cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
650
Views
0
Helpful
6
Replies

ASA SFR module stuck , can not do any command

zeljkosan
Level 1
Level 1

Hello, I have problems with Cisco ASA 5545. 

We have two in cluster, and recently we RMA whole ASA, and put same SSD disks from removed one.

After I put these commands:

ASA#sw-module module sfr recover configure image disk0:/asa$
ASA#sw-module module sfr recover boot

I started debug, but it stuck in this 

***
*** EVENT: The module is being recovered.
*** TIME: 08:55:23 UTC Dec 4 2023
***


12 hours later I typed:

ASA#show module sfr log console

Displaying Console Log Information for Module sfr:

***
*** EVENT: The module is being recovered.
*** TIME: 08:55:23 UTC Dec 4 2023
***

For all commands I get same message

ASA#sw-module module sfr reset/recover/reload/uninstall

Module sfr should be shut down before resetting it or loss of configuration may occur.

Reset/recover/reload/uninstall module sfr? [confirm]

Module sfr cannot be resetrecover/reload/uninstall, please stop the current recovery before trying to reset the module.

And if I start shutdown:

ASA#sw-module module sfr shutdown

Shutdown module sfr? [confirm]

Module sfr cannot be shut down, not in Up or Unresponsive state.

Also:

ASA#session sfr console
ERROR: Failed opening console session with module sfr. Module is in "Recover" state.
Please try again later.

I have read this article, but it doesn't help me so far:

https://community.cisco.com/t5/network-security/sfr-is-stuck-in-recover-for-12-hours-asa5545-x/td-p/4260412

6 Replies 6

marce1000
VIP
VIP

 

 - Connect to the ASA with https://cway.cisco.com/cli/   ; at the top left press and or run 'System Diagnostics' , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

balaji.bandi
Hall of Fame
Hall of Fame

When you mentioned cluster are you trying while the cluster connected, or is this ASA out of cluster ?

 

what ASA Code running ?? what SFR version on other work which working ?

check below guide may help you :

https://edledge.com/unwanted-asa-failover-due-to-sfr-error/

still issue i suggest you to re-image SFR.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

As noted by @balaji.bandi , please share your ASA and sfr module boot file version.

zeljkosan
Level 1
Level 1

Hello thanks for fast reply,

I appologize for long text.

I have two asa in Cluster connected with failover link set up on gi0/7

ASA5545X/pri/act# show version

Cisco Adaptive Security Appliance Software Version 9.8(4)25
Firepower Extensible Operating System Version 2.2(2.124)
Device Manager Version 7.13(1)

Compiled on Mon 06-Jul-20 08:03 PDT by builders
System image file is "disk0:/asa984-25-smp-k8.bin"
Config file at boot was "startup-config"

What other info do you need from cluster or primary ASA?

Secondar ASA

ASA5545X/sec/stby(config)# sw-module module sfr uninstall
Module sfr will be uninstalled. This will completely remove the disk image assocated with the sw-module including any configuration that existed within it.
Uninstall module sfr? [confirm]
Module sfr cannot be uninstalled, not in Up, Down, or Unresponsive state.
ASA5545X/sec/stby(config)#

 

ASA5545X/sec/stby(config)# show ver

Cisco Adaptive Security Appliance Software Version 9.8(4)25
Firepower Extensible Operating System Version 2.2(2.124)
Device Manager Version 7.13(1)

Compiled on Mon 06-Jul-20 08:03 PDT by builders
System image file is "disk0:/asa984-25-smp-k8.bin"
Config file at boot was "startup-config"

ASA5545X up 21 hours 48 mins
failover cluster up 6 years 322 days

Hardware: ASA5545, 12288 MB RAM, CPU Lynnfield 2660 MHz, 1 CPU (8 cores)
ASA: 6450 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Boot microcode : CNPx-MC-BOOT-2.00
SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005
IPSec microcode : CNPx-MC-IPSEC-MAIN-0026
Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4


ASA5545X/sec/stby# show failover
Failover On
Failover unit Secondary
Failover LAN Interface: failover GigabitEthernet0/7 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 6 of 316 maximum
MAC Address Move Notification Interval not set
Version: Ours 9.8(4)25, Mate 9.8(4)25
Serial Number: Ours FCH16207E42, Mate FCH19477ERF
Last Failover at: 10:24:20 CEST Dec 4 2023
This host: Secondary - Standby Ready
Active time: 263 (sec)
slot 0: ASA5545 hw/sw rev (1.0/9.8(4)25) status (Up Sys)
Interface **** ALL INTERFACES ****: Normal (Monitored)

Other host: Primary - Active
Active time: 8322337 (sec)
slot 0: ASA5545 hw/sw rev (1.0/9.8(4)25) status (Up Sys)
Interface **** ALL INTERFACES ****: Normal (Monitored)

slot 1: SFR5545 hw/sw rev (N/A/6.6.1-91) status (Up/Up)
ASA FirePOWER, 6.6.1-91, Up, (Monitored)
slot 1: SFR5545 hw/sw rev (N/A/6.6.1-91) status (Up/Up)
ASA FirePOWER, 6.6.1-91, Up, (Monitored)

 

ASA5545X/sec/stby# show service-policy sfr

Global policy:
Service-policy: global_policy
Class-map: CM-SFR
SFR: card status Not Applicable, mode fail-open
packet input 0, packet output 0, drop 0, reset-drop 0


ASA5545X/sec/stby# sh run all monitor-interface
...
monitor-interface service-module

zeljkosan
Level 1
Level 1

Hello,

I solved this problem by formatting SSD disk, and you need to have both same SSD disk series  (I get different one SSD disk from RMA, so I requested for one more), and after all we install SFR module.

 

Br

Glad you resolved and thank you for sharing the outcome.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card