cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
961
Views
0
Helpful
2
Replies

Update 5506-X with FirePOWER failover

Hello,

 

 

I need to update an ASAs failover 5506-X with FirePOWER to overcome vulnerability CVE-2018-0296.


I would like to know how I can transfer the .bin that is on disk0: from the first ASA to the second.

 

 

Regards,

1 Accepted Solution

Accepted Solutions

Nelson Neto
Level 1
Level 1

Use the command:

 

FW-Primary/act# copy disk0:/asa964-18-lfbff-k8.SPA cluster:FW-Secondary

View solution in original post

2 Replies 2

Hi, I see a lot of errors on the interface:

 

Interface GigabitEthernet0/1 "inside", is up, line protocol is up
Hardware is i825xxGB rev03, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address xxxx.xxxx.xxxx, MTU 1500
IP address x.x.x.x, subnet mask x.x.x.x
40873611552 packets input, 24161952752164 bytes, 0 no buffer
Received 584349 broadcasts, 0 runts, 0 giants
20675385 input errors, 0 CRC, 0 frame, 20675385 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
0 L2 decode drops
41475878351 packets output, 21624031950460 bytes, 20368959 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops, 0 tx hangs
input queue (blocks free curr/low): hardware (255/230)
output queue (blocks free curr/low): hardware (255/0)
Traffic Statistics for "inside":
40873402031 packets input, 23385913357886 bytes
41496247310 packets output, 20856791981497 bytes
97146495 packets dropped
1 minute input rate 4727 pkts/sec, 2791783 bytes/sec
1 minute output rate 4621 pkts/sec, 1688935 bytes/sec
1 minute drop rate, 7 pkts/sec
5 minute input rate 5123 pkts/sec, 3136113 bytes/sec
5 minute output rate 5060 pkts/sec, 2327510 bytes/sec
5 minute drop rate, 6 pkts/sec
Control Point Interface States:
Interface number is 4
Interface config status is active
Interface state is active

 

Can you check the interface settings of the inside switch where the firewall is connected?

Cn you try to force speed and duplex on both devices, firewall and switch?

The current bandwidth is very low, more or less 2Mbit/s.

 

Can you test the delay after clear connection, clear xlate command?

 

Regards.

Nelson Neto
Level 1
Level 1

Use the command:

 

FW-Primary/act# copy disk0:/asa964-18-lfbff-k8.SPA cluster:FW-Secondary

Review Cisco Networking for a $25 gift card