06-27-2011 09:51 AM - edited 03-11-2019 01:51 PM
Hello:
Well I just had an issue last weekend, we got a mainteinace of a firewall where the engineer had to turn of the device and open the case to cleaning it with compressed air and when he finished and turn on the devices the firewall was acting weird because it was rebooting every time that the device finished to load all the configuration, I was checking this with a CISCO engineer an he told me that the problem was because we were hitting a bug, the bug is CSCtb07060
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId= CSCtb07060
And as I was checking it says that maybe the problem is when you have the IOS 8.2(1) with more than 25 o 30 subinterfaces and the bug fixes on the IOS 8.2(4). I was working with this IOS since april or may I don't remember and everything was working fine so it was only when we turn off the device that this bootloop happens. And in fact I have another devices with more than 30 subinterfaces configured and I was wonder if this going to happen on those ASAs.
Does anybody have this problem before or something related to?
Regards
Solved! Go to Solution.
06-27-2011 10:51 PM
Luis,
The problem is not going to be present until you reload the Unit, I know you have been running with this firewall for sometime now, and that you have others too, but there are some conditions that need to be met prior the ASA to fall on this bug such as the Firewall im multiple conext, 25 to 30 subinterfaces, and version 8.2.1.
I am sure that if you reload the other ASA firewall is going to fall into this bug. The reason why you have not get this error before it should be because you have not reloaded the other ASAs, you have added more vlans since the last reload etc.
However, to be in safe ground, I would suggest you to upgrade.
Mike
06-27-2011 10:51 PM
Luis,
The problem is not going to be present until you reload the Unit, I know you have been running with this firewall for sometime now, and that you have others too, but there are some conditions that need to be met prior the ASA to fall on this bug such as the Firewall im multiple conext, 25 to 30 subinterfaces, and version 8.2.1.
I am sure that if you reload the other ASA firewall is going to fall into this bug. The reason why you have not get this error before it should be because you have not reloaded the other ASAs, you have added more vlans since the last reload etc.
However, to be in safe ground, I would suggest you to upgrade.
Mike
06-28-2011 09:08 AM
Hi Mike:
I was checking another devices that are working with the IOS 8.2(1) and I found that some of them got more than 25, in fact there is one that have 35 subinterfaces configured and this device was already rebooted and nothing happens, so I am not conviced at all with this bug, because if what are you saying is correct I should have this problem with the ASA that have the IOS 8.2(1) and the 35 subinterfaces.
Maybe this is something different, I guess ...
Regards
06-28-2011 09:23 AM
Do they have SSM modules? The one that you own and that hit this bug has one?
Mike
06-28-2011 09:33 AM
The one that hit the bug had a SSM module, the other 5 also have SSM modules
Regards
06-28-2011 09:42 AM
I'll say that you may want to take a look at the related bug CSCte12203. It states
"Under rare conditions the ASA has problems supporting +30 subinterfaces with an AIP-SSM installed"
So I stand corrected, it wont be for sure that is going to have the bug, it just may hit it. To be on safe ground, you will need to update the code.
Mike Rojas
06-28-2011 09:47 AM
I also see that but I'm not sure what they mean with rare conditions...
06-28-2011 10:06 AM
Rare conditions means that the device may reload or not having the type of configuration described that produces the bug.
Mike
06-28-2011 10:16 AM
Ok Mike, well I will made some test with a device that I have in the lab, meanwhile I will upgrade the ASAs with more than 25 vlans to prevent this kind of problems.
Thanks for your help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide