cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2341
Views
5
Helpful
7
Replies

ASA 5516-x ASDM don't connect firepower.

GaeMi
Level 1
Level 1

Hello.

My ASA 5516-x don't connect firepower.

I launched asdm, asdm is stucked "software completed" about 1-2 mins.

after 1-2mins, asdm boot up, but I can't see firepower panels.

and I clicked "ASA firepower Status", ASDM is stucked constantly, so i needed to kill asdm process.

CLI command "show module sfr details" makes same thing.

 

 

I have been installed other ASA 5516-x 2 times, but those ASA 5516-x are connecting to firepower very well.

ASA OS Version, ASDM Version, Firepower are even perfectly same..!! 

Still, the ASA 5516-x that I installed earlier is going well...

 

I tried commands "sw-module module sfr shutdown" "sw-module module sfr reset" "sw-module module sfr reload", but I can't resolve this problem.

 

How can I resolve this problem?

asdm 로그인.PNG

ASDM is stucked 1-2mins "Software update completed" turn.

 

asdm 로그인 후.PNG

After log on ASDM, when loading percent is "80%", stucked 1-2mins.

I can use ASA functions, but when I click Firepower  functions, ASDM is stucked forever.

 

1 Accepted Solution

Accepted Solutions

Hi,

 

   Ensure you use a version of ASDM that supports FPWR (not sure in which version it came), likewise ensure that ASA can reach the management IP address of FPWR. Look here for reference:

 

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/200889-Using-ASDM-to-manage-a-FirePOWER-module.html

 

Regards,

Cristian Matei.

View solution in original post

7 Replies 7

GaeMi
Level 1
Level 1
ASA OS ver : 9.8(2)
ASDM ver : 7.9(2)152
Firepower ver : 6.2.2-81

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   You never get an output at the command "show module sfr details"? How about command "show module sfr log console" or just "show module"?

 

Regards,

Cristian Matei.

Yes, I never get an output "show module sfr details"

But I can get an output "show module sfr log console" and "show module"

And, I found that Firepower is not detected in the "show version" output.

 

<show version>

Cisco Adaptive Security Appliance Software Version 9.8(2)
Firepower Extensible Operating System Version 2.2(2.52)
Device Manager Version 7.9(2)152

Compiled on Sun 27-Aug-17 13:06 PDT by builders
System image file is "disk0:/asa982-lfbff-k8.SPA"
Config file at boot was "startup-config"

Yesco-Firewall up 8 days 18 hours

Hardware: ASA5516, 8192 MB RAM, CPU Atom C2000 series 2416 MHz, 1 CPU (8 cores)
Internal ATA Compact Flash, 8000MB
BIOS Flash M25P64 @ 0xfed01000, 16384KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Number of accelerators: 1

1: Ext: GigabitEthernet1/1 : address is 4ce1.7659.660c, irq 255
2: Ext: GigabitEthernet1/2 : address is 4ce1.7659.660d, irq 255
3: Ext: GigabitEthernet1/3 : address is 4ce1.7659.660e, irq 255
4: Ext: GigabitEthernet1/4 : address is 4ce1.7659.660f, irq 255
5: Ext: GigabitEthernet1/5 : address is 4ce1.7659.6610, irq 255
6: Ext: GigabitEthernet1/6 : address is 4ce1.7659.6611, irq 255
7: Ext: GigabitEthernet1/7 : address is 4ce1.7659.6612, irq 255
8: Ext: GigabitEthernet1/8 : address is 4ce1.7659.6613, irq 255
9: Int: Internal-Data1/1 : address is 4ce1.7659.660b, irq 255
10: Int: Internal-Data1/2 : address is 0000.0001.0002, irq 0
11: Int: Internal-Control1/1 : address is 0000.0001.0001, irq 0
12: Int: Internal-Data1/3 : address is 0000.0001.0003, irq 0
13: Ext: Management1/1 : address is 4ce1.7659.660b, irq 0
14: Int: Internal-Data1/4 : address is 0000.0100.0001, irq 0

Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 150 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 4 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 300 perpetual
Total VPN Peers : 300 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total TLS Proxy Sessions : 1000 perpetual
Botnet Traffic Filter : Disabled perpetual
Cluster : Enabled perpetual
Cluster Members : 2 perpetual
VPN Load Balancing : Enabled perpetual

Serial Number: JAD24020KMG
Running Permanent Activation Key: 0xeb24eb75 0x04bcdaed 0xb801e9ac 0x854cc00c 0x0b180a9e
Configuration register is 0x1
Image type : Release
Key Version : A

 

<show module>

Mod Card Type Model Serial No.
---- -------------------------------------------- ------------------ -----------
1 ASA 5516-X with FirePOWER services, 8GE, AC, ASA5516 JAD24020KMG
sfr FirePOWER Services Software Module ASA5516 JAD24020KMG

Mod MAC Address Range Hw Version Fw Version Sw Version
---- --------------------------------- ------------ ------------ ---------------
1 4ce1.7659.660b to 4ce1.7659.6613 3.3 1.1.15 9.8(2)
sfr 4ce1.7659.660a to 4ce1.7659.660a N/A N/A 6.2.2-81

Mod SSM Application Name Status SSM Application Version
---- ------------------------------ ---------------- --------------------------
sfr ASA FirePOWER Up 6.2.2-81

Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
1 Up Sys Not Applicable
sfr Up Up

 

And I can get an output "show module sfr log console".

 

<show module sfr log console>

LILO 24.2 boot:
Loading 6.2.2.........................................................................
BIOS data check successful
[ 0.000000] Initializing cgroup subsys cpuset
[ 0.000000] Initializing cgroup subsys cpu
[ 0.000000] Initializing cgroup subsys cpuacct
[ 0.000000] Linux version 3.10.53sf.cisco-150 (build@ful-sfosbuild01) (gcc version 4.7.1 (GCC) ) #1 SMP PREEMPT Thu Aug 31 19:02:52 UTC 2017
[ 0.000000] Command line: auto BOOT_IMAGE=6.2.2 ro root=fd05 console=ttyS0,9600
[ 0.000000] e820: BIOS-provided physical RAM map:
[ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
[ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
[ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000de5fdfff] usable
[ 0.000000] BIOS-e820: [mem 0x00000000de5fe000-0x00000000de5fffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved
[ 0.000000] NX (Execute Disable) protection: active
[ 0.000000] SMBIOS 2.4 present.
[ 0.000000] Hypervisor detected: KVM
[ 0.000000] No AGP bridge found
[ 0.000000] e820: last_pfn = 0xde5fe max_arch_pfn = 0x400000000
[ 0.000000] PAT not supported by CPU.
[ 0.000000] found SMP MP-table at [mem 0x000fda80-0x000fda8f] mapped at [ffff8800000fda80]
[ 0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
[ 0.000000] init_memory_mapping: [mem 0xde200000-0xde3fffff]
[ 0.000000] init_memory_mapping: [mem 0xdc000000-0xde1fffff]
[ 0.000000] init_memory_mapping: [mem 0x80000000-0xdbffffff]
[ 0.000000] init_memory_mapping: [mem 0x00100000-0x7fffffff]
[ 0.000000] init_memory_mapping: [mem 0xde400000-0xde5fdfff]
[ 0.000000] ACPI: RSDP 00000000000fd840 00014 (v00 BOCHS )
[ 0.000000] ACPI: RSDT 00000000de5fe2b0 00034 (v01 BOCHS BXPCRSDT 00000001 BXPC 00000001)
[ 0.000000] ACPI: FACP 00000000de5fff80 00074 (v01 BOCHS BXPCFACP 00000001 BXPC 00000001)
[ 0.000000] ACPI: DSDT 00000000de5fe2f0 011A9 (v01 BXPC BXDSDT 00000001 INTL 20100528)
[ 0.000000] ACPI: FACS 00000000de5fff40 00040
[ 0.000000] ACPI: SSDT 00000000de5ff620 0091A (v01 BOCHS BXPCSSDT 00000001 BXPC 00000001)
[ 0.000000] ACPI: APIC 00000000de5ff4e0 000A0 (v01 BOCHS BXPCAPIC 00000001 BXPC 00000001)
[ 0.000000] ACPI: HPET 00000000de5ff4a0 00038 (v01 BOCHS BXPCHPET 00000001 BXPC 00000001)
[ 0.000000] No NUMA configuration found
[ 0.000000] Faking a node at [mem 0x0000000000000000-0x00000000de5fdfff]
[ 0.000000] Initmem setup node 0 [mem 0x00000000-0xde5fdfff]
[ 0.000000] NODE_DATA [mem 0xde5fa000-0xde5fdfff]
[ 0.000000] kvm-clock: Using msrs 4b564d01 and 4b564d00
[ 0.000000] kvm-clock: cpu 0, msr 0:de5f9001, boot clock
[ 0.000000] Zone ranges:
[ 0.000000] DMA [mem 0x00001000-0x00ffffff]
[ 0.000000] DMA32 [mem 0x01000000-0xffffffff]
[ 0.000000] Normal empty
[ 0.000000] Movable zone start for each node
[ 0.000000] Early memory node ranges
[ 0.000000] node 0: [mem 0x00001000-0x0009efff]
[ 0.000000] node 0: [mem 0x00100000-0xde5fdfff]
[ 0.000000] ACPI: PM-Timer IO Port: 0xb008
[ 0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x03] lapic_id[0x03] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x04] lapic_id[0x04] enabled)
[ 0.000000] ACPI: LAPIC (acpi_id[0x05] lapic_id[0x05] enabled)
[ 0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
[ 0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
[ 0.000000] IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
[ 0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
[ 0.000000] Using ACPI (MADT) for SMP configuration information
[ 0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000
[ 0.000000] smpboot: Allowing 6 CPUs, 0 hotplug CPUs
[ 0.000000] e820: [mem 0xde600000-0xfeffbfff] available for PCI devices
[ 0.000000] Booting paravirtualized kernel on KVM
[ 0.000000] setup_percpu: NR_CPUS:64 nr_cpumask_bits:64 nr_cpu_ids:6 nr_node_ids:1
[ 0.000000] PERCPU: Embedded 24 pages/cpu @ffff8800de000000 s69568 r8192 d20544 u262144
[ 0.000000] kvm-clock: cpu 0, msr 0:de5f9001, primary cpu clock
[ 0.000000] KVM setup async PF for cpu 0
[ 0.000000] kvm-stealtime: cpu 0, msr de00ba40
[ 0.000000] Built 1 zonelists in Node order, mobility grouping on. Total pages: 898274
[ 0.000000] Policy zone: DMA32
[ 0.000000] Kernel command line: auto BOOT_IMAGE=6.2.2 ro root=fd05 console=ttyS0,9600
[ 0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
[ 0.000000] Checking aperture...
[ 0.000000] No AGP bridge found
[ 0.000000] Memory: 3582304k/3643384k available (4768k kernel code, 392k absent, 60688k reserved, 2399k data, 884k init)
[ 0.000000] Preemptible hierarchical RCU implementation.
[ 0.000000] RCU restricting CPUs from NR_CPUS=64 to nr_cpu_ids=6.
[ 0.000000] NR_IRQS:4352 nr_irqs:728 16
[ 0.000000] Console: colour VGA+ 80x25
[ 0.000000] console [ttyS0] enabled
[ 0.000000] allocated 14680064 bytes of page_cgroup
[ 0.000000] please try 'cgroup_disable=memory' option if you don't want memory cgroups
[ 0.000000] tsc: Detected 2416.666 MHz processor
[ 0.003000] Calibrating delay loop (skipped) preset value.. 4833.33 BogoMIPS (lpj=2416666)
[ 0.004009] pid_max: default: 32768 minimum: 301
[ 0.005076] Security Framework initialized
[ 0.008034] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
[ 0.012027] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
[ 0.014201] Mount-cache hash table entries: 256
[ 0.015285] Initializing cgroup subsys memory
[ 0.016145] Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0
[ 0.016145] Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0
[ 0.016145] tlb_flushall_shift: 6
[ 0.018090] Freeing SMP alternatives: 12k freed
[ 0.020763] ACPI: Core revision 20130328
[ 0.024119] ACPI: All ACPI Tables successfully acquired
[ 0.028266] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
[ 0.029004] smpboot: CPU0: Intel QEMU Virtual CPU version 1.5.0 (fam: 06, model: 02, stepping: 03)
[ 0.033000] Performance Events: unsupported p6 CPU model 2 no PMU driver, software events only.
[ 0.041162] smpboot: Booting Node 0, Processors #1[ 0.003000] kvm-clock: cpu 1, msr 0:de5f9041, secondary cpu clock
[ 0.056048] KVM setup async PF for cpu 1
[ 0.056048] kvm-stealtime: cpu 1, msr de04ba40
#2[ 0.003000] kvm-clock: cpu 2, msr 0:de5f9081, secondary cpu clock
[ 0.072030] KVM setup async PF for cpu 2
[ 0.072030] kvm-stealtime: cpu 2, msr de08ba40
#3[ 0.003000] kvm-clock: cpu 3, msr 0:de5f90c1, secondary cpu clock
[ 0.088047] KVM setup async PF for cpu 3
[ 0.088047] kvm-stealtime: cpu 3, msr de0cba40
#4[ 0.003000] kvm-clock: cpu 4, msr 0:de5f9101, secondary cpu clock
[ 0.104030] KVM setup async PF for cpu 4
[ 0.104030] kvm-stealtime: cpu 4, msr de10ba40
#5 OK
[ 0.003000] kvm-clock: cpu 5, msr 0:de5f9141, secondary cpu clock
[ 0.120082] Brought up 6 CPUs
[ 0.120030] KVM setup async PF for cpu 5
[ 0.120030] kvm-stealtime: cpu 5, msr de14ba40
[ 0.121005] smpboot: Total of 6 processors activated (28999.99 BogoMIPS)
[ 0.124181] devtmpfs: initialized
[ 0.126107] NET: Registered protocol family 16
[ 0.128540] ACPI: bus type PCI registered
[ 0.129372] PCI: Using configuration type 1 for base access
[ 0.156948] bio: create slab <bio-0> at 0
[ 0.159415] ACPI: Added _OSI(Module Device)
[ 0.160009] ACPI: Added _OSI(Processor Device)
[ 0.161030] ACPI: Added _OSI(3.0 _SCP Extensions)
[ 0.162006] ACPI: Added _OSI(Processor Aggregator Device)
[ 0.169236] ACPI: Interpreter enabled
[ 0.170014] ACPI: (supports S0 S5)
[ 0.171004] ACPI: Using IOAPIC for interrupt routing
[ 0.172164] PCI: Using host bridge windows from ACPI; if necessary, use "pci=nocrs" and report a bug
[ 0.174438] ACPI: No dock devices found.
[ 0.188566] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff])
[ 0.189304] acpi PNP0A03:00: fail to add MMCONFIG information, can't access extended PCI configuration space under this bridge.
[ 0.190032] PCI host bridge to bus 0000:00
[ 0.191009] pci_bus 0000:00: root bus resource [bus 00-ff]
[ 0.192031] pci_bus 0000:00: root bus resource [io 0x0000-0x0cf7]
[ 0.193008] pci_bus 0000:00: root bus resource [io 0x0d00-0xffff]
[ 0.194000] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff]
[ 0.195007] pci_bus 0000:00: root bus resource [mem 0xde600000-0xfebfffff]
[ 0.207340] pci 0000:00:01.3: quirk: [io 0xb000-0xb03f] claimed by PIIX4 ACPI
[ 0.209027] pci 0000:00:01.3: quirk: [io 0xb100-0xb10f] claimed by PIIX4 SMB
[ 0.296507] acpi PNP0A03:00: ACPI _OSC support notification failed, disabling PCIe ASPM
[ 0.297007] acpi PNP0A03:00: Unable to request _OSC control (_OSC support mask: 0x08)
[ 0.300113] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
[ 0.301652] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
[ 0.303647] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
[ 0.305355] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
[ 0.307112] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
[ 0.309000] ACPI: Enabled 16 GPEs in block 00 to 0F
[ 0.311261] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,locks=none
[ 0.312007] vgaarb: loaded
[ 0.312674] vgaarb: bridge control possible 0000:00:02.0
[ 0.314693] SCSI subsystem initialized
[ 0.315007] ACPI: bus type ATA registered
[ 0.318041] ACPI: bus type USB registered
[ 0.319435] usbcore: registered new interface driver usbfs
[ 0.320939] usbcore: registered new interface driver hub
[ 0.322540] usbcore: registered new device driver usb
[ 0.324405] pps_core: LinuxPPS API ver. 1 registered
[ 0.325026] pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giometti <giometti@linux.it>
[ 0.328007] PTP clock support registered
[ 0.329260] PCI: Using ACPI for IRQ routing
[ 0.331416] NetLabel: Initializing
[ 0.332005] NetLabel: domain hash size = 128
[ 0.333004] NetLabel: protocols = UNLABELED CIPSOv4
[ 0.334045] NetLabel: unlabeled traffic allowed by default
[ 0.336105] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
[ 0.337042] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
[ 0.338353] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
[ 0.345873] Switching to clocksource kvm-clock
[ 0.347492] pnp: PnP ACPI init
[ 0.348158] ACPI: bus type PNP registered
[ 0.351742] pnp: PnP ACPI: found 8 devices
[ 0.352793] ACPI: bus type PNP unregistered
[ 0.380141] NET: Registered protocol family 2
[ 0.381873] TCP established hash table entries: 32768 (order: 7, 524288 bytes)
[ 0.383831] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
[ 0.385615] TCP: Hash tables configured (established 32768 bind 32768)
[ 0.387295] TCP: reno registered
[ 0.388121] UDP hash table entries: 2048 (order: 4, 65536 bytes)
[ 0.389614] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
[ 0.391441] NET: Registered protocol family 1
[ 0.392979] RPC: Registered named UNIX socket transport module.
[ 0.394441] RPC: Registered udp transport module.
[ 0.395597] RPC: Registered tcp transport module.
[ 0.396756] RPC: Registered tcp NFSv4.1 backchannel transport module.
[ 0.398347] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
[ 0.399818] pci 0000:00:01.0: PIIX3: Enabling Passive Release
[ 0.401259] pci 0000:00:01.0: Activating ISA DMA hang workarounds
[ 0.407238] microcode: CPU0 sig=0x623, pf=0x0, revision=0x1
[ 0.408665] microcode: CPU1 sig=0x623, pf=0x0, revision=0x1
[ 0.410062] microcode: CPU2 sig=0x623, pf=0x0, revision=0x1
[ 0.411470] microcode: CPU3 sig=0x623, pf=0x0, revision=0x1
[ 0.412869] microcode: CPU4 sig=0x623, pf=0x0, revision=0x1
[ 0.414246] microcode: CPU5 sig=0x623, pf=0x0, revision=0x1
[ 0.415860] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
[ 0.419824] HugeTLB registered 2 MB page size, pre-allocated 0 pages
[ 0.421977] VFS: Disk quotas dquot_6.5.2
[ 0.423060] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
[ 0.425753] NFS: Registering the id_resolver key type
[ 0.427047] Key type id_resolver registered
[ 0.428096] Key type id_legacy registered
[ 0.429362] msgmni has been set to 6996
[ 0.432676] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251)
[ 0.434480] io scheduler noop registered
[ 0.435476] io scheduler deadline registered
[ 0.436618] io scheduler cfq registered (default)
[ 0.439552] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input0
[ 0.441360] ACPI: Power Button [PWRF]
[ 0.448237] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
[ 0.451704] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
[ 0.455478] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 11
[ 0.460464] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
[ 0.485663] 00:05: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
[ 0.510928] 00:06: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
[ 0.514696] Non-volatile memory driver v1.3
[ 0.515750] Linux agpgart interface v0.103
[ 0.517507] [drm] Initialized drm 1.1.0 20060810
[ 0.526194] brd: module loaded
[ 0.530961] loop: module loaded
[ 0.537833] vda: vda1 vda2 vda3 < vda5 vda6 vda7 >
[ 0.543565] Loading iSCSI transport class v2.0-870.
[ 0.551567] scsi0 : ata_piix
[ 0.552886] scsi1 : ata_piix
[ 0.553981] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14
[ 0.555670] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15
[ 0.558111] e100: Intel(R) PRO/100 Network Driver, 3.5.24-k2-NAPI
[ 0.559654] e100: Copyright(c) 1999-2006 Intel Corporation
[ 0.561154] igb: Intel(R) Gigabit Ethernet Network Driver - version 5.0.3-k
[ 0.562890] igb: Copyright (c) 2007-2013 Intel Corporation.
[ 0.564384] Fusion MPT base driver 3.04.20
[ 0.565428] Copyright (c) 1999-2008 LSI Corporation
[ 0.566646] Fusion MPT SPI Host driver 3.04.20
[ 0.567874] Fusion MPT FC Host driver 3.04.20
[ 0.569144] Fusion MPT SAS Host driver 3.04.20
[ 0.570700] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
[ 0.572355] ehci-pci: EHCI PCI platform driver
[ 0.573574] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
[ 0.575231] uhci_hcd: USB Universal Host Controller Interface driver
[ 0.577087] usbcore: registered new interface driver usblp
[ 0.578555] usbcore: registered new interface driver usb-storage
[ 0.580268] i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,12
[ 0.583631] serio: i8042 KBD port at 0x60,0x64 irq 1
[ 0.584880] serio: i8042 AUX port at 0x60,0x64 irq 12
[ 0.586712] mousedev: PS/2 mouse device common for all mice
[ 0.589263] rtc_cmos 00:00: RTC can wake from S4
[ 0.590688] input: AT Translated Set 2 keyboard as /devices/platform/i8042/serio0/input/input1
[ 0.593766] rtc_cmos 00:00: rtc core: registered rtc_cmos as rtc0
[ 0.595610] rtc_cmos 00:00: alarms up to one day, 114 bytes nvram, hpet irqs
[ 0.597587] i2c /dev entries driver
[ 0.598927] md: raid1 personality registered for level 1
[ 0.601214] device-mapper: ioctl: 4.24.0-ioctl (2013-01-15) initialised: dm-devel@redhat.com
[ 0.603339] cpuidle: using governor ladder
[ 0.604943] hidraw: raw HID events driver (C) Jiri Kosina
[ 0.611689] usbcore: registered new interface driver usbhid
[ 0.613089] usbhid: USB HID core driver
[ 0.614189] ipip: IPv4 over IPv4 tunneling driver
[ 0.615979] TCP: cubic registered
[ 0.616823] Initializing XFRM netlink socket
[ 0.618149] NET: Registered protocol family 10
[ 0.619569] NET: Registered protocol family 17
[ 0.620717] Key type dns_resolver registered
[ 0.622602] registered taskstats version 1
[ 0.624365] console [netcon0] enabled
[ 0.625288] netconsole: network logging started
[ 0.710051] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100
[ 0.711568] ata1.00: 6291456 sectors, multi 16: LBA48
[ 0.713627] ata1.00: configured for MWDMA2
[ 0.714709] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100
[ 0.716845] ata2.00: configured for MWDMA2
[ 0.725171] scsi 0:0:0:0: Direct-Access ATA QEMU HARDDISK 1.5. PQ: 0 ANSI: 5
[ 0.727845] sd 0:0:0:0: [sda] 6291456 512-byte logical blocks: (3.22 GB/3.00 GiB)
[ 0.728252] sd 0:0:0:0: Attached scsi generic sg0 type 0
[ 0.729304] scsi 1:0:0:0: CD-ROM QEMU QEMU DVD-ROM 1.5. PQ: 0 ANSI: 5
[ 0.733892] sd 0:0:0:0: [sda] Write Protect is off
[ 0.734463] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
[ 0.734465] cdrom: Uniform CD-ROM driver Revision: 3.20
[ 0.735788] sr 1:0:0:0: Attached scsi generic sg1 type 5
[ 0.739375] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn't support DPO or FUA
[ 0.742628] sda: sda1
[ 0.743998] sd 0:0:0:0: [sda] Attached SCSI disk
[ 1.213262] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/serio1/input/input2
[ 1.216097] md: Waiting for all devices to be available before autodetect
[ 1.217746] md: If you don't use raid, use raid=noautodetect
[ 1.219700] md: Autodetecting RAID arrays.
[ 1.220730] md: Scanned 0 and added 0 devices.
[ 1.221847] md: autorun ...
[ 1.222564] md: ... autorun DONE.
[ 1.225604] EXT3-fs (vda5): mounted filesystem with ordered data mode
[ 1.227236] VFS: Mounted root (ext3 filesystem) readonly on device 253:5.
[ 1.228938] kjournald starting. Commit interval 5 seconds
[ 1.229480] devtmpfs: mounted
[ 1.231311] Freeing unused kernel memory: 884k freed
INIT: version 2.88 booting
cat: /proc/cmdline: No such file or directory
cat: /proc/cmdline: No such file or directory
Mounting proc file system... [ OK ]
Mounting sys file system... [ OK ]
Starting udev [ 1.386819] udevd (790): /proc/790/oom_adj is deprecated, please use /proc/790/oom_score_adj instead.
[ 1.389336] udevd version 124 started
[ 1.405129] tsc: Refined TSC clocksource calibration: 2416.664 MHz
[ 1.479262] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M
[ 1.492665] FDC 0 is a S82078B
[ 1.497952] sfpacket: module license 'Proprietary' taints kernel.
[ 1.499891] Disabling lock debugging due to kernel taint
[ 1.503550] Sourcefire Bridging Packet Driver - version 6.0.0
[ 1.505138] Copyright (c) 2004-2010 Sourcefire, Inc.
[ 1.510449] SFPacket Inter-VM Shared Memory Driver - version 6.0.0
[ 1.512892] Copyright (c) 2014 Cisco Systems, Inc.
[ 1.520587] KVM_IVSHMEM: Major device number is: 247
[ 1.522333] KVM_IVSHMEM: Probing for KVM_IVSHMEM Device
[ 1.524689] KVM_IVSHMEM: result is 0
[ 1.526103] KVM_IVSHMEM: iomap base = 0x18446683600578412544
[ 1.528182] KVM_IVSHMEM: ioaddr = fc000000 ioaddr_size = 16777216
[ 1.529918] SFIVMSHM info: Registered device 'kvm_ivshmem'.
[ 1.531366] KVM_IVSHMEM: Registered with the SFIVMShm driver.
[ 1.532874] KVM_IVSHMEM: irq = 11 regaddr = febf1000 reg_size = 256

