SFR is in Recovery Mode

Dear all, 

i have a situation as mentioned below.

  • I have two ASA 5525 in Active-Standby mode
  • I have installed firesight Successfully.
  • Situation is when i would like to go "Session sfr" for cli mode. it gives me a syslog massage which is "sfr is not responding the for this session". moreover when i typed "sh module" in cli mode i found that SFR is in "Recovery" mode. after that i stopped the Recovery mode and try to reboot the sfr. but it remains in Recovery mode.

need suggestion.

Marvin Rhoads
Hall of Fame Guru

You may need to re-image the sfr software module. the following will accomplish that:

ciscoasa# sw-module module sfr recover configure image disk0:/<boot file name that you have loaded onto ASA flash - it is an "img" file type>
ciscoasa# sw-module module sfr recover boot

Once you've done that, you should be able to session into the module console and run "setup", followed by "system install". During this last step you will need the full "pkg" file available for upload onto the module.

Files can be found here for registered users with a support contract. (Expand the 5.4.0 section of the tree to see the smaller img and large pkg files.)

Hi Marvin Rhoads,

Thanks for your suggestion.

i am also thinking to re-image the SFR.

should i need to boot the PKG file after system install. because when i use commsnd "Sh disk0:/" i could not see the PKG file in the device.






Imaging and booting an sfr module is a 2-stage process.

The first stage is to bootstrap using the img file (~ 40 MB) that is on the ASA disk0 compact flash (or other accessible media such as the USB). Running setup after you've done that gets you to the point of the sfr module having enough functionality to be a client on the network and proceed to the next stage.

The second stage involves transferring the much larger pkg file (~420 MB) from an external source (such as an ftp server) onto the sfr module itself and then completing the installation.

Now problem is solved.

Now problem is solved.

You're welcome.

Please rate or mark question as answered if it helped.

Hi Guys,

I have 5525X and started the process of upgrade from




I uploaded the image to flash via browser and performed the following

sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.1.0-330.img
sw-module module sfr recover boot

Unfortunately now the module appears to be stuck in ---- ------------------ --------------------- -------------
 sfr Recover 

Any idea how i can get out of this, do i reload the ASA or the module?



how long have you waited they take ages? did you turn debugging on to see whats its doing?

debug module-boot 

Hi Peter,

Yes i waited a good 45mins and was still the same. So i have now rebooted the ASA itself and now i have a sfr module thats unresponsive. Going to try it again.

fw-01/pri/act# sw-module module sfr recover configure image disk0:/asasfr-$
fw-01/pri/act# sw-module module sfr recover boot

Module sfr will be recovered. This may erase all configuration and all data
on that device and attempt to download/install a new image for it. This may take
several minutes.

Recover module sfr? [confirm]
Recover issued for module sfr.
fw-01/pri/act# Mod-sfr 4> ***
Mod-sfr 5> *** EVENT: Creating the Disk Image...
Mod-sfr 6> *** TIME: 06:02:04 UTC Sep 12 2016
Mod-sfr 7> ***
Mod-sfr 8> ***
Mod-sfr 9> *** EVENT: The module is being recovered.
Mod-sfr 10> *** TIME: 06:02:04 UTC Sep 12 2016
Mod-sfr 11> ***

See attached log so far...... Still siting at sfr Recover, how long should it take, i was under the impression no longer than 10mins?


45 mins is not long enough Ive seen them take hours sometimes

Hi Peter,

Thanks again for your response its is appreciated. Are you saying it takes hours for the .img initial recover or the consequent upload of the .pkg?


The IMG is pretty quick - the PKG takes ages! leave debugging on! also I noticed on a 5.4. to 6.0 upgrade last week it asks you a question to which you need to respond yes halfway though!!

I watched one for an hour once, then drove an hour home, it didnt come up till 22:00 hours at night!


Hi Peter,

Thanks again. So i think my problem was the fact that although in recover mode waiting for .img i was then just thinking it was failed or stuck. I was also try

"session sfr" but then tried "session sfr console" and was then presented with the boot prompt :) Just performed the following

system install noconfirm

apparently the "noconfirm" then you dont get any prompts to confirm. Its downloaded from the ftp server and i have the debugging on (see attached), still now worried my session will time out, set ssh timeout to 60. I'll wait to see what happens now. Thanks for your help very much appreciated

Marvin is correct - Ive done a shedload of these now!


Hi All,


I am experiencing a problem. Please find the bellow console output.


asasfr-boot>system install
Package Detail
Description: Cisco ASA-SFR 6.2.0-362 System Install
Requires reboot: Yes

Do you want to continue with upgrade? [y]:
Warning: Please do not interrupt the process or turn off the system.
Doing so might leave system in unusable state.

Starting upgrade process ...
Populating new system image

Reboot is required to complete the upgrade. Press 'Enter' to reboot the system.

Broadcast message from root (ttyS1) (Sun Sep 17 00:24:56 2017):

The system is going down for reboot NOW!
Console session with module sfr terminated.
EXT-FWR-1# session sfr console
ERROR: Failed opening console session with module sfr. Module is in "Recover" state.
Please try again later.


EXT-FWR-1# show module

Mod Card Type Model Serial No.
---- -------------------------------------------- ------------------ -----------
0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525 FCH203XXX
ips Unknown N/A FCH203XXXX
cxsc Unknown N/A FCH20XXXX
sfr Unknown N/A FCH203XXXXX

Mod MAC Address Range Hw Version Fw Version Sw Version
---- --------------------------------- ------------ ------------ ---------------
0 006b.f1fa.149b to 006b.f1fa.14a4 3.0 2.1(9)8 9.2(2)4
ips 006b.f1fa.1499 to 006b.f1fa.1499 N/A N/A
cxsc 006b.f1fa.1499 to 006b.f1fa.1499 N/A N/A
sfr 006b.f1fa.1499 to 006b.f1fa.1499 N/A N/A

Mod SSM Application Name Status SSM Application Version
---- ------------------------------ ---------------- --------------------------
ips Unknown No Image Present Not Applicable
cxsc Unknown No Image Present Not Applicable

Mod Status Data Plane Status Compatibility
---- ------------------ --------------------- -------------
0 Up Sys Not Applicable
ips Unresponsive Not Applicable
cxsc Unresponsive Not Applicable
sfr Recover Not Applicable

Mod License Name License Status Time Remaining
---- -------------- --------------- ---------------
ips IPS Module Disabled perpetual



Already 4 hours passed. but it is showing in recover status.

Looking forward for good response.

