02-04-2023 11:06 AM - edited 02-10-2023 11:52 PM
I am using two Cisco Fire Power ASA 5515-X last two years. But suddenly from last 3 month one Firewall has been hanging automatically. Nothing does work then. After reboot manually it does work. but after sometime same issue occurred again. I use asa9-12-3-12-smp-k8.bin version for both firewall. I change to the default version. But same issue. For this reason my production is hampering. I can't understand what is the issue. No warranty for those firewall. So need your expert advise immediately for solving this issue.
Note: Alarm LED has ON when Firewall habged
Thank you.
02-04-2023 12:24 PM
Firewall has been hanging automatically <<- what is you notice
02-04-2023 12:25 PM
Try to upgrade to 9.12.4 interim based on the available code and check.
Also may be if you have the archive config, check what was a major change done last 3 months from the day you have the issue in the network also config wise, sure you do mention defaulting the config to factory still having issues, so possibly post the config here.
when you mentioned hanged, you were not able to reach the box, how about the console? does the failover work?
02-04-2023 03:37 PM - edited 02-04-2023 03:37 PM
The FW could be experiencing DDoS. Go HERE and see what security vulnerabilities 9.12.3.12 is affected.
02-05-2023 04:14 AM
Thanks your nice reply. Console also does not work then. Failover is working. Secondary FW is now as a primary. Both are same version used.
One question : If I change to 9.12.4 then FirePower version need to change? If need then what will be the version of firepower?
02-05-2023 09:40 AM
check the compatible matrix :
https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html
02-06-2023 12:41 PM
Friend I changed the IOS to 9.12.4.10 yesterday. Today same issue has raised again. What can I do now?
02-06-2023 01:03 PM
show interface for both ASA and both INside and OUTside, please share this
02-06-2023 10:32 PM
Primary-FW/act# sh inter
Primary-FW/act# sh interface
Interface GigabitEthernet0/0 "outside", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Input flow control is unsupported, output flow control is off
Description: Connect to BANet_Firewall
MAC address 2c33.1151.3fd8, MTU 1500
IP address 10.11.244.4, subnet mask 255.255.255.248
488684 packets input, 102340537 bytes, 0 no buffer
Received 652 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
594578 packets output, 289051881 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (494/453)
output queue (blocks free curr/low): hardware (511/493)
Traffic Statistics for "outside":
488623 packets input, 93497180 bytes
594578 packets output, 278341147 bytes
647 packets dropped
1 minute input rate 68 pkts/sec, 13027 bytes/sec
1 minute output rate 85 pkts/sec, 42799 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 60 pkts/sec, 11710 bytes/sec
5 minute output rate 72 pkts/sec, 32452 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface GigabitEthernet0/1 "", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Active member of Redundant1
MAC address 2c33.1151.b5d9, MTU not set
IP address unassigned
594608 packets input, 289213405 bytes, 0 no buffer
Received 3 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
488008 packets output, 102113435 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (485/450)
output queue (blocks free curr/low): hardware (511/499)
Interface GigabitEthernet0/2 "FOLink", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Description: LAN/STATE Failover Interface
MAC address 2c33.1151.b5dd, MTU 1500
IP address 192.168.99.2, subnet mask 255.255.255.252
16510 packets input, 4869468 bytes, 0 no buffer
Received 1 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
147909 packets output, 119278044 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 1 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (502/456)
output queue (blocks free curr/low): hardware (463/425)
Traffic Statistics for "FOLink":
16466 packets input, 4498118 bytes
147848 packets output, 116608526 bytes
0 packets dropped
1 minute input rate 1 pkts/sec, 222 bytes/sec
1 minute output rate 18 pkts/sec, 14767 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 1 pkts/sec, 266 bytes/sec
5 minute output rate 19 pkts/sec, 15303 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface GigabitEthernet0/3 "", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Standby member of Redundant1
MAC address 2c33.1151.b5da, MTU not set
IP address unassigned
13 packets input, 4542 bytes, 0 no buffer
Received 13 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
13 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (498/498)
output queue (blocks free curr/low): hardware (511/511)
Interface GigabitEthernet0/4 "", is administratively down, line protocol is down
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex, Auto-Speed
Input flow control is unsupported, output flow control is off
Available but not configured via nameif
MAC address 2c33.1151.b5de, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (511/511)
output queue (blocks free curr/low): hardware (511/511)
Interface GigabitEthernet0/5 "", is administratively down, line protocol is down
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex, Auto-Speed
Input flow control is unsupported, output flow control is off
Available but not configured via nameif
MAC address 2c33.1151.b5db, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (511/511)
output queue (blocks free curr/low): hardware (511/511)
Interface Management0/0 "management", is up, line protocol is up
Hardware is en_vtun rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address 2c33.1151.3fd4, MTU 1500
IP address 192.168.10.1, subnet mask 255.255.255.0
446162 packets input, 231257963 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
483664 packets output, 37871618 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
1 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (0/0)
output queue (blocks free curr/low): hardware (0/0)
Traffic Statistics for "management":
446131 packets input, 224807865 bytes
483664 packets output, 31100322 bytes
1573 packets dropped
1 minute input rate 6 pkts/sec, 266 bytes/sec
1 minute output rate 13 pkts/sec, 3323 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 51 pkts/sec, 24874 bytes/sec
5 minute output rate 57 pkts/sec, 4461 bytes/sec
5 minute drop rate, 0 pkts/sec
Management-only interface. Blocked 0 through-the-device packets
Interface Redundant1 "inside", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address 2c33.1151.3fd5, MTU 1500
IP address 192.168.100.1, subnet mask 255.255.255.248
594988 packets input, 289301256 bytes, 0 no buffer
Received 16 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
13 L2 decode drops
488358 packets output, 102191268 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (966/450)
output queue (blocks free curr/low): hardware (1022/499)
Traffic Statistics for "inside":
592377 packets input, 274975239 bytes
488358 packets output, 93400651 bytes
2 packets dropped
1 minute input rate 84 pkts/sec, 42625 bytes/sec
1 minute output rate 68 pkts/sec, 12999 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 72 pkts/sec, 32191 bytes/sec
5 minute output rate 60 pkts/sec, 11681 bytes/sec
5 minute drop rate, 0 pkts/sec
Redundancy Information:
Member GigabitEthernet0/1(Active), GigabitEthernet0/3
Last switchover at 10:20:24 UTC Feb 7 2023
02-06-2023 04:39 PM
you need provide more information and logs
show run
network diagram
what logs you see?
hang means it totally stop working?
02-06-2023 10:34 PM
02-06-2023 11:36 PM
you need provide more information and logs ( your log empty)
show run
network diagram
what logs you see?
hang means it totally stop working?
02-07-2023 12:07 AM
02-07-2023 03:14 PM
I check the interface, it OK there is no problem.
but I see some thing I dont see before in config.
you config one link for failover
you also config link for status
then you config IP for status not for failover
please remove this
failover link FOLink GigabitEthernet0/2
and check.
also I see HSRP before the ASA HA
so
are HSRP point to Active ASA ?
are ASA point to VIP of HSRP ?
are you sure that there is L2 between ASA inside ?
02-08-2023 10:41 AM
No HSRP between Firewalls. This is ASA failover configuration.
are you sure that there is L2 between ASA inside ?
Yes.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide