cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2692
Views
20
Helpful
3
Replies

sw-module module sfr - Invalid input detected at

Bolik
Level 1
Level 1

Hello there!

 

I'm not ASA super hero engineer, and I need some help.

 

I have upgraded 4 ASA (three 5512 and one 5506) to a new version - 9.10(1). Until updating I didn't know, that it was with Firepower Service.

After upgrade Firepower doesn't work. I have read installation manual and upload new boot img to ASA - asasfr-5500x-boot-6.2.3-4.img.

ASA-111# show disk0: | i img
  124  41846784    Jul 28 2017 10:37:08  asasfr-5500x-boot-6.2.0-2.img
  133  42956800    Nov 07 2018 14:18:18  asasfr-5500x-boot-6.2.3-4.img

I see a SSD in system:

ASA-111# show inventory 
show_inventory_all -1744774352
Name: "Chassis", DESCR: "ASA 5512-X with SW, 6 GE Data, 1 GE Mgmt, AC"
PID: ASA5512           , VID: V04     , SN: FGLblablabla

Name: "Storage Device 1", DESCR: "Model Number: Micron_M600_MTFDDAK128MBF"
PID: N/A               , VID: N/A     , SN: MSAblablabla
ASA-111# show module 

Mod  Card Type                                    Model              Serial No. 
---- -------------------------------------------- ------------------ -----------
   0 ASA 5512-X with SW, 6 GE Data, 1 GE Mgmt, AC ASA5512            FCH1blablabla
 ips Unknown                                      N/A                FCH1blablabla
cxsc Unknown                                      N/A                FCH1blablabla
 sfr Unsupported                                  Unsupported                   

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version     
---- --------------------------------- ------------ ------------ ---------------
   0 cc46.d6bf.a8b3 to cc46.d6bf.a8ba  1.0          2.1(9)8      9.10(1)
 ips cc46.d6bf.a8b1 to cc46.d6bf.a8b1  N/A          N/A          
cxsc cc46.d6bf.a8b1 to cc46.d6bf.a8b1  N/A          N/A          

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
cxsc Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable        
 ips Unresponsive       Not Applicable        
cxsc Unresponsive       Not Applicable        

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual     

 

ASA-111# show version 

Cisco Adaptive Security Appliance Software Version 9.10(1) 
Firepower Extensible Operating System Version 2.4(1.103)
Device Manager Version 7.10(1)

Compiled on Wed 24-Oct-18 16:31 PDT by builders
System image file is "disk0:/asa9101-smp-k8.bin"
Config file at boot was "startup-config"

ASA-111 up 4 days 10 hours

Hardware:   ASA5512, 4096 MB RAM, CPU Clarkdale 2800 MHz, 1 CPU (2 cores)
            ASA: 1651 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 4096MB

But when I try to install Firepower I got en error^

 

 

ASA-111#  sw-module module sfr recover configure image disk0:/asasfr-5500x-boo$

 sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.2.0-2.i                  ^mg

ERROR: % Invalid input detected at '^' marker.

I can't type sfr word after sw-module module, there is no variant to choose sfr.

 

The error the same on all ASA's 5512, including ASA 5506.

 

I have deleted ips module like it was said in manual:

ASA-111# sw-module module ips shutdown

Shutdown module ips? [confirm]
Shutdown issued for module ips.
ASA-111# sw-module module ips uninstall

Unable to uninstall Module ips, it does not have a software image installed.
ASA-111#

But there is no effect and I still have no idea how to install Firepower service.

 

Any Idea what I'm doing wrong?

Thanks in advance!

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Please refer to the release notes for ASA 9.10(1). They note the following:

 

"No support in 9.10(1) for the ASA FirePOWER module on the ASA 5506-X series and the ASA 5512-X—The ASA 5506-X series and 5512-X no longer support the ASA FirePOWER module in 9.10(1) and later due to memory constraints. You must remain on 9.9(x) or lower to continue using this module. "

https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html

 

You need to stay on the 9.9(x) or earlier release train. Your best bet for now would be 9.8(3)14.

 

 

 

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

Please refer to the release notes for ASA 9.10(1). They note the following:

 

"No support in 9.10(1) for the ASA FirePOWER module on the ASA 5506-X series and the ASA 5512-X—The ASA 5506-X series and 5512-X no longer support the ASA FirePOWER module in 9.10(1) and later due to memory constraints. You must remain on 9.9(x) or lower to continue using this module. "

https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html

 

You need to stay on the 9.9(x) or earlier release train. Your best bet for now would be 9.8(3)14.

 

 

 

Oh, good news for me! Thank's a lot for your help.

I have very small experience with Firepower, and because of that I don't think about supporting FP in new version.

 

Thank you!

You're welcome.

 

No matter what device (ASA, Firepower, router, switch etc.) it is a good habit to develop to ALWAYS read the release notes before installing new software. 

Review Cisco Networking for a $25 gift card