<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"> 
  <channel>
  <title>Adaptive Security Device Manager Hot Issues from Cisco TAC</title>
  <link>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</link>
  <description>Hot Issues from Cisco TAC.  Please click the link for complete details.</description>
  <language>en-us</language>

  <managingEditor>wsisk@cisco.com (Wes Sisk)</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com (Cisco Newsroom)</webMaster>
  <pubDate>Mon, 20 May 2013 10:18:40 EDT</pubDate>
  <lastBuildDate>Mon, 20 May 2013 10:18:40 EDT</lastBuildDate>
  <generator>PERL</generator>

  <docs>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</docs>
  <ttl>10080</ttl>

<item>
<title>ASDM 7.0 does not display unidirectional NAT rules with service., Fixed CSCud20548</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud20548</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

Some NAT rules are not visible in ASDM. 
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
ASDM 7.0 
NAT rules with both the &quot;unidirectional&quot; and &quot;no-proxy-arp&quot; keywords. 
ASA 8.3/8.4/8.5/8.6 and 9.0
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
Not needed, the rules are present in configuration and are in operation.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCud20548</guid>
</item>
<item>
<title>Read-only user logged into ASDM-Unauthorized change-password msg appears, Fixed CSCua29422</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCua29422</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
Read-only user logged into ASDM-Unauthorized change-password msg appear
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
login to ASDM using read-only user. Privilege level 5.
&lt;br&gt;&lt;B&gt;Workaround:&lt;/B&gt;
Just press &quot;ok&quot; to proceed further.

&lt;B&gt;PSIRT Evaluation:&lt;/B&gt;
The Cisco PSIRT has evaluated this issue and does not meet the criteria for PSIRT ownership or involvement. This issue will be addressed via normal resolution channels.

If you believe that there is new information that would cause a change in the severity of this issue, please contact psirt@cisco.com for another evaluation.

Additional information on Cisco&#39;s security vulnerability policy can be found at the following URL:

http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCua29422</guid>
</item>
<item>
<title>ENH: ASDM should reconnect to ASA on connection loss, Open CSCsz94175</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsz94175</link>
<description>






&lt;B&gt;Symptom:&lt;/B&gt;

There are permanent connections between the ASDM and the ASA to display stats and logs. These connections might get disconnected due to external factors.

The asdm will not reconnect automatically to the ASA when this happens. This should be done automatically.






&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;




&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

You can reconnect manually by going to the main ASDM page. There In the lower right-hand corner of the main ASDM frame (6th position to the left), there is a 2-computer (connection status) icon.

If you click on that icon a dialog box will be presented offering to reconnect ASDM if needed.



&lt;br&gt;
&lt;B&gt;Further Problem Description:&lt;/B&gt;














</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCsz94175</guid>
</item>
<item>
<title>ASDM 6.4.9 inserting ACL while modifing Group Policy, Fixed CSCua71251</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCua71251</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

While modifing existing Group Policy or adding a new one via:

Remote Access VPN &gt; Network Client Access &gt; Group Policies

The following ACL is adding to ASA configuration:

access-list AnyConnect_Client_Local_Print extended deny ip any any 

access-list AnyConnect_Client_Local_Print extended permit tcp any any eq lpd 

access-list AnyConnect_Client_Local_Print remark IPP: Internet Printing Protocol 

access-list AnyConnect_Client_Local_Print extended permit tcp any any eq
631
access-list AnyConnect_Client_Local_Print remark Windows&#39; printing port

access-list AnyConnect_Client_Local_Print extended permit tcp any any eq
9100
access-list AnyConnect_Client_Local_Print remark mDNS: multicast DNS protocol 

access-list AnyConnect_Client_Local_Print extended permit udp any host xxx.x.x.xxx eq 5353

access-list AnyConnect_Client_Local_Print remark LLMNR: Link Local Multicast Name Resolution protocol 

access-list AnyConnect_Client_Local_Print extended permit udp any host
xxx.x.x.xxx eq 5355
access-list AnyConnect_Client_Local_Print remark TCP/NetBIOS protocol 

access-list AnyConnect_Client_Local_Print extended permit tcp any any eq
137
access-list AnyConnect_Client_Local_Print extended permit udp any any eq netbios-ns
&lt;br&gt;

&lt;B&gt;Conditions:&lt;/B&gt;
Always
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

Use CLI for modifing existing Group Policy or adding a new one 


</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCua71251</guid>
</item>
<item>
<title>ASDM shows incomplete ASA connection table entries, Fixed CSCue46483</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue46483</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASDM ASA Connection Monitoring Table displays incomplete and incorrect entries.

ASDM-&gt; Monitoring -&gt; Proprties -&gt; Connections

For example,  the Source IP and Source Port fields as well as the Idle Time, Sent/Received ones have no entries at all,
while the Destination IP and Destination Ports fields are populated with incorrect entries.

All above are compared to the reference CLI outputs.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

ASA 8.4.5 or 8.4.4
ASDM 7.1.1(52)
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

Either consult CLI or use ASDM 7.1.1(52) with ASA 9.0.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCue46483</guid>
</item>
<item>
<title>Sorting ASDM connections table by sent/received sorts lexicographically, Fixed CSCto34582</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCto34582</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;
This is a cosmetic issue only.

When viewing the table of active connections in ASDM, if the list is sorted by data &quot;sent/received&quot; then the connections are sorted in lexicographical order. So it might appear like this:

Connection C - Data Sent 9 K
Connection A - Data Sent 9 MB

ASDM shows that 9K is &quot;more&quot; than 9 MB, since &#39;K&#39; comes before &#39;M&#39; in the alphabet. It should sort the connections by the actual number of bytes transferred on the connection.
&lt;br&gt;&lt;B&gt;Conditions:&lt;/B&gt;
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;
None within ASDM. Use the &#39;show conn&#39; command on the ASA command line to view the active connections through the ASA
&lt;B&gt;More Info:&lt;/B&gt;



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCto34582</guid>
</item>
<item>
<title>HAS wizard fails license check incorrectly, Fixed CSCtz65316</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtz65316</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

ASDM HAS wizard fails license check incorrectly.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;
&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtz65316</guid>
</item>
   
</channel>
</rss>
