cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1899
Views
0
Helpful
6
Replies

ASA SFR module stuck , can not do any command

zeljkosan
Level 1
Level 1

Hello, I have problems with Cisco ASA 5545. 

We have two in cluster, and recently we RMA whole ASA, and put same SSD disks from removed one.

After I put these commands:

ASA#sw-module module sfr recover configure image disk0:/asa$
ASA#sw-module module sfr recover boot

I started debug, but it stuck in this 

***
*** EVENT: The module is being recovered.
*** TIME: 08:55:23 UTC Dec 4 2023
***


12 hours later I typed:

ASA#show module sfr log console

Displaying Console Log Information for Module sfr:

***
*** EVENT: The module is being recovered.
*** TIME: 08:55:23 UTC Dec 4 2023
***

For all commands I get same message

ASA#sw-module module sfr reset/recover/reload/uninstall

Module sfr should be shut down before resetting it or loss of configuration may occur.

Reset/recover/reload/uninstall module sfr? [confirm]

Module sfr cannot be resetrecover/reload/uninstall, please stop the current recovery before trying to reset the module.

And if I start shutdown:

ASA#sw-module module sfr shutdown

Shutdown module sfr? [confirm]

Module sfr cannot be shut down, not in Up or Unresponsive state.

Also:

ASA#session sfr console
ERROR: Failed opening console session with module sfr. Module is in "Recover" state.
Please try again later.

I have read this article, but it doesn't help me so far:

https://community.cisco.com/t5/network-security/sfr-is-stuck-in-recover-for-12-hours-asa5545-x/td-p/4260412

6 Replies 6

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Connect to the ASA with https://cway.cisco.com/cli/   ; at the top left press and or run 'System Diagnostics' , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

balaji.bandi
Hall of Fame
Hall of Fame

When you mentioned cluster are you trying while the cluster connected, or is this ASA out of cluster ?

 

what ASA Code running ?? what SFR version on other work which working ?

check below guide may help you :

https://edledge.com/unwanted-asa-failover-due-to-sfr-error/

still issue i suggest you to re-image SFR.

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

As noted by @balaji.bandi , please share your ASA and sfr module boot file version.

zeljkosan
Level 1
Level 1

Hello thanks for fast reply,

I appologize for long text.

I have two asa in Cluster connected with failover link set up on gi0/7

ASA5545X/pri/act# show version

Cisco Adaptive Security Appliance Software Version 9.8(4)25
Firepower Extensible Operating System Version 2.2(2.124)
Device Manager Version 7.13(1)

Compiled on Mon 06-Jul-20 08:03 PDT by builders
System image file is "disk0:/asa984-25-smp-k8.bin"
Config file at boot was "startup-config"

What other info do you need from cluster or primary ASA?

Secondar ASA

ASA5545X/sec/stby(config)# sw-module module sfr uninstall
Module sfr will be uninstalled. This will completely remove the disk image assocated with the sw-module including any configuration that existed within it.
Uninstall module sfr? [confirm]
Module sfr cannot be uninstalled, not in Up, Down, or Unresponsive state.
ASA5545X/sec/stby(config)#

 

ASA5545X/sec/stby(config)# show ver

Cisco Adaptive Security Appliance Software Version 9.8(4)25
Firepower Extensible Operating System Version 2.2(2.124)
Device Manager Version 7.13(1)

Compiled on Mon 06-Jul-20 08:03 PDT by builders
System image file is "disk0:/asa984-25-smp-k8.bin"
Config file at boot was "startup-config"

ASA5545X up 21 hours 48 mins
failover cluster up 6 years 322 days

Hardware: ASA5545, 12288 MB RAM, CPU Lynnfield 2660 MHz, 1 CPU (8 cores)
ASA: 6450 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Boot microcode : CNPx-MC-BOOT-2.00
SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005
IPSec microcode : CNPx-MC-IPSEC-MAIN-0026
Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4


ASA5545X/sec/stby# show failover
Failover On
Failover unit Secondary
Failover LAN Interface: failover GigabitEthernet0/7 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 6 of 316 maximum
MAC Address Move Notification Interval not set
Version: Ours 9.8(4)25, Mate 9.8(4)25
Serial Number: Ours FCH16207E42, Mate FCH19477ERF
Last Failover at: 10:24:20 CEST Dec 4 2023
This host: Secondary - Standby Ready
Active time: 263 (sec)
slot 0: ASA5545 hw/sw rev (1.0/9.8(4)25) status (Up Sys)
Interface **** ALL INTERFACES ****: Normal (Monitored)

Other host: Primary - Active
Active time: 8322337 (sec)
slot 0: ASA5545 hw/sw rev (1.0/9.8(4)25) status (Up Sys)
Interface **** ALL INTERFACES ****: Normal (Monitored)

slot 1: SFR5545 hw/sw rev (N/A/6.6.1-91) status (Up/Up)
ASA FirePOWER, 6.6.1-91, Up, (Monitored)
slot 1: SFR5545 hw/sw rev (N/A/6.6.1-91) status (Up/Up)
ASA FirePOWER, 6.6.1-91, Up, (Monitored)

 

ASA5545X/sec/stby# show service-policy sfr

Global policy:
Service-policy: global_policy
Class-map: CM-SFR
SFR: card status Not Applicable, mode fail-open
packet input 0, packet output 0, drop 0, reset-drop 0


ASA5545X/sec/stby# sh run all monitor-interface
...
monitor-interface service-module

zeljkosan
Level 1
Level 1

Hello,

I solved this problem by formatting SSD disk, and you need to have both same SSD disk series  (I get different one SSD disk from RMA, so I requested for one more), and after all we install SFR module.

 

Br

Glad you resolved and thank you for sharing the outcome.

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card