01-08-2018 01:32 AM - edited 02-21-2020 07:05 AM
Hi,
I want to upgrade the ASA 5512 and 5525 from 9.1(1) to the latest recommended version. Please suggest the recommended stable version to upgrade to - 9.6/9.7.
Thanks
Sreeraj
Solved! Go to Solution.
01-08-2018 02:43 AM
Yes that particular vulnerability is fixed in the suggested release.
You asked for a version of either the 9.6 or 9.7 train. v9.7 has had less revision, and unless there is a feature which was made available in v9.7, v9.6 is the suggested release.
So in choosing a release from the v9.6 go for the latest 'interim' release which contains bug fixes discovered since the last feature/ maintenance release.
cheers,
Seb.
01-08-2018 01:48 AM
Hi there,
For both platforms v9.6.3 is the recommended release. specifically you will want the interim release:
asa963-20-smp-k8.bin
cheers,
Seb.
01-08-2018 02:04 AM
Thanks for expert input.
Basically I want to mitigate the below vulnerability by the code upgrade
Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow Vulnerability
Web link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike.
Hope this vulnerability will be fixed with the ASA code-asa963-20-smp-k8.bin. Please suggest also, Any specific reason for suggesting asa963-20-smp-k8.bin. Kindly provide your expert inputs.
01-08-2018 02:43 AM
Yes that particular vulnerability is fixed in the suggested release.
You asked for a version of either the 9.6 or 9.7 train. v9.7 has had less revision, and unless there is a feature which was made available in v9.7, v9.6 is the suggested release.
So in choosing a release from the v9.6 go for the latest 'interim' release which contains bug fixes discovered since the last feature/ maintenance release.
cheers,
Seb.
01-09-2018 07:08 AM
Thanks. Could you please advice on the below bug as well.
Potential Traffic Outage (9.6(2.1) through 9.6(3))—Due to bug CSCvd78303, the ASA may stop passing traffic after 213 days of uptime. The effect on each network will be different, but it could range from an issue of limited connectivity to something more extensive like an outage. You must upgrade to a new version without this bug, when available. In the meantime, you can reboot the ASA to gain another 213 days of uptime. Other workarounds may be available. See Field Notice FN-64291 for affected versions and more information.
Will, asa963-20-smp-k8.bin addresses this.
Also do suggest, the supported recommended ASDM version.
Thanks
01-10-2018 02:47 AM
Hi,
I am not able to find ASA code-asa963-20-smp-k8.bin on Cisco download section. I am looking at asa963-1-smp-k8.bin. Please comment.
Thanks
Sreeraj
01-10-2018 05:39 AM
Look under All Releases -> Interim -> 9 -> 9.6.3
01-14-2018 11:33 PM
Thanks a lot, I could find 9.6.3(2), which comes under the interim release.
01-08-2018 04:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide