12-26-2019 01:51 AM - edited 02-21-2020 09:47 AM
Hello,
this is the 5th time that our ASA Firepower has restarted without any user intervention. It is in a critical location in our datacenter. Could you help me please?
Following the software and hardware specs :
Cisco Adaptive Security Appliance Software Version 9.8(1)
Firepower Extensible Operating System Version 2.2(2.53)
Device Manager Version 7.8(1)
Compiled on Wed 10-May-17 16:01 PDT by builders
System image file is "disk0:/fxos-lfbff-k8.2.2.2.53.SPA"
Config file at boot was "startup-config"
XXXXXXXXXXXXX up 1 hour 19 mins
SSP Slot Number: 1
Hardware: FPR4K-SM-24, 116806 MB RAM, CPU Xeon E5 series 2194 MHz, 2 CPUs (48 cores)
Encryption hardware device : Cisco FP Crypto on-board accelerator (revision 0x1)
Boot microcode : CN35x-MC-Boot-0001
SSL/IKE microcode : CNN35x-MC-SSL-0014
IPSec microcode : CNN35x-MC-IPSEC-0005
Number of accelerators: 2
Thanks in advance
12-26-2019 05:41 AM
Is this device facing internet edge FW? if so check some bugs reported, people have experienced too, after upgrade things look ok.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftd
12-26-2019 05:59 AM
please upgrade the software. the version you running cisco publish vulnerability Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability.
12-26-2019 07:12 AM
Thank you Sheraz, I will do the upgrade during maintenance operation and do an update.
The network infrastructure is freezed during in December.
Appreciate your response
12-26-2019 10:23 AM
Management should allow break-fix I guess, since you may face notice reboots quite often so you have service outage may occur.
12-26-2019 01:20 PM - edited 12-26-2019 01:21 PM
That the completely make sense. due to holidays change freeze are in place and this is quite understandable. however, business should untersatnad the gravity of this complex situation. could you try emergency change control? chances are less as most of the staff / decision maker are on holidays. This is a tough call for you though i can completely understand this.
12-27-2019 01:46 AM
completely agree with you. the decision-making will be for after the holidays for sure but at each restart (around 10 minutes), many VPNs fall and impact on the production and the finances of the company
12-27-2019 02:54 AM
yes, this what i was mentioned earlier, Business need to take decision, upgrade downtime is less cost than the Business Loss.
If i were you, i pickup the phone and make an call to the authorisation person to process this upgrade.
Since you are proactively informed (so blame is not yours) - if not it will come as circle to your desk.
12-27-2019 04:25 AM
you just need to informed your line manager/head of IT on this situation let him know what are the options available. you need to get out of this situation. before everyone point finger on you. and you become an easy meat.
as long as you escalated this to your higher authorities are you safe if this get back to you than you in postion to say i have followed the protocols and decision maker delayed it. safe your self before this become a business P1.
Regards,
12-27-2019 05:08 AM
thanks for your advice!
Already done, I'm waiting for their approval. I won't have holliday at all :)
I will make you aware on what is done and if it will resolve or not my issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide