11-11-2018 11:23 PM - edited 03-12-2019 07:05 AM
Hello there!
I'm not ASA super hero engineer, and I need some help.
I have upgraded 4 ASA (three 5512 and one 5506) to a new version - 9.10(1). Until updating I didn't know, that it was with Firepower Service.
After upgrade Firepower doesn't work. I have read installation manual and upload new boot img to ASA - asasfr-5500x-boot-6.2.3-4.img.
ASA-111# show disk0: | i img 124 41846784 Jul 28 2017 10:37:08 asasfr-5500x-boot-6.2.0-2.img 133 42956800 Nov 07 2018 14:18:18 asasfr-5500x-boot-6.2.3-4.img
I see a SSD in system:
ASA-111# show inventory show_inventory_all -1744774352 Name: "Chassis", DESCR: "ASA 5512-X with SW, 6 GE Data, 1 GE Mgmt, AC" PID: ASA5512 , VID: V04 , SN: FGLblablabla Name: "Storage Device 1", DESCR: "Model Number: Micron_M600_MTFDDAK128MBF" PID: N/A , VID: N/A , SN: MSAblablabla
ASA-111# show module Mod Card Type Model Serial No. ---- -------------------------------------------- ------------------ ----------- 0 ASA 5512-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5512 FCH1blablabla ips Unknown N/A FCH1blablabla cxsc Unknown N/A FCH1blablabla sfr Unsupported Unsupported Mod MAC Address Range Hw Version Fw Version Sw Version ---- --------------------------------- ------------ ------------ --------------- 0 cc46.d6bf.a8b3 to cc46.d6bf.a8ba 1.0 2.1(9)8 9.10(1) ips cc46.d6bf.a8b1 to cc46.d6bf.a8b1 N/A N/A cxsc cc46.d6bf.a8b1 to cc46.d6bf.a8b1 N/A N/A Mod SSM Application Name Status SSM Application Version ---- ------------------------------ ---------------- -------------------------- ips Unknown No Image Present Not Applicable cxsc Unknown No Image Present Not Applicable Mod Status Data Plane Status Compatibility ---- ------------------ --------------------- ------------- 0 Up Sys Not Applicable ips Unresponsive Not Applicable cxsc Unresponsive Not Applicable Mod License Name License Status Time Remaining ---- -------------- --------------- --------------- ips IPS Module Disabled perpetual
ASA-111# show version Cisco Adaptive Security Appliance Software Version 9.10(1) Firepower Extensible Operating System Version 2.4(1.103) Device Manager Version 7.10(1) Compiled on Wed 24-Oct-18 16:31 PDT by builders System image file is "disk0:/asa9101-smp-k8.bin" Config file at boot was "startup-config" ASA-111 up 4 days 10 hours Hardware: ASA5512, 4096 MB RAM, CPU Clarkdale 2800 MHz, 1 CPU (2 cores) ASA: 1651 MB RAM, 1 CPU (1 core) Internal ATA Compact Flash, 4096MB
But when I try to install Firepower I got en error^
ASA-111# sw-module module sfr recover configure image disk0:/asasfr-5500x-boo$ sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.2.0-2.i ^mg ERROR: % Invalid input detected at '^' marker.
I can't type sfr word after sw-module module, there is no variant to choose sfr.
The error the same on all ASA's 5512, including ASA 5506.
I have deleted ips module like it was said in manual:
ASA-111# sw-module module ips shutdown
Shutdown module ips? [confirm]
Shutdown issued for module ips.
ASA-111# sw-module module ips uninstall
Unable to uninstall Module ips, it does not have a software image installed.
ASA-111#
But there is no effect and I still have no idea how to install Firepower service.
Any Idea what I'm doing wrong?
Thanks in advance!
Solved! Go to Solution.
11-12-2018 02:09 AM
Please refer to the release notes for ASA 9.10(1). They note the following:
"No support in 9.10(1) for the ASA FirePOWER module on the ASA 5506-X series and the ASA 5512-X—The ASA 5506-X series and 5512-X no longer support the ASA FirePOWER module in 9.10(1) and later due to memory constraints. You must remain on 9.9(x) or lower to continue using this module. "
https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html
You need to stay on the 9.9(x) or earlier release train. Your best bet for now would be 9.8(3)14.
11-12-2018 02:09 AM
Please refer to the release notes for ASA 9.10(1). They note the following:
"No support in 9.10(1) for the ASA FirePOWER module on the ASA 5506-X series and the ASA 5512-X—The ASA 5506-X series and 5512-X no longer support the ASA FirePOWER module in 9.10(1) and later due to memory constraints. You must remain on 9.9(x) or lower to continue using this module. "
https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html
You need to stay on the 9.9(x) or earlier release train. Your best bet for now would be 9.8(3)14.
11-12-2018 02:19 AM
Oh, good news for me! Thank's a lot for your help.
I have very small experience with Firepower, and because of that I don't think about supporting FP in new version.
Thank you!
11-12-2018 02:25 AM
You're welcome.
No matter what device (ASA, Firepower, router, switch etc.) it is a good habit to develop to ALWAYS read the release notes before installing new software.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide