<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"> 
  <channel>
  <title>Adaptive Security Appliance Hot Issues from Cisco TAC</title>
  <link>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</link>
  <description>Hot Issues from Cisco TAC.  Please click the link for complete details.</description>
  <language>en-us</language>

  <managingEditor>wsisk@cisco.com (Wes Sisk)</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com (Cisco Newsroom)</webMaster>
  <pubDate>Mon, 17 Jun 2013 10:43:37 EDT</pubDate>
  <lastBuildDate>Mon, 17 Jun 2013 10:43:37 EDT</lastBuildDate>
  <generator>PERL</generator>

  <docs>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</docs>
  <ttl>10080</ttl>

<item>
<title>Clientless plugins are not working, Fixed CSCug23031</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug23031</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Clientless plugins (telnet/ssh, RDP, etc.) no longer work in ASA 8.4(6). When you access them through the clientless portal, only a blank page is displayed.
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Launching the plugin after login to the portal.  Seen using ASA 8.4(6) and any Internet browser (Internet Explorer, Firefox, Chrome, etc.).
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
Upgrade to ASA version 9.x or downgrade to 8.4(5).
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug23031</guid>
</item>
<item>
<title>ASA:Traffic denied &#39;licensed host limit of 0 exceeded, Open CSCuh23347</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh23347</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA 5505 drops Traffic with syslog message &quot;%ASA-4-450001: Deny traffic for protocol 1 src inside:10.11.12.3/512 dst outside:4.2.2.2/0, licensed host limit of 0 exceeded&quot; with Base License.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
ASA 5505 running 8.4.6 with Base license.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
upgrade to 9.0.2, 9.1.2 or downgrade to 8.2.5. Also works on 8.4.5.6

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh23347</guid>
</item>
<item>
<title>ASA 8.4(6) - WebVPN Plugins No Longer Function,   CSCuh15069</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh15069</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Web plugins (telnet/ssh, RDP, etc.) no longer work in ASA 8.4(6). When you access them through the clientless portal, only a blank page is displayed.
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Seen using ASA 8.4(6) and any Internet browser (Internet Explorer, Firefox, Chrome, etc.).
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
Upgrade to ASA version 9.x or downgrade to 8.4(5).
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh15069</guid>
</item>
<item>
<title>webvpn-l7-rewrite: add full fledged VBScript rewirter, Open CSCuh40325</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh40325</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Applications using VBscipt fail over clientless webvpn
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Use any application that uses VBScript over webvpn without ST enabled.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
enable ST to bypass the rewriter, if that doesn&#39;t work then create an APCF.

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh40325</guid>
</item>
<item>
<title>AIP-SSM-40 not recognized as genuine Cisco product, Terminated CSCtz29732</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtz29732</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASA and AIP-SSM module may reported error related to &quot;Failed Identification Test in slot 1&quot;
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

Observed on a 5520 and 5540 with AIP-SSM-40 running 8.4.3 and 7.0(6)E4
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

Reload/reseat the module

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtz29732</guid>
</item>
<item>
<title>Connection not removed even after reaching idle timeout, Open CSCuh13899</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh13899</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Some connection may not removed even after reaching idle timeout.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Yet to identify which specific and what condition these connection are not removed.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Clearing this connection manually, but very difficult in customer environment. This will not be acceptable / workable workaround.

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh13899</guid>
</item>
<item>
<title>Standby ASA reloads unexpectedly after config sync with netflow enabled, Fixed CSCud56558</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud56558</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASA running 8.4.5 with netflow configuration may reload while replicating config
seen in 2 conditions

- disable failover and re-enable failover on the standby unit
- write standby on the active unit
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

netflow should be enabled by applying it to the policy-map
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

disable netflow or avoid doing a write standby

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud56558</guid>
</item>
<item>
<title>ASA drops some CX/CSC inspected HTTP packets due to PAWS violation, Fixed CSCug19491</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug19491</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Certain HTTP connections might experience slowdowns or fail to complete if the packets are inspected by the CX module.

HTTP packets might be dropped by the ASA for the ASP drop reason &quot;TCP packet failed PAWS test (tcp-paws-fail)&quot;
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
All of the following conditions must be met to encounter this problem:
1) The traffic flow must be subjected to inspection by the ASA CX module
2) The connection must be HTTP over TCP
3) The HTTP GET message must be so big as to become segmented into multiple TCP packets. This might occur if the cookie values in the get are very long
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Using the ASA&#39;s modular policy framework, disable TCP timestamps for the connections:

!
access-list http-traffic extended permit tcp any any eq www
!
class-map http-class
 match access-list http-traffic
!
tcp-map TCP-map-timestamps
  tcp-options timestamp clear
!
policy-map global_policy
...
 class http-class
  set connection advanced-options TCP-map-timestamps
!

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug19491</guid>
</item>
<item>
<title>ASA UDP 500 port not removed from PAT pool, Terminated CSCuf56976</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf56976</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
New VPN connections will fail if the VPN port is allocated from PAT pool on the same interface.  We should not allow the VPN port to be used in the PAT pool.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Problem observed on 9.1.1.
PAT configured for same interface that terminates the VPN.
Problem is intermittent. Source ip address is random. VPN will work fine until this xlate using the UDP port is created.
Clearing this xlate will restore VPN connectivity.   

Example:
nat (any,outside) after-auto source dynamic any interface dns
crypto map outside_map interface outside

sh xlate:
UDP PAT from any:&lt;inside-ip&gt;/123 to outside:&lt;outside-ip&gt;/500 flags riD idle 0:00:51 timeout 0:00:30
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Issue &quot;clear xlate&quot; to clear the translation that is using the VPN port
Adjust PAT configuration to use an IP address that differs from the VPN interface IP

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf56976</guid>
</item>
<item>
<title>ASA writes past end of file system then can&#39;t boot, Fixed CSCuc98398</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuc98398</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
After upgrading the ASA OS the device does not boot successfully, and will continually loop the unsuccessful boot sequence.

The following will be seen on the console of the ASA (The ASA and image file will vary):

-----------------------------------------------------------------------------------
Evaluating BIOS Options ...
Launch BIOS Extension to setup ROMMON

Cisco Systems ROMMON Version (1.0(12)13) #0: Thu Aug 28 15:55:27 PDT 2008

Platform ASA5505

Use BREAK or ESC to interrupt boot.
Use SPACE to begin boot immediately.

Launching BootLoader...
Boot configuration file contains 1 entry.


Loading disk0:/asa844-9-k8.bin... Booting... 
Platform ASA5505

Loading...
IO memory blocks requested from bigphys 32bit: 9672

## APPLIANCE REBOOTS AUTOMATICALLY HERE ##
-----------------------------------------------------------------------------------
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Cisco ASA where the disk (Compact Flash) is already close to full or is fragmented from frequent use and a new 
version of the OS is saved on the disk (without removing any files) and the new file is made the boot file 
in the configuration.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Delete the bad file from flash, as well as any other images that are no longer in use to free up more space on the flash. Then, re-download the new 
file to flash

- or -

1) Copy all the files off of the ASA&#39;s disk
2) Format the disk:
3) Copy the files back onto the disk, starting with the OS image you wish the ASA to boot. 

The second procedure (involving the re-format) is the preferred workaround, as it places the ASA image towards the beginning of the filesystem, making the chances of 
encountering this problem much less.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuc98398</guid>
</item>
<item>
<title>Osiris: Crash when NULL pointer was passed to the l2p function, Fixed CSCuf85524</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf85524</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
A crash occurs and the console at the time of the crash should say:

&quot; Panic: DATAPATH-0-2764 - _mempool_dma_l2p: Invalid laddr 0x21a0 passed in. DMA pool 0 starts 0x___________ ends 0x_________ DMA pool 1 starts 0x__________ ends 0x__________ &quot;
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Establishing AnyConnect DTLS connections. Crash occurs after ~1000. 
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
There are no workarounds. 
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf85524</guid>
</item>
<item>
<title>ASA does not obfuscate aaa-server key when timeout is configured., Open CSCuh27912</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh27912</link>
<description>&amp;lt;B&amp;gt;Symptom:&amp;lt;/B&amp;gt;
The ASA isn&amp;apos;t obfuscating passwords when timeout configured before aaa-server key command.

&amp;lt;B&amp;gt;Conditions:&amp;lt;/B&amp;gt;
timeout configured in aaa-server host command.

&amp;lt;B&amp;gt;Workaround:&amp;lt;/B&amp;gt;
none.

&amp;lt;B&amp;gt;More Info:&amp;lt;/B&amp;gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh27912</guid>
</item>
<item>
<title>ASA may reload with traceback in thread name: Reload Control Thread, Terminated CSCtn03617</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtn03617</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;


ASA may reload with traceback in Thread name: Reload Control Thread. 
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

ASA 8.x
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

None at this time.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtn03617</guid>
</item>
<item>
<title>Traceback after upgrade from 8.2.5 to 8.4.6, Fixed CSCuh19234</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh19234</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Crash happens during upgrade migration from 8.2.5 -&gt; 8.4.6. Causing bootloop.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
ASA with version 8.2.5
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Manual migration of the config

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh19234</guid>
</item>
<item>
<title>ASA 9.1.2 - Memory corruptions in ctm hardware crypto code., Open CSCuh19462</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh19462</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA crashes in CERT API thread
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
ASA running 9.1.2 version on smp platform
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
not known
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh19462</guid>
</item>
<item>
<title>Upgrade ASA causes traceback with assert during spinlock, Fixed CSCud77352</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud77352</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA may generate a traceback in DATAPATH-0-1238 with assert+48 at slib/../finesse/snap_api.h:161
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Upgrading ASA from 8.6.1.5 to 9.1.1
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
NA

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud77352</guid>
</item>
<item>
<title>ASA exhausting DHCP pool when acting as a proxy for VPN clients, Terminated CSCts45189</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCts45189</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
1. When the client disconnect it doesn&#39;t seem to request for a release of the IP address
2. The same client seems to use up more than one ip address from the DHCP pool exhausting the pool and thus preventing new users to connect after a while.
3. When a client tries to renew it&#39;s lease the ASA seems to be renewing the lease for the wrong client ip address
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
1. configure ASA to use the DHCP server to assign an ip address
2. use an IPSEC VPN client.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
1. Shift the DHCP pools around quite frequently on the dhcp server
or 
2. Reload the ASA

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCts45189</guid>
</item>
<item>
<title>Anyconnect sessions do not connect due to uauth failure, Open CSCuh08432</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh08432</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Anyconnect sessions are randomly rejected, both from standalone client and from portal
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
This is seen randomly after upgrading to 9.0.2. debug webvpn reports:  vpn_put_uauth failed!
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
Issue is not seen on 8.4
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh08432</guid>
</item>
<item>
<title>ASA assert traceback during xlate replication in a failover setup, Fixed CSCuf07393</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf07393</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
An ASA firewall running in STANDBY as part of an Active/Standby or Active/Active high availability configuration may crash citing an assert in thread name DATAPATH-x-xxxx.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
The crash is seen in rare circumstances on a standby firewall or a firewall in an Active/Active high availability configuration where some contexts are STANDBY on that firewall.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None at this time. In order to reduce the impact of crashes in an Active/Active failover configuration you might want to move both ACTIVE Failover Groups to one ASA

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf07393</guid>
</item>
<item>
<title>Traceback in Thread Name: OSPF Router during interface removal, Fixed CSCug98894</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug98894</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Traceback in OSPF process
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Removing an interface with OSPF configured on it
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug98894</guid>
</item>
<item>
<title>Re-transmitted FIN not allowed through with sysopt connection timewait, Fixed CSCuh20716</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh20716</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
An ASA firewall, by design, will remove a connection from the connection table upon seeing all the packets required to close the connection. In situations where the ASA sees all the required packets, but perhaps some of the packets are lost in transit to their destinations, host endpoints may try to re-transmit packets needed to close the connection gracefully. Since the connection was closed and removed from the ASA&#39;s connection table, those packets would fail to pass through the firewall. 

By enabling &#39;sysopt connection timewait&#39; on the ASA Firewall, these connections will be left in the connection table for an additional 15 seconds in an effort to allow for packet loss during the closing of a connection (the firewall should allow the retransmitted FINs through/etc.). Currently, however, re-transmitted TCP FIN packets that are part of the normal TCP closing sequence, are denied and dropped by the firewall despite the presence of &#39;sysopt connection timewait&#39;.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
This is seen on all current build of ASA firewall code and is only relevant when the firewall has the following command in its configuration:

  sysopt connection timewait

Please consult the bug details in order to determine a fixed version of code.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Currently the only workaround that has been identified is to utilize TCP state bypass on the ASA Firewall in question. Not only will this allow the re-transmitted FIN-ACK packets through the firewall, but it does so by disabling TCP checking along with a host of other security related feature. As a result care should be used when evaluating TCP State Bypass as a workaround for this situation.

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh20716</guid>
</item>
<item>
<title>ASA 9.0.1 &amp; 9.1.1 - 256 Byte Blocks depletion, Fixed CSCue90343</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue90343</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Entry seen in logs:
--------------------------
ASA-3-321007  System is low on free memory blocks of size 256 (0 CNT out of 3636 MAX)


Output from&quot;show blocks&quot;:
---------------------------------------
SIZE    MAX    LOW    CNT  INUSE   HIGH
     0   2200   2198   2200      0      1
     4    100     99     99      0      0
    80   1000    998   1000      0      2
   256   2100      0      0      0      2
  1550   6274   6232   6271      1     40
  2048    100    100    100      0      0
  2560    164    164    164      0      0
  4096    100    100    100      0      0
  8192    100    100    100      0      0
  9344    100    100    100      0      0
 16384    100    100    100      0      0


Possible problems with:
--------------------------------
--Stateful failover, 
--Syslog messages,
--TCP Module
--connecting to ASA with SSH, telent is working fine - issue present till power cycle, reload from CLI might not work
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
ASA 9.0.1 and 9.1.1

EtherChannel configured with Active mode of LACP (Link Aggregation Control Protocol)
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
Not known at this moment
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue90343</guid>
</item>
<item>
<title>Traceback in Thread Name: Dispatch Unit, Open CSCug60235</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug60235</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA may generate a traceback and reload in the dispatch unit thread
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
This issue has been seen on ASA 8.4(5), other versions may also be affected
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
No known workaround at this time

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug60235</guid>
</item>
<item>
<title>ASA 8.4.4.1 traceback in threadname Datapath, Open CSCuf93071</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf93071</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASA5585-SSP-60 running 8.4.4.1 crashed in threadname &#39;datapath&#39;
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
&lt;br&gt;


&lt;B&gt;Workaround:&lt;/B&gt;

Disable IPS.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuf93071</guid>
</item>
<item>
<title>Connections not timing out when the route changes on the ASA, Open CSCue46275</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue46275</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

Connections on the ASA are not timing out after a route change
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

timeout floating-conn was set to 30 seconds
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

clear out the connections manually

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue46275</guid>
</item>
<item>
<title>Page fault traceback in crypto_lib_keypair_show_mypubkey_all, Fixed CSCtw93059</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtw93059</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASA may traceback in Thread Name ssh when &quot;show crypto key mypubkey rsa&quot; command 
is run.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

This was observed in 8.4(2) release. The trigger is not known yet.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

Do not use the &quot;show crypto key mypubkey rsa&quot; command



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtw93059</guid>
</item>
<item>
<title>ASA traceback in datapath thread with netflow enabled, Fixed CSCue88423</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue88423</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA may reload with traceback in a datapath thread (such as DATAPATH-1-1241) with 
abort type Assert failure. Line like the below will be seen in the crashinfo 
output:

Panic: DATAPATH-1-1241 - Message #93 : spin_lock_fair_mode_enqueue: Lock 
(snp_nf_block_t) is held for a long time, owner: DATAPATH-2-1242, requestor: 
DATAPATH-1-1241
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Netflow is configured and enabled on the ASA.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
1. Disable Netflow or...
2. Disable the flow-teardown filtering

More Info:



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue88423</guid>
</item>
<item>
<title>Cisco ASA config rollback via CSM doesnt work in multi context mode, Fixed CSCuh10827</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh10827</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
The roll-back for Cisco ASA configs via CSM doesnt work with &quot;&quot;aaa authorization comm LOCAL&quot;.

CSM shows rollback completed however the configs are still there on the ASA.

Device HW &amp; SW Details:

HW - Cisco ASA 5585
SW - 8.4.5
CSM - 4.3 (running on VM)
Cisco ACS server - 5.3
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
Cisco ASA in multi-context mode configured with RADIUS authentication with Cisco ACS 5.x and local authorization via &quot;aaa authorization comm LOCAL&quot; and integrated to CSM 4.3.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None

&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh10827</guid>
</item>
<item>
<title>dbgtrace: Adjustable logging buffer Required, Open CSCuh36489</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh36489</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
DAP debugs output hits a limit when the output is more than around 1470 lines. Hence we should have adjustable logging buffer command to adjust the amount of buffer available for such debugs
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
ASA Software Version 9.1(2)
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCuh36489</guid>
</item>
<item>
<title>mrib entries mayy not be seen upon failover initiated by auto-update, Fixed CSCue62470</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue62470</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
In rare conditions upon failover triggered by auto-update server (CSM), ASA may not show any mrib, mfib or mroute entries until multicast-routing is toggled.
&quot;show asp drop&quot; may show huge spike in &quot;No route to host (no-route)&quot; counter..
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
This was first identified on an ASA5520 failover pair running 8.4.3.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Toggle multicast routing.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue62470</guid>
</item>
<item>
<title>ASA runs out of CTM memory when under heavy SSL Load, Terminated CSCtn26868</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtn26868</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

The inability to access the ASA via ASDM and webvpn/AnyConnect.
show asp drop indicates: SSL malloc error (ssl-malloc-error)
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

High load ~200 or more users on AnyConnect/webvpn
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

1. Disable and re-enable webvpn.
2. Reboot

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtn26868</guid>
</item>
<item>
<title>ASA 8.3.1: Traceback with snp_fp_punt_block_free_cleanup, Fixed CSCth80945</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCth80945</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA 5580-20 reloads after normal operation for a number of days.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
ASA 5580 running 8.3.1-release code.
IPsec remote access configured.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None - Use a stateful failover pair to avoid downtime.



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCth80945</guid>
</item>
<item>
<title>IKEv2: ASA does not clear entry from asp table classify crypto, Fixed CSCud28106</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud28106</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Intermittently ikev2 Anyconnect clients are no longer able to access internal resources even though the tunnel gets built just fine.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
1. ikev2 Anyconnect clients
2. ASA 8.4.x
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
1. increase the time period before the ip address is reused from the VPN pool
2. disconnect the user from the ASA.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud28106</guid>
</item>
<item>
<title>ASA shared port-channel subinterfaces and multicontext traffic failure, Fixed CSCue59676</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue59676</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
An ASA configured in multi context mode, with port-channels divided into subinterfaces, may experience an issue where traffic to certain contexts will fail if the port-channel has more than one active TenGigabitEthernet member.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
This was first observed in an environment using 250 contexts with more than 300 subinterfaces.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Reduce the number of contexts or subinterfaces.

Deleting the context experience the problem and reconfiguring it sometimes resolves the issue for that context, but the problem may then move to another context.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue59676</guid>
</item>
<item>
<title>ASA 5580 traceback when CSM attempts deployment, Fixed CSCtu30581</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtu30581</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
ASA 5580 crashes when CSM attempt deployment

SSLVPN/CSD is not enabled on the ASA firewall, however, when CSM (Cisco Security Manager) attempts to make a cofiguration deployment for the ASA (which contains configuration for the Default Group-Policy), the ASA5580 crashes!

CSM version is 4.1 and ASA is 5580 on 8.4.2(11).
Attached is the traceback information I could collect from the console of the firewall during the crash.
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
Seen only when there is a functional interaction between CSM and the ASA 5580 firewall.
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None.


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtu30581</guid>
</item>
   
</channel>
</rss>
