10-21-2018 11:36 AM - edited 03-12-2019 07:02 AM
Hello:
I am new to Cisco, pardon my little knowledge. I've acquired an ASA 5506-X with FIREPOWER and I've asked a friend to help configure it. We're not able to enter "enable-mode" when we connect to the console. We are using the USB port on the device. I thought it was related to licensing but I got a license and all the security features show enabled on the GUI. How do I access "enable-mode" so that I can run some configuration commands from the prompt?
Thanks,
Mwamba
Solved! Go to Solution.
10-22-2018 05:06 AM
Most likely you have the Firepower Threat Defense (FTD) image. With FTD you must do all configuration (except for initial setup and a VERY limited set of commands) from the GUI - either the on-box Firepower Device Manager or a remote Firepower Management Center.
10-21-2018 07:19 PM - edited 10-21-2018 07:20 PM
If it's a fresh image, the enable password is blank. You should be able to type enable, hit enter and when it asks for a password, hit enter again. Once you're in enable mode, go into global configuration mode with config t then issue enable secret <whatever password you want to use>. Then either type exit or hit Ctrl-Z to get out of configuration mode.
FYI, the "secret" part of the command encrypts the password so it's not just sitting there in plaintext when someone runs show running-config.
Once you get out of enable and re-enter with the newly established password, you should wr mem
10-21-2018 08:26 PM
10-22-2018 05:06 AM
Most likely you have the Firepower Threat Defense (FTD) image. With FTD you must do all configuration (except for initial setup and a VERY limited set of commands) from the GUI - either the on-box Firepower Device Manager or a remote Firepower Management Center.
10-22-2018 05:13 AM
Now that makes sense! And yes, I have FTD on this device. I understand that you mean this is by design. Is there a way to go around it? I must mention that at the moment I am not using the FTD features (I havent bought licenses for them - still debating whether I should or shouldn't). Can I replace this image with something else? And how do I do so?
Thanks.
10-22-2018 05:21 AM
Yes you can replace the FTD image with a "classic" ASA image. You will need entitlement to download the ASA and aSDM software (generally implying a support contract).
Instructions for the reimage can be found here:
10-22-2018 05:27 AM
Hi Marvin,
Is there a way I can setup ASDM on this device as it is (with the FTD image)? Tried to find some resource online without success.
Once again, thank you for your help.
Mwamba
10-22-2018 05:32 AM
No that's not possible. ASDM cannot manage any device running FTD in any way whatsoever.
FTD is managed via the on-box GUI (Firepower Device Manager). You can manage it remotely using a Firepower Management Center server. The cloud-based Cisco Defense Orchestrator also provides some management capabilities. Only the first method can be done without separate licensing.
10-22-2018 05:47 AM
10-22-2018 05:48 AM
You're welcome.
Please mark the helpful replies as such to encourage participation in the community.
10-26-2018 10:45 AM
HI Marvin,
I'm in a very similar situation with the 5506, FTD unit. Brand new unit with older firmware, bought a license and have the latest firmware downloaded, but locked completely out from the ASA5506- username and password doesn't accept, terminal client doesn't communicate(putty and hyper-terminal), and when plugging the USB into the laptop- it tries to load, errors out saying nothing to load. Have tried several laptops, same result. Cisco USB console connection shows in device manager, but no drivers, etc..Given that the only configuration method is through a browser(Thank you for the post) any ideas how to get back in? Is there a super secret thing that can be typed in to get back in? magical button to push? FYI: reset doesn't do anything to help this.
Thanks in advance,
Ron
10-27-2018 10:26 PM
Do you get a DHCP-assigned address and see the FDM GUI at all when you connect via Ethernet to the ASA?
If you have a USB-serial console cable but no drivers then you need to download and install the Cisco USB console driver.
https://software.cisco.com/download/home/282867573/type/282855122/release/3.1
With that installed you should be able to get a command prompt and follow the quick start guide:
10-28-2018 12:32 PM
Hi Marvin,
Yes, I get the GUI through the browser- login page. Can't login- doesn't accept the user/password- tried every combination, admin/Admin123 and the ones I set up. I followed a quick setup guide, through the browser, upon receiving the unit over a month ago- locked out since. The guide you linked below appears similar- but not the same as what I used. Maybe the guide I used wasn't the correct one....?
That led me to go to USB CLI. I ended up hunting for the USB drivers and downloaded a USB console driver from a Cisco Router 22xx page(after i replied to your post found in a document Windows has to use a Cisco downloadable USB driver) and that appears to have worked this past weekend. Connecting by way of Putty and serial comms, but this doesn't seem to provide access for changes. >Configure command is not recognized....>Configure password isn't accessible either through this type of comms or my access level.
I'll give SSH a try(document mentions to use SSH).
Thanks,
Ron
10-28-2018 10:02 PM
Please connect the console and turn on session logging in putty?
Then power cycle the unit. Share the resulting output.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide