Cisco Firewall :: ASA 5505 Frequency Restart And Create A Crash-info File
Nov 28, 2010My asa5505 frequency restart and create a crash-infor file.
View 3 RepliesMy asa5505 frequency restart and create a crash-infor file.
View 3 RepliesWe have Cisco 3945 Router and generating crashinfo while firing PRI from this Router.
View 1 Replies View RelatedOur 6500 was reboot by self with crash info and i found it was happened by CPU HOG. The log is below for CPU HOG and you can see many times from attached crash info file.
%SYS-SP-3-CPUHOG: Task is running for (16000)m secs, more than (2000)m secs (15/12),process = RPC pagp_switch_mp2sp.
[code]....
I think this process made high CPU & memory issue and then there were internal communication fail.. isn't it? So i need to know what PRC pagp_switch_mp2sp is to prevent next issue.
Got a problem with my 1760 router. Bought it from ebay and booted it on today and got this error,It has 180224K/16384K bytes of memory and 2 paritions of 32768K flash.I erased both partitions and put a different version of the IOS on (still 12.4) and there is no difference, still get the errors.These aren't on any of my other 1760 routers so I assume they are linked to the problem.
View 3 Replies View Related2147483647 2012-Jun-27 20:23:40 Emergency %OS-F-BUFFER: OSBUFG_buf_alloc: Buffer pool magic is invalid ***** FATAL ERROR ***** Reporting Task: GOAH. Software Version: 1.2.5.70 (date 11-Jun-2012 t ime 17:35:31) <snip> ***** END OF FATAL ERROR *****
The switch was running a relatively basic configuration and not under any appreciable load when the crash occurred. It had been running 1.2.5.70 for quite some time and had been restarted several times since the firmware upgrade. I have not been able to reproduce the issue on demand.
Facing issue with ACE module Part#ACE20-MOD-K9 having NP failed error message and module got restarted.
Module software currently# c6ace-t1k9-mz.A2_1_6a.bin
We have studied the Support Community document and got the BUG id's information having impact on this module, BUG id's: CSCsv92321, CSCsx25981, CSCsq38638
Software version to upgrade for the ACE module having no impact on this ACE module by these BUG id's having parity error symptoms.
on my Active/Stanby ASA5505 has Sec+ License(trial), I can't create more then 3 nameif interface however,
Licensed features for this platform:
Maximum Physical Interfaces : 8 perpetual
VLANs : 3 DMZ Unrestricted
Dual ISPs : Enabled perpetual
VLAN Trunk Ports : 8 perpetual
Inside Hosts : Unlimited 17 days
Failover : Active/Standby 17 days
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled 17 days
AnyConnect Premium Peers : 2 perpetual
I have a Cisco 5505 with a security plus license and but I can’t seem to create sub interfaces on it.
ASA1(config)# sh ver
Cisco Adaptive Security Appliance Software Version 8.2(2)4Device Manager Version 6.0(3)
Compiled on Wed 03-Feb-10 14:17 by buildersSystem image file is “disk0:/asa822-4-k8.bin”Config file at boot was “startup-config”
ASA1 up 1 day 18 hours
Hardware: ASA5505, 512 MB RAM, CPU Geode 500 MHzInternal ATA Compact Flash, 128MBBIOS Flash Firmware Hub @ 0xffe00000, 1024KB
[code]....
I have a production ASA 5505 that is working perfectly. I wanted to take a spare ASA 5505 and copy the running config to it so that I would have a backup unit that could be swapped out if the production unit went down.
Both units have security plus and running 8.2(1). The only difference is that the production ASA has 512MB of RAM while the backup ASA has 256MB. Also the backup has anyconnect and the production unit does not.
I copied the running-config to my tftp server and then copied the running config from my tftp server to the backup ASA as startup-config. After reload the device booted with an identical configuration to my production ASA, but after swapping out the units to test it, I have no access to the WAN or DMZ from my LAN. Swapping back to the production unit and all works as it should.
I printed out the running config from both devices and compared them line by line. They are identical except for the anyconnect line on the backup ASAs config file.
My computer will sometimes be connected to the router but internet access isn't available.This is easily fixed by resetting the router, but I was thinking that it would be good to just write a batch file to do it when needed.How would a write a batch file that will restart the router based of the result of pinging an internet site/server.
View 2 Replies View RelatedI have a customer an exisiting 5505 which connects to multiple sites for a site-to-site VPN. This firewall was not installed by myself originally I have just been asked to take a look now.The situation is that we now need to edit one of the existing site-to-site VPNs to include the remote sites expanded network. I have tried doing this through the ASDM and have found that I cannot add new network objects. I have tried creating a new network object group and then added the new networks from there but I am completely unable to add the new objects.I believe a picture tells a thousand words in this case so I have attached some images which show the problem. I have also tried going through the VPN wizard, this also does not allow me to add new network objects.
View 2 Replies View Relatedtrying to configure our ASA 5505 (hence my request for the ASDM). However, I can go CLI if push comes to shove.
What I'm trying to do is allow a range of IP addresses on the inside interface (those which the DHCP server is doling out IPs which are XXX.X.XXX.14-140) to access email only (which is hosted offsite). They still need to access the file servers which are on the inside but nothing should be going out to the internet other than email.
I believe I have to create a Network Object which contains the IP range I wish to restrict. I can see where I add the Network Object but I don't know what the syntax should be to specify the address range.
I'm also not sure what the sequence of the ACLs should be and whether or not I can keep the default Access Rules in place. There are the two implicit rules: 1) Permit any traffic out to less secure networks 2) Deny any traffic to anywhere (which is superceded by rule 1, yes?)
To create an Access Rule like the one I desire, do I need to move the two existing rules down the list so that the new one will supercede both implicit rules?
I just upgraded my firewall to ASA 5505. Now, my original static ip address cofiguration is gone. Apperantly, Cisco went away from static ip address to something like nat (inside,outside) dynamic interface. how to create a static ip address under version 8.4? By the way, I am sharing what my configuration used to look before upgrading.
!
hostname cisco-asa
domain-name default.domain.invalid
names
!
interface Vlan1
nameif inside
security-level 100
[code].....
I'm trying via the ASDM to port forward http connections to a DVR for the purpose of viewing IP cams.I've tried via ASDM to create a public server but I'm not allowed to use my public IP address for the public Interface.I have only one public IP address available.Is there any way round this ? I would also like to know how I can enable NAT with PAT.I've tried setting the outside Interface for use with PAT but It keeps reverting to the setting for a range of external addresses.I'm not really used to the ASA cli yet , I'm getting there.If there's a workaround via the CLI , I'll take that route.
View 4 Replies View RelatedJust started using our ASA 5505 v8.2 (1) Trying to configure the ASA appliance to allow access into an internal resource (i.e want to be able to RDP into a system behind the ASA from the internet).I have used a static NAT:
static (inside,outside) 100.100.100.2 192.168.1.28 netmask 255.255.255.255
access-list OUTSIDE extended permit tcp any host 100.100.100.2 eq 3389
When I view the logs it is reporting the following:Inbound TCP connection denied from 206.100.100.1 (external IP) to 100.100.100.2 /3389 flags SYN on interface outside.Been pulling my hair out with this one as I believe I have everything configured correctly.
I have a WS-C3560X-24 and attached to that are some 9 acces switches, for some weeks now my 3560 reboots some time what couse that the other 9 switches are down for some minuts as well and i dont want this of course. the reboot happens at random times and some times one week not and then like yesterday afternoon it rebooted again.
when i check the Flash directory there is no crash file and when i look at the logging its clean and just shows the startup. it's not the powersuply it's redundend and more L3 switches are attached to this power source and they dont reboot.
L3_AIM#sh versionCisco IOS Software, C3560E Software (C3560E-UNIVERSALK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)Technical Support: [URL] Copyright (c) 1986-2011 by Cisco Systems,
[Code]......
I've been trying to configure this Cisco ASA 5505 for days now. I used to be able to use the ASDM gui application, but i've since transitioned into using the CLI. Trying to go back to ASDM, it won't let me get back in, and when i try show asdm image, it says Device Manager image file not set. I have no CD for this device and I need that image file for the ASDM. How can I locate the file and install it on the router so I can use it?
View 2 Replies View Relatedhow to create a .bat file to test ping with nane and ip address
View 1 Replies View RelatedI have a domain server and its has 100 users. some time my users PC Net session Jam. So that time i need to delete the Net session.
View 1 Replies View RelatedI have many WiSM WLC's running 7.0.116.0. One WLC was rebooted few days ago but there was no crash file and nothing in logs say why this issue happened.There was a power problem at the same time the WLC rebooted (some switches and PE's was rebooted as well) but if it is a power issue why only one WLC inside the WiSM rebooted and the other WLC is still working fine with no reboot?I have 5 WiSM modules connected to the same 6500 box, only one WLC was rebooted which indicates a crash but no crash file registered for it.Is there anyway I can find the reason why that WLC was rebooted?
View 6 Replies View RelatedI have a serious problem with my corporate firewall, witch is an ASA 5520, fv 8.3, with 8 +1 interfaces. It suddenly started to crash every 10/20 minutes and rebooting alone.
First of all I checked system resources witch are in a very low usage state. I also checked interfaces errors, but nothing strange come out o from error counters analysis. I tried disabling logging and all the service policy rules configured, but nothing changed.
Nothing changed and firewall continue restarting by itself.
Last logs I received before crash were:
%ASA-4-711004: Task ran for 35 m sec, Process = Dispatch Unit, PC = 84a619e, Call stack =
%ASA-4-711004: Task ran for 35 m sec, Process = Dispatch Unit, PC = 84a619e, Call stack = 0x084A619E 0x084A6512 0x084A70E1 0x084A7987 0x084A7AAA 0x08558B9B 0x08558E8A 0x083D3518 0x083CA145 0x080659D1 0x089196D9 0x08919790 0x089FF711 0x08A27468
Here the sh crash info command on module 0, after last reboot:
[Code] ......
I have to upgrade to an ASA 5510 CSC, and the new license is generated, the file you sent me licensing, only seen this:Activation Code not required for this renewal. Please go to "Administration> Product License" in the CSC SSM console and click "Check Status Online" to get the latest expiration date (BASE: 09/04/2014, PLUS: 09/04/2014).This means that what I have not make any upgrades or license charge in the ASA? Does the automatic update is made?
View 1 Replies View RelatedOur Firewall is just new. ASA5525X
Today, during a packet_trace to debug a routing problem, the active ASA
- thsasaprd02 - crashed suddenly.
I was able to copy-paste the console - including the command that triggered it - After the reboot I ran the command again, on the same ASA - after doing a manual failover - the command succeeded normally.
We are running an FWSM on a 6509 with a SUP720. Firmware 3.2(18), in MultiContext Routed Mode, with shared MSFC.Everything runs fine on this baby most of them time, however occasionally without warning and with no specific pattern the Primary node will fail (as in completely stop responding) and the secondary will takover as active. Two get the primary up agian, I reset the hw-module and then no failover active on the secondary to return the primary as active. However, after this event, I start to experience strange issues with connectivity. Certain TCP src dst combinations will just not work.
View 1 Replies View RelatedI have two cisco ASA 5505 devices and two cisco switches plugged to ASAs in each office. I need to create a VPN tunnel between two offices.
-Network behind the ASA1 in office1 is 192.168.1.0/24 with DHCP server – 192.168.1.10
-Networks behind the ASA2 in office2 are 192.168.5.0/25; 192.168.5.128/26 and 192.168.5.192/26
All computers in office2 need to get IPs from DHCP server 192.168.1.10. I have switch in office2 with 3 VLANS and I can assign computers from different subnets to different VLANs.How can I archive this goal? Should I assign 3 IPs for ASA2 inside interface (192.168.5.1, ...5.129, ...5.193) as a default gateways for each subnet? Should I put dhcp helper address 192.168.1.10 on the switch for each VLAN?
we have a cisco asa 5505 and it working great .i want to create web server that only selected public ip address can access.
View 3 Replies View RelatedI have a newly aquired asa 5505 that I just set up to the bare minimum configurations. I followed a cisco paper on how to create a "remote access vpn" setup for ipsec. I can sucessfully connect and establish a VPN, but when I try to access an inside resource from the vpn address, the asa blocks it.
Specific error is: Code...
I recently had some trouble with my ASA 5505 in that the running config would not be saved after a reboot. Definitely looked like a hardware problem with the flash memory. I have since bought a new flash memory card and copied the contents of the old card to the new card. 1st problem I have is that I can see the image on the new card, but for some reason it wont boot into that image. I get /file not found
I then successfully load a new image to the device and it boots successfully. I then follow it with a
Cisco asa# config t
Cisco(config)# boot system disk0:/asa831-k8.bin
(to ensure it boots from the flash in the future) and I get
WARNING: BOOT variable added, but unable to find disk0:/asa831-k8.bin
I have since tried
ciscoasa# fsck disk0:
Unsupported file system type!
%Error checking disk0: (No such file or directory)
When ever I try to do anything with Disk0: i get the same error. (No such file or directory). I have also tried putting the old flash card in the ASA and I now get the same response.
[OK] webvpn
webvpn
[ERROR] anyconnect image disk0:/anyconnect-win-3.0.08057-k9.pkg 2
copying 'disk0:/anyconnect-win-3.0.08057-k9.pkg' to a temporary ramfs file failed
Trying to add the windows anyconnect to the list of usable software for clients and that error happened. What is going wrong? I assume I dont have enough RAM...
can i create my own a signal
View 1 Replies View RelatedI have connected the AIR-BR1310G and one meter apart I installed a GPS antenna. When the AIR-BR1310G is up, the GPS stop detecting satellites. Using a spectrum analyzer I found that the AIR-BR1310G transmits a frequency of 1575 MHz along with the normal 2.4 GHz one. How can I eliminate this annoying 1575 MHz signal from the AIR-BR1310G?
View 8 Replies View Relatedwhat is maximum clock frequency of LAN card?
View 3 Replies View RelatedI have a Cisco ASA 5505 with the base License. I want to split my network and add a new Internet Access, the first network in Orange works fine. My question is how can i access the file server from the second network (192.168.X.0 /24) ? The 3 switches are Cisco SF300-24P.
View 7 Replies View Related