06-18-2019 09:08 AM - edited 02-21-2020 09:13 AM
We have an HA pair of ASA-5525x firewalls. Occasionally when we will deploy changes the SFR that is the standby mode will not update and the only way we have been able to correct this problem is to do a complete rebuild of the SFR module. We have tried the obvious solution of reloading the module and even rebooting the ASA but neither will bring the SFR back to an operational status. When doing a show module sfr the results show that the module is UP. It is getting old having to rebuild an SFR module each time this happens, hopefully someone has experienced this before and can help out...
06-18-2019 06:37 PM
A couple of questions and one recommendation:
1. What version of ASA code are you running?
2. Have you considered moving to FTD (Unified image)?
3. I noticed from the screenshots that you are running version 6.3.0-1 and I would highly recommend that you apply the latest patch (3). I just checked the release notes and there are several resolved defects that are related with deploying configuration changes:
Thank you for rating helpful posts!
06-19-2019 08:17 AM
We are running version: 9.6(4)17
Don't believe that this is an ASA firmware of SFR version issue. We have had this problem since the initial deployment of the firewalls which have been in place for quite some time now and we update them regularly.
With the project list we have it's just not possible to migrate to FTD.
Thanks,
Ben
06-19-2019 11:06 AM
Hmm. This is strange as I have several customers running similar deployments and they have not had this issue. I would suggest reaching out to TAC to get to the bottom of this.
Also, one more question: What is the ROMMON version of the ASAs?
Thank you for rating helpful posts!
06-19-2019 09:00 PM
Like @nspasov I have also done numerous HA ASA pairs with Firepower service module and never seen this problem.
I could postulate that the standby unit has a misconfiguration with the Firepower module - for instance using the same address for ASA management and sfr module would confuse the downstream device's arp table and cause intermittent connectivity and failure to deploy or upgrade.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide