cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4289
Views
30
Helpful
34
Replies

Cisco ASA 5515-X hanged several times.(Urgent)

ibbulbul
Level 1
Level 1

I am using two Cisco Fire Power ASA 5515-X last two years. But suddenly from last 3 month one Firewall has been hanging automatically. Nothing does work then. After reboot manually it does work. but after sometime same issue occurred again. I use asa9-12-3-12-smp-k8.bin version for both firewall. I change to the default version. But same issue. For this reason my production is hampering. I can't understand what is the issue. No warranty for those firewall. So need your expert advise immediately for solving this issue.

Note: Alarm LED has ON when Firewall habged

Thank you.

34 Replies 34

Firewall has been hanging automatically <<- what is you notice 

balaji.bandi
Hall of Fame
Hall of Fame

Try to upgrade to 9.12.4 interim based on the available code and check.

Also may be if you have the archive config, check what was a major change done last 3 months from the day you have the issue in the network also config wise, sure you do mention defaulting the config to factory still having issues, so possibly post the config here.

when you mentioned hanged, you were not able to reach the box, how about the console? does the failover work?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Leo Laohoo
Hall of Fame
Hall of Fame

The FW could be experiencing DDoS.  Go HERE and see what security vulnerabilities 9.12.3.12 is affected.  

Thanks your nice reply. Console also does not work then. Failover is working. Secondary FW is now as a primary. Both are same version used.
One question : If I change to 9.12.4 then FirePower version need to change? If need then what will be the version of firepower?

Friend I changed the IOS to 9.12.4.10 yesterday. Today same issue has raised again. What can I do now?

 

show interface for both ASA and both INside and OUTside, please share this 


Primary-FW/act# sh inter
Primary-FW/act# sh interface
Interface GigabitEthernet0/0 "outside", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Input flow control is unsupported, output flow control is off
Description: Connect to BANet_Firewall
MAC address 2c33.1151.3fd8, MTU 1500
IP address 10.11.244.4, subnet mask 255.255.255.248
488684 packets input, 102340537 bytes, 0 no buffer
Received 652 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
594578 packets output, 289051881 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (494/453)
output queue (blocks free curr/low): hardware (511/493)
Traffic Statistics for "outside":
488623 packets input, 93497180 bytes
594578 packets output, 278341147 bytes
647 packets dropped
1 minute input rate 68 pkts/sec, 13027 bytes/sec
1 minute output rate 85 pkts/sec, 42799 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 60 pkts/sec, 11710 bytes/sec
5 minute output rate 72 pkts/sec, 32452 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface GigabitEthernet0/1 "", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Active member of Redundant1
MAC address 2c33.1151.b5d9, MTU not set
IP address unassigned
594608 packets input, 289213405 bytes, 0 no buffer
Received 3 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
488008 packets output, 102113435 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (485/450)
output queue (blocks free curr/low): hardware (511/499)
Interface GigabitEthernet0/2 "FOLink", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Description: LAN/STATE Failover Interface
MAC address 2c33.1151.b5dd, MTU 1500
IP address 192.168.99.2, subnet mask 255.255.255.252
16510 packets input, 4869468 bytes, 0 no buffer
Received 1 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
147909 packets output, 119278044 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 1 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (502/456)
output queue (blocks free curr/low): hardware (463/425)
Traffic Statistics for "FOLink":
16466 packets input, 4498118 bytes
147848 packets output, 116608526 bytes
0 packets dropped
1 minute input rate 1 pkts/sec, 222 bytes/sec
1 minute output rate 18 pkts/sec, 14767 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 1 pkts/sec, 266 bytes/sec
5 minute output rate 19 pkts/sec, 15303 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface GigabitEthernet0/3 "", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
Standby member of Redundant1
MAC address 2c33.1151.b5da, MTU not set
IP address unassigned
13 packets input, 4542 bytes, 0 no buffer
Received 13 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
13 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (498/498)
output queue (blocks free curr/low): hardware (511/511)
Interface GigabitEthernet0/4 "", is administratively down, line protocol is down
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex, Auto-Speed
Input flow control is unsupported, output flow control is off
Available but not configured via nameif
MAC address 2c33.1151.b5de, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (511/511)
output queue (blocks free curr/low): hardware (511/511)
Interface GigabitEthernet0/5 "", is administratively down, line protocol is down
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex, Auto-Speed
Input flow control is unsupported, output flow control is off
Available but not configured via nameif
MAC address 2c33.1151.b5db, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (511/511)
output queue (blocks free curr/low): hardware (511/511)
Interface Management0/0 "management", is up, line protocol is up
Hardware is en_vtun rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address 2c33.1151.3fd4, MTU 1500
IP address 192.168.10.1, subnet mask 255.255.255.0
446162 packets input, 231257963 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
483664 packets output, 37871618 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
1 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (0/0)
output queue (blocks free curr/low): hardware (0/0)
Traffic Statistics for "management":
446131 packets input, 224807865 bytes
483664 packets output, 31100322 bytes
1573 packets dropped
1 minute input rate 6 pkts/sec, 266 bytes/sec
1 minute output rate 13 pkts/sec, 3323 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 51 pkts/sec, 24874 bytes/sec
5 minute output rate 57 pkts/sec, 4461 bytes/sec
5 minute drop rate, 0 pkts/sec
Management-only interface. Blocked 0 through-the-device packets

Interface Redundant1 "inside", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address 2c33.1151.3fd5, MTU 1500
IP address 192.168.100.1, subnet mask 255.255.255.248
594988 packets input, 289301256 bytes, 0 no buffer
Received 16 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
13 L2 decode drops
488358 packets output, 102191268 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (966/450)
output queue (blocks free curr/low): hardware (1022/499)
Traffic Statistics for "inside":
592377 packets input, 274975239 bytes
488358 packets output, 93400651 bytes
2 packets dropped
1 minute input rate 84 pkts/sec, 42625 bytes/sec
1 minute output rate 68 pkts/sec, 12999 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 72 pkts/sec, 32191 bytes/sec
5 minute output rate 60 pkts/sec, 11681 bytes/sec
5 minute drop rate, 0 pkts/sec
Redundancy Information:
Member GigabitEthernet0/1(Active), GigabitEthernet0/3
Last switchover at 10:20:24 UTC Feb 7 2023

you need provide more information and logs

show run

network diagram

what logs you see?

hang means it totally stop working?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Bro you can check the logs.

Yes Hang means, Totally stops no working at all.

you need provide more information and logs  ( your log empty)

show run

network diagram

what logs you see?

hang means it totally stop working?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

what logs you see?

Ans:  Nothing log I can see.

hang means it totally stop working?

Ans: yes. need to reload again. then it has up for some hours and then again hanged.

 

I check the interface, it OK there is no problem. 
but I see some thing I dont see before in config. 
you config one link for failover 
you also config link for status
then you config IP for status not for failover 
please remove this 

failover link FOLink GigabitEthernet0/2

and check. 

also I see HSRP before the ASA HA
so 
are HSRP point to Active ASA ?
are ASA point to VIP of HSRP ?
are you sure that there is L2 between ASA inside ?
 

No HSRP between Firewalls. This is ASA failover configuration.

are you sure that there is L2 between ASA inside ?

Yes.

Review Cisco Networking for a $25 gift card