01-05-2022 02:00 AM
I am re-imaging two ASA-5545Xs with a vFMC from 6.3.0.5 to 6.6.5. I recovered the module and installed the boot image file without any issues however, when trying to download the firepower software package via FTP, it repeatedly fails at random percentages. The module can ping the FTP device and default gateway ruling that out. I added an anonymous user to the FileZilla server so that a UN and PW was not needed and tried http. I move the file to several different locations including my C drive and it made no difference.
It will fail anywhere from 27.1 - 60% with no explanation. I have re-imaged our modules twice in the past to start fresh rather then upgrade and never ran into this issue. The errors I see from the sfr console and FileZilla are below as well as the cmd I am using.
Module Status
Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
0 Up Sys Not Applicable
ips Unresponsive Not Applicable
cxsc Unresponsive Not Applicable
sfr Recover Not Applicable
FileZilla Server Error
(000129)1/5/2022 3:52:28 AM - anonymous (10.199.1.104)> 426 Connection closed; aborted transfer of "/asasfr-sys-6.6.5-81.pkg"
(000129)1/5/2022 3:52:29 AM - anonymous (10.199.1.104)> disconnected.
SFR Console Error
Package download failed. Please try again. If the problem persists, check if server is unreliable,or move the file to a different server or try different protocol.
Upgrade aborted.
ASASFR1-boot>
Any ideas?
Solved! Go to Solution.
01-05-2022 07:01 AM
Yeah, I tried it both ways via FTP. Ironically it just now took the image as I've been repeatedly trying and nothing has changed. I have another ASA to perform this on and will let everyone know how that goes. I'll also open a case with TAC to see if this is a known issue.
01-05-2022 03:45 AM
01-05-2022 03:59 AM
Yes, 6.6 is the last supported version. This is also being done so we can migrate to 2130's down the road.
01-05-2022 06:41 AM
Can you confirm that you used the associated prerequisite boot image "asasfr-5500x-boot-6.6.5-2.img"?
I've only ever done it using authenticated ftp but that shouldn't make a difference.
01-05-2022 06:46 AM
Correct, that is the boot image I am using. Commands I used below.
sw-module module sfr recover configure image flash:/asasfr-5500x-boot-6.6.5-2.img
sw-module module sfr recover boot
01-05-2022 06:55 AM
OK, so that's correct. Have you tried it as an authenticated ftp user?
If that fails as well, I'd see what TAC has to say about the issue.
I assume you are running a compatible ASA version - most recent ones are compatible with Firepower service module 6.6.x:
01-05-2022 07:01 AM
Yeah, I tried it both ways via FTP. Ironically it just now took the image as I've been repeatedly trying and nothing has changed. I have another ASA to perform this on and will let everyone know how that goes. I'll also open a case with TAC to see if this is a known issue.
01-06-2022 07:52 AM
Standby ASA had no issues with the image upload. Thank you all for pitching in.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide