cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1241
Views
0
Helpful
2
Replies

FPR2110 with ASA image upgrade

m.mojas
Level 1
Level 1

Hello!

I upgraded 2110 with ASA image using this procedure (from 9.8.2 to 9.9.1.4):

Cisco ASA Upgrade Guide - Upgrade the ASA Appliance or ASAv [Cisco ASA 5500-X Series Firewalls] - Cisco

During upgrade this were the logs (some logs are ommited):

INFO: Verifying signature for cisco-asa.9.9.1.4 ...

INFO: Verifying signature for cisco-asa.9.9.1.4 ... success

Cisco ASA: CMD=-bootup, CSP-ID=cisco-asa.9.9.1.4__asa_001_JMX2201Y0FJBRPHYP1, FLAG=''

Cisco ASA booting up ...

Cisco ASA started successfully.

.....

Mar 28 11:22:22 FPR2110-1 FPRM: <<%%FPRM-2-DEFAULT_INFRA_BUNDLE_INSTALL_APP_FAILURE>> [F1313][critical][default-infra-bundle-install-app-failure][sys/fw-system] Software Pack upgrade failure

...

Cisco Adaptive Security Appliance Software Version 9.9(1)4

  ****************************** Warning *******************************

  This product contains cryptographic features and is

  subject to United States and local country laws

  governing, import, export, transfer, and use.

  Delivery of Cisco cryptographic products does not

  imply third-party authority to import, export,

  distribute, or use encryption. Importers, exporters,

  distributors and users are responsible for compliance

  with U.S. and local country laws. By using this

  product you agree to comply with applicable laws and

  regulations. If you are unable to comply with U.S.

  and local laws, return the enclosed items immediately.

  A summary of U.S. laws governing Cisco cryptographic

  products may be found at:

  http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

  If you require further assistance please contact us by

  sending email to export@cisco.com.

  ******************************* Warning *******************************

Cisco Adaptive Security Appliance Software, version 9.9

Copyright (c) 1996-2018 by Cisco Systems, Inc.

For licenses and notices for open source software used in this product, please visit

http://www.cisco.com/go/asa-opensource

                Restricted Rights Legend

Use, duplication, or disclosure by the Government is

subject to restrictions as set forth in subparagraph

(c) of the Commercial Computer Software - Restricted

Rights clause at FAR sec. 52.227-19 and subparagraph

(c) (1) (ii) of the Rights in Technical Data and Computer

Software clause at DFARS sec. 252.227-7013.

                Cisco Systems, Inc.

                170 West Tasman Drive

                San Jose, California 95134-1706

No such file or directoryReading from flash...

!!.WARNING: This command will not take effect until interface 'outside' has been assigned an IPv4 address

*** Output from config line 150, "ip-client outside"

..

Cryptochecksum (unchanged): aa648a67 ca03c9d7 ad4750d4 3bb85f4b

INFO: Power-On Self-Test in process.

.............

INFO: Power-On Self-Test complete.

INFO: Starting SW-DRBG health test...

INFO: SW-DRBG health test passed.

INFO: Starting SW-DRBG health test...

INFO: SW-DRBG health test passed.

After upgrade I have situation in which ASA booted with 9.9.1.4 but FXOS says that update failed.

FPR2110-1 /ssa/slot/app-instance # show

Application Instance:

    Application Name Admin State Operational State Running Version Startup Version

    ---------------- ----------- ----------------- --------------- ---------------

    asa              Enabled    Update Failed     9.8.2           9.9.1.4

FPR2110-1# sh ver det

Bootloader-Vers: 1.0.04

System Running-Vers: 2.3(1.54)

Npu Running-Vers: 2.3(1.54)

Service Manager Running-Vers: 2.3(1.54)

Package-Vers: 9.9.1.4

Listing from show version on ASA:

UCB-FW1-ASA# sh ver

Cisco Adaptive Security Appliance Software Version 9.9(1)4

Firepower Extensible Operating System Version 2.3(1.54)

Device Manager Version 7.9(1)

Did anyone have this situation?


Thank you and best regards,

Maja

1 Accepted Solution

Accepted Solutions

goransx
Cisco Employee
Cisco Employee

Hi Maja,

this issue is best addressed by opening a TAC case.

Thanks,

Goran

View solution in original post

2 Replies 2

goransx
Cisco Employee
Cisco Employee

Hi Maja,

this issue is best addressed by opening a TAC case.

Thanks,

Goran

Hi!

Thank you for your answer. Re-image helped. I used 9.9.2 for re-image and after that device is up and it is running ok.

I think that something is wrong with version 9.9.1.4. I upgraded second firewall directly to 9.9.2 without any problems.


Regards,

Maja

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: