03-25-2019 05:21 AM - edited 02-21-2020 08:58 AM
Hi
I have few ASA's in my network for which when I try to do session SFR
Iam getting the message :
"Opening command session with module sfr.
Module sfr did not respond to session request."
What could be the reasons for getting the above messages ?
Has the module gone faulty and require any HW replacemet ?
Or
How can I recover this SFR module, can anyone pls help.
Thanks in Advance
KRSC
07-08-2021 08:50 AM
Yes it will work. The compatibility matrix I linked earlier confirms it. But I would not recommend going with the bare minimum release.
The recommended ASA releases 9.12x or 9.14x are fully compatible with Firepower 6.2.2. and, should you decide to move to the recommended Firepower 6.6.4 later, still remain compatible.
Using a recommended ASA release puts you on a better security footing as they are fully patched for current known vulnerabilities.
07-09-2021 01:02 AM
Hi
since I have my 6.2.2 FMC which already supervises a 6.2.2 firepower so I cannot go directly to 6.4.0 for the FMC. For the moment, the need is to make the two firepower work first. to version 6.2.2 afterwards I can go to 6.4. I just have one last question is there an intermediate version between version 9.2 and version 9.14 or I can go directly to version 9.14
07-09-2021 01:41 AM
Your ASA can be upgraded directly from 9.2 to 9.14.
Just be careful of your site-site VPNs (if you have any configured). Some defaults have changed and you may need to specify some things explicitly for the VPNs to come back up.
07-09-2021 01:45 AM
Thanks very much i will try after i come back to you for the results.
07-13-2021 12:11 AM
Hello
I have another problem.I have shutdown the ASA and restart it then the ASDM is no longer reachable.I have done any change help please.
07-13-2021 05:24 AM
Is it a single ASA or an HA pair?
Check your asdm image statement in the running-config vs. what asdm bin file is present on disk0.
07-13-2021 09:47 AM
07-13-2021 10:04 AM
Did you check that the specified ASDM image "asdm-7221.bin" is present on disk0? ("dir" command)
If it is, please also check the strong crypto license is also present:
show activation-key | i AES
07-13-2021 11:55 AM
he is the show version output
Cisco Adaptive Security Appliance Software Version 9.8(2)
Firepower Extensible Operating System Version 2.2(2.52)
Compiled on Sun 27-Aug-17 13:13 PDT by builders
System image file is "disk0:/asa982-smp-k8.bin"
Config file at boot was "startup-config"
GOUYGUI up 20 hours 16 mins
Hardware: ASA5525, 8192 MB RAM, CPU Lynnfield 2393 MHz, 1 CPU (4 cores)
ASA: 4191 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB
Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
Boot microcode : CNPx-MC-BOOT-2.00
SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005
IPSec microcode : CNPx-MC-IPSEC-MAIN-0026
Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4
0: Int: Internal-Data0/0 : address is 2c4f.520a.703c, irq 11
1: Ext: GigabitEthernet0/0 : address is 2c4f.520a.7041, irq 5
2: Ext: GigabitEthernet0/1 : address is 2c4f.520a.703d, irq 5
3: Ext: GigabitEthernet0/2 : address is 2c4f.520a.7042, irq 10
4: Ext: GigabitEthernet0/3 : address is 2c4f.520a.703e, irq 10
5: Ext: GigabitEthernet0/4 : address is 2c4f.520a.7043, irq 5
6: Ext: GigabitEthernet0/5 : address is 2c4f.520a.703f, irq 5
7: Ext: GigabitEthernet0/6 : address is 2c4f.520a.7044, irq 10
8: Ext: GigabitEthernet0/7 : address is 2c4f.520a.7040, irq 10
9: Int: Internal-Data0/1 : address is 0000.0001.0002, irq 0
10: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0
11: Int: Internal-Data0/2 : address is 0000.0001.0003, irq 0
12: Ext: Management0/0 : address is 2c4f.520a.703c, irq 0
13: Int: Internal-Data0/3 : address is 0000.0100.0001, irq 0
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 200 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
Carrier : Disabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 750 perpetual
Total VPN Peers : 750 perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Shared License : Disabled perpetual
Total TLS Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
IPS Module : Disabled perpetual
Cluster : Enabled perpetual
Cluster Members : 2 perpetual
This platform has an ASA5525 VPN Premium license.
Serial Number: FCH231473VU
Running Permanent Activation Key: 0x1425e977 0xf89f193b 0x51422da8 0xe3c4d464 0x4415c69d
Configuration register is 0x1
Image type : Release
Key version : A
i don't see the device manager version in the output.Before if i make show version it appear.for the licence i think it ust be the source of my problem if i do a show run i don't see it
07-14-2021 05:24 AM
The ASDM version will not show up in "show version". "show run asdm" will show you the ASDM version that's configured. As I noted earlier, cross reference that to "dir" to make sure the specified file is on the ASA's disk0.
07-14-2021 04:25 AM
Hello
I want to copy ASA 9.2 config to ASA 9.8 version .Will VPN work if i do that.
07-14-2021 05:24 AM
@seckka21 wrote:
Hello
I want to copy ASA 9.2 config to ASA 9.8 version .Will VPN work if i do that.
Yes.
07-15-2021 09:03 AM
07-15-2021 07:46 PM
Already answered in your other thread.
Please do not post the same question in multiple discussions.
08-04-2021 01:52 PM
hi
Finally i have a solution.
Instead of installing firepower version 6.2.2 i try 6.2.3 and it works .Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide