cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1415
Views
0
Helpful
4
Replies

Asa Start Failed

alfo5179
Level 1
Level 1

Hello,

We are deploying a new FPR-2140 to be in appliance mode using ASA.

We had followed the below steps to download the image and then install it. but after we install the image, we receive the same error, cannot open Application.

Do you have an idea of what can we else do to fix it?

 

 

firepower-2140# connect asa
Error: Application is not installed.
firepower-2140#
firepower-2140# show ver
Version: 2.8(1.144)
Startup-Vers: 2.8(1.144)
firepower-2140#
firepower-2140#
firepower-2140# scope firmware
firepower-2140 /firmware # show package
Name Package-Vers
--------------------------------------------- ------------
cisco-asa-fp2k.9.14.2.13.SPA 9.14.2.13
cisco-asa-fp2k.9.8.4.20.SPA 9.8.4.20
firepower-2140 /firmware # delete package cisco-asa-fp2k.9.8.4.20.SPA
firepower-2140 /firmware #
firepower-2140 /firmware # show package
Name Package-Vers
--------------------------------------------- ------------
cisco-asa-fp2k.9.14.2.13.SPA 9.14.2.13
firepower-2140 /firmware #
firepower-2140 /firmware #
firepower-2140 /firmware # connect asa
Error: Application is not installed.
firepower-2140 /firmware #
firepower-2140 /firmware #
firepower-2140 /firmware # download image tftp://10.5.87.152/netsec.devops/cisco-asa-fp2k.9.16.4.39.SPA
Please use the command 'show download-task' or 'show download-task detail' to check download progress.
% Download-task cisco-asa-fp2k.9.16.4.39.SPA : completed successfully.

firepower-2140 /firmware # show package
Name Package-Vers
--------------------------------------------- ------------
cisco-asa-fp2k.9.14.2.13.SPA 9.14.2.13
cisco-asa-fp2k.9.16.4.39.SPA 9.16.4.39
firepower-2140 /firmware #
firepower-2140 /firmware # scope auto-in
firepower-2140 /firmware/auto-install # install security-pack version 9.16.4.39

The system is currently installed with security software package 9.14.2.13, which has:
- The platform version: 2.8.1.144
- The CSP (asa) version: 9.14.2.13
If you proceed with the upgrade 9.16.4.39, it will do the following:
- upgrade to the new platform version 2.10.1.1609
- upgrade to the CSP asa version 9.16.4.39
During the upgrade, the system will be reboot

Do you want to proceed ? (yes/no):yes

This operation upgrades firmware and software on Security Platform Components
Here is the checklist of things that are recommended before starting Auto-Install
(1) Review current critical/major faults
(2) Initiate a configuration backup

Do you want to proceed? (yes/no):yes

Triggered the install of software package version 9.16.4.39
Install started. This will take several minutes.
For monitoring the upgrade progress, please enter 'show' or 'show detail' command.
firepower-2140 /firmware/auto-install # show detail

Firmware Auto-Install:
Package-Vers: 9.16.4.39
Oper State: Scheduled
Installation Time: 2023-10-25T21:21:28.711
Upgrade State: Ready
Upgrade Status:
Validation Software Pack Status:
Firmware Upgrade Status:
Current Task:
firepower-2140 /firmware/auto-install #
Broadcast message from root@firepower-2140 (Wed Oct 25 21:23:28 2023):

All shells being terminated due to system /sbin/reboot

--------------- Error after the installation: ---------------

firepower-2140# connect asa
Error: Application is not installed.

firepower-2140 /fabric-interconnect # scope ssa
firepower-2140 /ssa # show app-instance
Application Name Slot ID Admin State Operational State Running Ver
sion Startup Version Cluster Oper State Cluster Role
-------------------- ---------- --------------- -------------------- -----------
---- --------------- -------------------- ------------
asa       1        Enabled          Start Failed

4 Replies 4

JP Miranda Z
Cisco Employee
Cisco Employee

Hi alfo5179,

Try the following:


firepower-2140# scope ssa
firepower-2140 /ssa # scope slot 1
firepower-2140 /ssa/slot # enter app-instance asa
firepower-2140 /ssa/slot/app-instance* # set startup-version 9.16.4.39
firepower-2140 /ssa/slot/app-instance* # exit
firepower-2140 /ssa/slot* # exit
firepower-2140 /ssa* # exit
firepower-2140* # commit-buffer

Hope this helps!

-JP-

Hello, JP,

Thanks for the reply.

I did exactly what you recommend, but still not allow me to access ASA mode, I tried to search more info about this but I didnt find.

firepower-2140# scope ssa
firepower-2140 /ssa # scope slot 1
firepower-2140 /ssa/slot # enter app-instance asa
firepower-2140 /ssa/slot/app-instance # set startup-version 9.16.4.39
firepower-2140 /ssa/slot/app-instance* # exit
firepower-2140 /ssa/slot* # exit
firepower-2140 /ssa* # commit-buffer
firepower-2140 /ssa #
firepower-2140 /ssa # exit
firepower-2140#
firepower-2140# connect asa
Error: Application is not installed.
firepower-2140#
firepower-2140#
firepower-2140#
firepower-2140#
firepower-2140# scope ssa
firepower-2140 /ssa # show app-instance
Application Name Slot ID Admin State Operational State Running Ver
sion Startup Version Cluster Oper State
-------------------- ---------- --------------- -------------------- -----------
---- --------------- ------------------
asa 1 Enabled Update Failed
9.16.4.39 Not Applicable

alfo5179,

 

Seems like there was a problem during the installation of the ASA, you can try performing a complete reimage following this steps:

https://www.cisco.com/c/en/us/td/docs/security/firepower/2100/troubleshoot_fxos/b_2100_CLI_Troubleshoot/b_2100_CLI_Troubleshoot_chapter_011.html#task_uzp_kv1_hbb

Keep in mind this is my recommendation only if this is not affecting any of your production since this is a new device, if this is affecting production i will recommend you to involve tac at least to get a root cause.

 

Hope this helps!

 

-JP-

mosomar
Cisco Employee
Cisco Employee

Only way to fix that you have to format everything from connect local-mgmt then format everything then load the image from TFTP.