE): tun1: link becomes ready
[ 42.235307] SFIVMSHM info: [3671]: Ring kvm_ivshmem - Done with index 0 and rval 0
[ 42.237291] Remapping addr = 0x7f77cebec000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 42.302169] SFIVMSHM info: [3673]: Ring kvm_ivshmem - Done with index 1 and rval 0
[ 42.304303] Remapping addr = 0x7fbfe61ad000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 42.315901] SFIVMSHM info: [3672]: Ring kvm_ivshmem - Done with index 2 and rval 0
[ 42.318151] Remapping addr = 0x7f702b000000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 64.201116] SFPacket_AFBP: Copied first heartbeat for future use (78 bytes)
[ 9219.441421] hpet1: lost 2 rtc interrupts
03-15-2020 05:12 PM
03-15-2020 05:42 PM
03-16-2020 07:54 AM
Hi,
Ensure you use a version of ASDM that supports FPWR (not sure in which version it came), likewise ensure that ASA can reach the management IP address of FPWR. Look here for reference:
Regards,
Cristian Matei.
03-16-2020 09:12 PM
As a result of verification through the document, it seems that ASA and Firepower can communicate(can ping), but my PC(ASDM) and Firepower cannot communicate. However, I found a log file in firepower console(/var/log/sf/updates.sh). It seemed that the update was aborted by shutting down the module during the version update. Eventually, I reinstalled firepower new version and I solved problem.
Card Type: FirePOWER Services Software Module
Model: ASA5516
Hardware version: N/A
Serial Number: JAD24020KMG
Firmware version: N/A
Software version: 6.4.0.7-53
MAC Address Range: 4ce1.7659.660a to 4ce1.7659.660a
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 6.4.0.7-53
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr: No DC Configured
Mgmt IP addr: 10.10.112.99
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 10.10.112.1
Mgmt web ports: 443
Mgmt TLS enabled: true
Thank you for your assistance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide