cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1231
Views
5
Helpful
14
Replies

HOW TO RUN CISCO ASA FIREPOWER SERVICE

edwincharles
Level 1
Level 1

Dears ,

Need help with installing and configuring the CISCO ASA FIREPOWER SERVICE in ASA5506-X

14 Replies 14

Ajay Saini
Level 7
Level 7

Assuming that you have required license, please follow the below link for initial install of firepower services on ASA. It includes step by step instructions:

http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html

Let me know if that helps.

-

AJ

Thanks Ajay

but have issue with accessing the asa with ASDM, without firepower can access

 when providing the ip for asa firepower asdm gives error

I've found ASDM 7.7(1.x) to be buggy that way.

Try downgrading the ASDM to 7.6(2.150) and then reconnect.

Hi marvin,

I downgraded the ASDM to 7.6(2.150) , but still the same error as attached

Have you tried clearing your Java temporary files or accessing from a different computer?

You might also try the Java Web Start launcher as an alternative.

You may also be hitting this bug:

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd12493

There is a brand new ASDM release 7.8(1) that fixes the bug. It can be found here:

https://software.cisco.com/download/release.html?mdfid=286283326&flowid=77251&softwareid=280775064&release=7.8.1&relind=AVAILABLE&rellifecycle=&reltype=latest

hello Marvin,

I have a doubt that asa firepower service as issue with asdm, as if connected without firepower , the ASA can be configured in ASDM

Oh so are you saying that only with FirePOWER module you get that error?

If so, please check the configuration and share output of:

show module sfr detail

...as ASDM uses that address information when connecting to the module. Your ASDM client must be able to reach the sfr module's configured IP address via tcp/443.

ciscoasa# sh module sfr detail
Getting details from the Service Module, please wait...
Card Type:          FirePOWER Services Software Module
Model:              ASA5506
Hardware version:   N/A
Serial Number:      JAD195007QY
Firmware version:   N/A
Software version:   5.4.1-211
MAC Address Range:  00fe.c8c4.3cab to 00fe.c8c4.3cab
App. name:          ASA FirePOWER
App. Status:        Up
App. Status Desc:   Normal Operation
App. version:       5.4.1-211
Data Plane Status:  Up
Console session:    Ready
Status:             Up
DC addr:            No DC Configured
Mgmt IP addr:       10.10.11.250
Mgmt Network mask:  255.255.255.0
Mgmt Gateway:       10.10.11.254
Mgmt web ports:     443
Mgmt TLS enabled:   true

I was able to setup wizard for the asa using ASDM, after I configure the ip for firepower services , then I open the ASDM I get the error

OK - I understand the problem better now.

I see you are running FirePOWER 5.4.1-211 and ASA 9.5(1). The compatibility guide says you shald have ASA 9.5(1.5) +. Reference:

http://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html

In the 9.5 train, 9.5(3.9) is currently the latest and recommended release for that train. Reference:

https://software.cisco.com/download/release.html?mdfid=286283326&flowid=77251&softwareid=280775065&release=9.8.1&relind=AVAILABLE&rellifecycle=&reltype=latest

Also, your version 5.4.1-211 is the first release of FirePOWER for the ASA 5506-X. I would suggest re-imaging it to a current release like 6.2. There have been a lot of bug fixes  and improvements in the past couple of years between those two versions.

thanks marvin, but is there way to get the 9.5(3.9), as we don't have smartnet to download

Sorry but a support contract is required to download new software versions. 

If you bought FirePOWER licenses you should have access to those FirePOWER images. 

dear marvin,

downgraded the java to 8u41 it worked

Review Cisco Networking for a $25 gift card