Activating all swap files/partitions...
[ 1.709596] Adding 1000444k swap on /dev/vda2. Priority:-1 extents[ OK ]s:1000444k
Mounting root file system in read-only mode... [ OK ]
Checking file systems...
e2fsck 1.42.9 (28-Dec-2013)
3D-6.2.2: clean, 20181/244320 files, 217838/976384 blocks
e2fsck 1.42.9 (28-Dec-2013)
e2fsck 1.42.9 (28-Dec-2013)
BOOT: clean, 51/24096 files, 24171/96256 blocks
/Volume: clean, 1736227/5554176 files, 4793836/22186412 blocks [ OK ]
Remounting root file system in read-write mode...
[ 1.841418] EXT3-fs (vda5): using internal journal [ OK ]
Mounting remaining file systems...
[ 1.849609] kjournald starting. Commit interval 5 seconds
[ 1.850205] EXT3-fs (sda1): using internal journal
[ 1.850207] EXT3-fs (sda1): mounted filesystem with ordered data mode
[ 1.857238] kjournald starting. Commit interval 5 seconds
[ 1.857493] EXT3-fs (vda7): using internal journal
[ 1.857496] EXT3-fs (vda7): mounted filesystem with ordered data mo[ OK ]
Removing /var/run/* and /var/lock/subsys/* [ OK ]
Removing /var/sf/run/*
Removing /tmp/cgi* files
Removing temporary files
Creating new /var/run/utmp... [ OK ]
Removing possible /etc/nologin /fastboot and /forcefsck... [ OK ]
Removing dhcp lock files... [ OK ]
/etc/rc.d/rcsysinit.d/S51udev_retry: line 35: log_info_msg: command no[ OK ]
Setting clock... [ OK ]
Initializing kernel random number generator... [ OK ]
Saving dmesg boot log [ OK ]
Loading fuse module failed!
Bringing up the loopback interface...
Upping interface lo [ OK ]
Configuring address the lo interface... [ OK ]
Configuring hostname to firepower [ OK ]
Configuring IPv6 address the lo interface... [ OK ]
Disable IPv6 default route [ OK ]
Configuring hostname to firepower [ OK ]
Configuring Static Routes
Starting ntp server [ OK ]
Writing hosts file [ OK ]
verify_fsic(start)
Running file integrity checks...
FIPS mode is disabled. Skip verifying file integrity
Setting kernel paramaters [ OK ]
INIT: Entering runlevel: 3
Starting system log daemon... [ OK ]
Starting cron daemon... [ OK ]
Adding swapfile /Volume/.swaptwo
[ 5.040294] Adding 2324440k swap on /Volume/.swaptwo. Priority:-2 extents:638 across:3172160k
Flushing all current IPv4 rules and user defined chains: [ 5.861733] ip_tables: (C) 2000-2006 Netfilter Core Team
...success
Clearing all current IPv4 rules and user defined chains: ...success
Applying iptables firewall rules:
Flushing chain `PREROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Flushing chain `POSTROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
[ 5.898944] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
Applying rules successed
Flushing all current IPv6 rules and user defined chains: [ 5.965981] ip6_tables: (C) 2000-2006 Netfilter Core Team
...success
Clearing all current IPv6 rules and user defined chains: ...success
Applying ip6tables firewall rules:
Flushing chain `PREROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Flushing chain `POSTROUTING'
Flushing chain `INPUT'
Flushing chain `FORWARD'
Flushing chain `OUTPUT'
Applying rules successed
Upping interface eth0 [ OK ]
Setting MTU... [ OK ]
Configuring DNS server: [8.8.8.8] [example.net]
List DNS server: [8.8.8.8] [example.net] [ OK ]
Writing out ntp server [ OK ]
Configuring address the eth0 interface... [ OK ]
Configuring IPv4 default route 10.10.112.1 for IP 10.10.112.99/255.255[ OK ]n eth0
Configuring hostname to firepower [ OK ]
Unconfiguring IPv6 [ OK ]
Configuring Static Routes
Starting ntp server [ OK ]
Writing hosts file [ OK ]
Interface disabled, downing [ OK ]
Starting portmap... [ OK ]
Starting nscd...
mkdir: created directory '/var/run/nscd' [ OK ]
Setting video params
setterm: cannot (un)set powersave mode: Inappropriate ioctl for device
Loading fuse module failed!
Generating public/private rsa1 key pair.
Saving key "/etc/ssh/ssh_host_key" failed: unknown or unsupported key [ OK ]
Starting , please wait......complete. [ OK ]
Starting xinetd:
Not reconfigurating
Thu Mar 12 08:30:34 UTC 2020
Starting MySQL...
Pinging mysql
Pinging mysql, try 1
Pinging mysql, try 2
Found mysql is running
Running initializeObjects...
Stopping MySQL...
Killing mysqld with pid 3249
Wait for mysqld to exit\c
done
Thu Mar 12 08:30:55 UTC 2020
Warning: speed or duplex not found in config file for eth0, using defaults...
modprobe: FATAL: Module ipmi_si not found in directory /lib/modules/3.10.53sf.cisco-150
Starting Cisco ASA5516, please wait...No PM running!
...started.
Mar 12 08:30:59 firepower SF-IMS[3626]: [3626] init script:system [INFO] pmmon Setting affinity to 4,5...
pid 3620's current affinity list: 0-5
pid 3620's new affinity list: 4,5
Mar 12 08:30:59 firepower SF-IMS[3628]: [3628] init script:system [INFO] pmmon The Process Manager is not running...
Mar 12 08:30:59 firepower SF-IMS[3629]: [3629] init script:system [INFO] pmmon Starting the Process Manager...
Mar 12 08:30:59 firepower SF-IMS[3630]: [3630] pm:pm [INFO] Using model number 72M

firepower login: [ 33.791481] SFHS[3631] - kvm_ivshmem: Set max latency to 0 msecs (0 jiffies)
[ 34.168425] tun: Universal TUN/TAP device driver, 1.6
[ 34.169763] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
[ 34.212516] SFIVMSHM info: Initializing Channel 0 Client Descriptor Base...
[ 34.214818] SFIVMSHM info: Initializing Channel 1 Client Descriptor Base...
[ 34.217241] SFIVMSHM info: Initializing packet buffer pool...
[ 34.219380] SFIVMSHM info: Initializing packet buffer pool done!
[ 34.607223] IPv6: ADDRCONF(NETDEV_UP): tun1: link is not ready
[ 34.862786] SFIVMSHM info: Shared Memory start addr = ffffc90000800000 size = 16777216
[ 34.864810] SFIVMSHM info: magicNum = 0x2a1337 version = 3 asa_state = INIT_COMPLETE ips_state = INIT_COMPLETE lineStatus = 1 mode = 0 totalSize = 16777216
[ 34.868236] SFIVMSHM info: Channel Info ch_count = 2
[ 34.869489] SFIVMSHM info: Channel Info #0: [TS pool_offset = 0 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.872160] SFIVMSHM info: Channel Info #0: [FS pool_offset = 36288 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.875295] SFIVMSHM info: Channel Info #1: [TS pool_offset = 72576 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.878362] SFIVMSHM info: Channel Info #1: [FS pool_offset = 108864 nextToRead = 0 nextToWrite = 0 count = 1008 pad = 0]
[ 34.881080] SFIVMSHM info: Packet Buffer pools [server start=147456 count=6902 size=14135296] [client start=14282752 count=1218 size=2494464] [pktbuf_size = 2048]
[ 34.885494] SFIVMSHM info: Allocated 165648 bytes for the array of 6902 IvmShm Buffers.
[ 34.888890] SFIVMSHM info: [3670]: Ring kvm_ivshmem - RX/TX thread created and started (ffff8800d8ac11c0)
[ 34.891918] SFIVMSHM info: [3670]: Ring kvm_ivshmem - Done with index -1 and rval 0
[ 35.395621] IPv6: ADDRCONF(NETDEV_CHANGE): tun1: link becomes ready
[ 42.235307] SFIVMSHM info: [3671]: Ring kvm_ivshmem - Done with index 0 and rval 0
[ 42.237291] Remapping addr = 0x7f77cebec000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 42.302169] SFIVMSHM info: [3673]: Ring kvm_ivshmem - Done with index 1 and rval 0
[ 42.304303] Remapping addr = 0x7fbfe61ad000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 42.315901] SFIVMSHM info: [3672]: Ring kvm_ivshmem - Done with index 2 and rval 0
[ 42.318151] Remapping addr = 0x7f702b000000, pfn = 0xfc000, size = 0x1000000, mem = ffffc90000800000, PAGE_SIZE = 0x1000
[ 64.201116] SFPacket_AFBP: Copied first heartbeat for future use (78 bytes)
[ 9219.441421] hpet1: lost 2 rtc interrupts

 

 

It was my mistake to say that firepower was not detected in the "show version" output.
When I check other ASA, it shows the same result.

Today, I retried Firepower shutdown, reset, reload.
I can get an output "show module sfr details".
But I can't see Firepower system in ASDM. Still stucked..

<show module sfr details>
Getting details from the Service Module, please wait...

Card Type: FirePOWER Services Software Module
Model: ASA5516
Hardware version: N/A
Serial Number: JAD24020KMG
Firmware version: N/A
Software version: 6.2.2-81
MAC Address Range: 4ce1.7659.660a to 4ce1.7659.660a
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 6.2.2-81
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr:
Mgmt IP addr: 10.10.112.99
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 10.10.112.1
Mgmt web ports: 443
Mgmt TLS enabled: true

Hi,

 

   Ensure you use a version of ASDM that supports FPWR (not sure in which version it came), likewise ensure that ASA can reach the management IP address of FPWR. Look here for reference:

 

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/200889-Using-ASDM-to-manage-a-FirePOWER-module.html

 

Regards,

Cristian Matei.

As a result of verification through the document, it seems that ASA and Firepower can communicate(can ping), but my PC(ASDM) and Firepower cannot communicate. However, I found a log file in firepower console(/var/log/sf/updates.sh). It seemed that the update was aborted by shutting down the module during the version update. Eventually, I reinstalled firepower new version and I solved problem.

 

Card Type: FirePOWER Services Software Module
Model: ASA5516
Hardware version: N/A
Serial Number: JAD24020KMG
Firmware version: N/A
Software version: 6.4.0.7-53
MAC Address Range: 4ce1.7659.660a to 4ce1.7659.660a
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 6.4.0.7-53
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr: No DC Configured
Mgmt IP addr: 10.10.112.99
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 10.10.112.1
Mgmt web ports: 443
Mgmt TLS enabled: true

 

Thank you for your assistance.

 

Review Cisco Networking products for a $25 gift card