cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5662
Views
25
Helpful
18
Replies

ASDM stop working after upgrading ASA.

loc.nguyen
Level 1
Level 1

Hi,

Hi

I have ASA  Model : ASA 5525-X

I just upgraded to a new ASA version: asa9-12-4-39-smp-k8.bin

ASDM stop working, so I upgrade ASDM to asdm image disk0:/asdm-7131-101.bin as the compatibility request.

https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html

 

I got the issue that can not authenticate. 

I tried to set up ASDM o other laptop but it did not help. 

Could you advise what I should do ?

 

asdm issue logon.jpg

 

Thanks

 

Loc

18 Replies 18

ciscoasa# show flash <- do you see the ASDM image ?

ciscoasa# verify flash:/asdm-xxxx.bin <- check if the image is OK - Yes

ciscoasa# show adsm image <-check what image run now - 
Device Manager image file not set

Marvin Rhoads
Hall of Fame
Hall of Fame

I came across the same thing just recently.Everything was setup correctly, had been working for years etc. etc.

We found a reddit thread whereby someone found that changing to "no aaa authentication http console LOCAL" fixes it. Counter-intuitive but it worked for us.

I believe it's a bug but didn't take the time to open a TAC case on it to confirm.

https://www.reddit.com/r/Cisco/comments/u941ye/asdm_not_working_after_asaasdm_upgrade/i77t9of/

Yeah, it worked for me. I used that for about 10 ASA I had issue with, all worked.  You made my day

 

Thank you very much. 

 

Loc

dchristenson
Level 1
Level 1

In case someone else has this issue, since none of the above worked for me.
ASDM worked fine on all 6 of my ASAs for years.
After I upgraded from 7.12(1) to 7.18(1.152), it stopped working on my VPN pair only. The other 2 pairs were fine.
After digging I found this on that pair:
webvpn  
 enable INSIDE tls-only
 enable OUTSIDE tls-only

We don't allow it internally anyways, so I disabled i
t and ASDM is now working:

# conf t
(config)# webvpn
(config-webvpn)# no enable INSIDE tls-only
WARNING: Disabling webvpn removes proxy-bypass settings.
Do not overwrite the configuration file if you want to keep existing proxy-bypass commands.
INFO: WebVPN and DTLS are disabled on 'INSIDE'.

Hope this helps someone else.

 

Review Cisco Networking for a $25 gift card