cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1277
Views
15
Helpful
11
Replies

Firepower on 5506

marcio.tormente
Level 4
Level 4

Dear friends!

I installed a 5506x on my company and I decide to upgrade the firepower software to version 6.0, but was impossible to migrate straight version 6.0, then I made the upgrade to version 5.4.1.3-26, after that I trayed to upgrade to version 6.0, didn´t work.

Now I´m still with the version 5.4.1.3-26 and when I try to access the firewall using ASDM, the error msg appear, as you can see in attach file, and I can access the firepower functions anymore, only status.

The IP 192.168.13.251 is alredy configured on firepower.

Anyone knows what is the cause of this problem?

Thanks

Marcio 

1 Accepted Solution

Accepted Solutions

Marcio,

The failed upgrade may have corrupted some of the necessary files. You may need to reimage the software module.

If you have Smartnet open a TAC case. (You should have Smartnet or else you wouldn't have been entitled to upgrade - right?)

Otherwise the process is pretty much laid out here:

http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc7

You should uninstall the current module first (explained earlier in the same document).

Using this approach you can start with 6.0 from a brand new install.

.

View solution in original post

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

Please log into the ASA command line and share the output of "show module sfr detail".

It will look something like this:

marvin-5506# show module sfr detail
Getting details from the Service Module, please wait...
Card Type: FirePOWER Services Software Module
Model: ASA5506
Hardware version: N/A
Serial Number: JAD191200TM
Firmware version: N/A
Software version: 6.0.0-1005
MAC Address Range: b0aa.777c.adf1 to b0aa.777c.adf1
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 6.0.0-1005
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr: No DC Configured
Mgmt IP addr: 192.168.1.254
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 192.168.1.1
Mgmt web ports: 443
Mgmt TLS enabled: true
marvin-5506#

Hello Marvin,

Follow the command result:

likasa# sh module sfr det

likasa# sh module sfr details

Getting details from the Service Module, please wait...

 

Card Type:          FirePOWER Services Software Module

Model:              ASA5506

Hardware version:   N/A

Serial Number:      JAD1922018J

Firmware version:   N/A

Software version:   5.4.1.3-26

MAC Address Range:  e865.49e3.f1e2 to e865.49e3.f1e2

App. name:          ASA FirePOWER

App. Status:        Up

App. Status Desc:   Normal Operation

App. version:       5.4.1.3-26

Data Plane Status:  Up

Console session:    Ready

Status:             Up

DC addr:            No DC Configured

Mgmt IP addr:       192.168.13.251

Mgmt Network mask:  255.255.255.0

Mgmt Gateway:       192.168.13.254

Mgmt web ports:     443

Mgmt TLS enabled:   true

Thanks

From the PC that you run ASDM on, can you ping the sfr module at 192.168.13.251?

If so, can you also ssh into it? (admin / Sourcefire are the default credentials)

Yes, I can ping 192.168.13.251, but is not possible to access the devise from this IP.

I alredy change the credentials.

I use to access the devide before the Upgrade, after that, I can access only ASA (ASDM/SSH), the firepower features don't appear on ASDM, only status.

Marcio,

The failed upgrade may have corrupted some of the necessary files. You may need to reimage the software module.

If you have Smartnet open a TAC case. (You should have Smartnet or else you wouldn't have been entitled to upgrade - right?)

Otherwise the process is pretty much laid out here:

http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc7

You should uninstall the current module first (explained earlier in the same document).

Using this approach you can start with 6.0 from a brand new install.

.

Marvin,

I´m trying to upgrate to other version, 5.4.1.5, but the system say that I don´t have enough space, this is very stange, because I saw your information and you have the version 6.0 in the same 5506, and this version is one after 5.4.1.5.

likasa# sh disk0
--#-- --length-- -----date/time------ path
100 69454656 May 27 2015 06:39:24 asa941-lfbff-k8.SPA
101 33 Jan 20 2016 19:33:10 .boot_string
11 4096 May 27 2015 06:42:38 log
19 4096 May 27 2015 06:43:44 crypto_archive
20 4096 May 27 2015 06:44:02 coredumpinfo
21 59 May 27 2015 06:44:02 coredumpinfo/coredump.cfg
102 24810876 Jun 26 2015 13:01:48 asdm-743.bin
103 27951104 Oct 22 2015 13:51:54 anyconnect-win-4.2.00096-pre-deploy-k9.iso
104 18989375 Oct 22 2015 13:59:06 anyconnect-win-4.2.00096-k9.pkg
105 204800 Jan 01 1980 00:00:00 FSCK0000.REC
106 4096 Jan 01 1980 00:00:00 FSCK0001.REC

7859437568 bytes total (4494483456 bytes free)

The failed upgrade probably left files on the storage system that the sfr module uses. You'd need to reimage or else enlist TAC help to clean that out.

You can see it from the module by sessioning into the sfr cli from the ASA cli, moving into expert mode (Linux shell) and then checking space there.

marvin-5506# session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

Sourcefire3D login: admin
Password:
Last login: Tue Jan 26 13:35:30 UTC 2016 on ttyS1

Copyright 2004-2015, Cisco and/or its affiliates. All rights reserved.
Cisco is a registered trademark of Cisco Systems, Inc.
All other trademarks are property of their respective owners
Cisco Fire Linux OS v6.0.0 (build 258)
Cisco ASA5506 v6.0.0 (build 1005)
> expert
admin@Sourcefire3D:~$ df -m
Filesystem 1M-blocks Used Available Use% Mounted on
/dev/root 3755 785 2779 23% /
devtmpfs 1112 1 1112 1% /dev
/dev/sda1 99 35 60 37% /boot
/dev/vda7 38371 11189 25233 31% /var
none 1113 1 1113 1% /dev/shm
tmpfs 1113 0 1113 0% /dev/cgroups
admin@Sourcefire3D:~$

Marvin, I made the re-image twice for version 6.0, but, after finish, I can´t acces the SFR mode.

The prompt remain like this:

likasa# session sfr con
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

the status of module is: 

likasa# sh module

Mod Card Type Model Serial No.
---- -------------------------------------------- ------------------ -----------
1 ASA 5506-X with FirePOWER services, 8GE, AC, ASA5506 JAD1922018J
sfr Unknown N/A JAD1922018J

Mod MAC Address Range Hw Version Fw Version Sw Version
---- --------------------------------- ------------ ------------ ---------------
1 e865.49e3.f1e3 to e865.49e3.f1ec 1.0 1.1.3 9.4(1)
sfr e865.49e3.f1e2 to e865.49e3.f1e2 N/A N/A

Mod SSM Application Name Status SSM Application Version
---- ------------------------------ ---------------- --------------------------

Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
1 Up Sys Not Applicable
sfr Recover Not Applicable

How can I see the all images file? in the disk0: there is only one .img, the version 5.4.1.3 is .sh, I´m afraid  of boot from this image .sh and stop everything.

Ps. The image .sh I can´t see on the sh disk0

What commands did you run to reimage?

The correct sequence would be to get copies of the boot and sys images here:

https://software.cisco.com/download/release.html?mdfid=286283326&softwareid=286277393&os=&release=6.0.0&relind=AVAILABLE&rellifecycle=&reltype=latest&i=!pp

Then copy the boot image onto the ASA disk0: and run the 3 commands below as described in the guide I linked earlier. Then go into the module run setup and then load the sys image (4th command below, substituting your http or ftp server as the source of the sys file).

sw-module module sfr uninstall
sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.0.0-1005.img
sw-module module sfr recover boot
system install [noconfirm] url

Hello Marvin,

I did exactly as in the link that you sent to me before, but for some reason that I have no idea why, insted of take some minutes after process the pkg file, they tooke hours.

Now, everything is working, the version is 6.0, is UP and all Firepower´s tab is showing.

Thanks for all supporte.

Glad to know it is working for you now.

I'm happy to help - thanks for the rating Marcio.

Review Cisco Networking for a $25 gift card