Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
So it seems like this is the expected behaviour for all the new releases:
In the old releases and in certain conditions, ASA doesn't check the source of the ARP request, please find the following software bug:
https://tools.cisco.com/bugsearch/bug/...
We also had some serious issues with this after an upgrade from 9.1(6) to 9.1(7).
After opening a case last week, I received an update today that there is an interim software release in which only the IKE vulnerability is fixed and no other "features...