cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3474
Views
0
Helpful
6
Replies

ASA upgrade when not able wr to flash

Michal Valach
Level 1
Level 1

Hi all, I have one issue. I have 2 ASA 5555 in failover, but based on TAC case in asa861-2-smp-k8.bin is bug, and cause to not able write anything on flash.  Cisco recomeded to upgrade to 8.6(1)7. But how to do it if not able copy to flash? I need zero downtime and maybe will not be able to have hands on ASAs, just remote access.

I got idea to use boot system tftp, but what if after reboot ASA will not find flash? Does anybody experience with this/similar case? Do you have any other recommendation ?   Many thanks for advices!

%Error opening disk0:/.private/startup-config (No more processes)

Error executing command

[FAILED]

1 Accepted Solution

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Wouldnt this have been something that the TAC could have helped with?

Do you have any ID related to the Bug?

I dont know how you can do this in a situation where you cant write to Flash. I mean you cant even copy the new image to the Flash so how are you going to boot to the new software? And since you cant save the configuration either to the Flash then when rebooting the ASA it wont have the "boot system tftp:/" configuration anymore?

I'd imagine this is a very very rare case. I have never run into this kind of problem. Probably one reason I cant think of a workaround right now

Still I would have imagined the TAC would have given you instruction how to proceed.

On a side note. If you already had the new software on the Flash at this point then you could simply delete the buggy software from the flash and the ASA would only have the new software to boot to. But I imagine this is not the case? (that you have the new software already on the Flash). Even then it could have some risks that I cant think of right now

- Jouni

View solution in original post

6 Replies 6

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

Wouldnt this have been something that the TAC could have helped with?

Do you have any ID related to the Bug?

I dont know how you can do this in a situation where you cant write to Flash. I mean you cant even copy the new image to the Flash so how are you going to boot to the new software? And since you cant save the configuration either to the Flash then when rebooting the ASA it wont have the "boot system tftp:/" configuration anymore?

I'd imagine this is a very very rare case. I have never run into this kind of problem. Probably one reason I cant think of a workaround right now

Still I would have imagined the TAC would have given you instruction how to proceed.

On a side note. If you already had the new software on the Flash at this point then you could simply delete the buggy software from the flash and the ASA would only have the new software to boot to. But I imagine this is not the case? (that you have the new software already on the Flash). Even then it could have some risks that I cant think of right now

- Jouni

jocamare
Level 4
Level 4

The problem when writing to flash is only present when running the particular version you mentioned, that means that you can rest assured that when booting from tftp with a different code [there will be some downtime] you will be then able to copy the file to flash.

I'm sure you have applied the following command:

fsck flash:

And have also tried to format the flash memory.

But wouldnt the "boot system tftp:" already dissapear right after the reboot of the ASA because it cant save that configuration change to the startup configuration on the Flash?

- Jouni

Michal Valach
Level 1
Level 1

@Jouni, you are rightI cannot boot from tftp, once I configure it, without saving, I will lost it.  I think I have to contact cisco.

@Jocamare, yes, will try fsck

Thanks

I still havent even seen a new ASA5500-X series

I started to wonder would it change anything to use an External Flash card? Surely the new ASAs have that?

I quickly checked that they have USB support? Wonder if it could be used to boot to the new software?

Just some quick thoughts.

- Jouni

Michal Valach
Level 1
Level 1

Thanks for help, conclosion is that we are going to do RMA for both devices to avoid any downtime :-)

Review Cisco Networking for a $25 gift card