Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.0.2(10) – 05/19/2013

Files:  asa902-10-smp-k8.bin, asa902-10-k8.bin

Defects resolved since 9.0.2:

 

CSCti38856

Elements in the network object group are not converted to network object

CSCtj87870

Failover disabled due to license incompatible different Licensed cores

CSCtr04553

Traceback @snp_ifc_purg_cb w/ clear conf all or write standby

CSCtr17899

Some legitimate traffic may get denied with ACL optimization

CSCtr65927

dynamic policy PAT fails with FTP data due to latter static NAT entry

CSCts15825

RRI routes are not injected after reload if IP SLA is configured.

CSCts50723

ASA: Builds conn for packets not destined to ASA's MAC in port-channel

CSCtw56859

Natted traffic not getting encrypted after reconfiguring the crypto ACL

CSCtx55513

ASA: Packet loss during phase 2 rekey

CSCty18976

ASA sends user passwords in AV as part of config command authorization.

CSCtz46845

ASA 5585 with IPS inline -VPN tunnel dropping fragmented packets

CSCtz47034

ASA 5585- 10 gig interfaces may not come up after asa reload

CSCtz56155

misreported high CPU

CSCtz64218

ASA may traceback when multiple users make simultaneous change to ACL

CSCtz70573

SMP ASA traceback on periodic_handler for inspecting icmp or dns trafic

CSCtz79578

Port-Channel Flaps at low traffic rate with single flow traffic

CSCua20850

5500X Software IPS console too busy for irq can cause data plane down.

CSCua35337

Local command auth not working for certain commands on priv 1

CSCua44723

ASA nat-pat: 8.4.4 assert traceback related to xlate timeout

CSCua60417

8.4.3 system log messages should appear in Admin context only

CSCua87170

Interface oversubscription on active causes standby to disable failover

CSCua91189

Traceback in CP Processing when enabling H323 Debug

CSCua93764

ASA: Watchdog traceback from tmatch_element_release_actual

CSCua99091

ASA: Page fault traceback when copying new image to flash

CSCub04470

ASA: Traceback in Dispatch Unit with HTTP inspect regex

CSCub08224

ASA 210005 and 210007 LU allocate xlate/conn failed with simple 1-1 NAT

CSCub11582

ASA5550 continous reboot with tls-proxy maximum session 4500

CSCub14196

FIFO queue oversubscription drops packets to free RX Rings

CSCub16427

Standby ASA traceback while replicating flow from Active

CSCub23840

ASA traceback due to nested protocol object-group used in ACL

CSCub37882

Standby ASA allows L2 broadcast packets with asr-group command

CSCub58996

ASA: Page fault traceback in Unicorn Proxy Thread with WebVPN

CSCub61578

ASA: Assert traceback in PIX Garbage Collector with GTP inspection

CSCub62584

ASA unexpectedly reloads with traceback in Thread Name: CP Processing

CSCub75522

ASA TFW sends broadcast arp traffic to all interfaces in the context

CSCub84164

ASA traceback in threadname Logger

CSCub85692

ASA crashes in IKE Daemon after reassembling ikev1 pkt in a L2L conn

CSCub89078

ASA standby produces traceback and reloads in IPsec message handler

CSCub99578

High CPU HOG when connnect/disconnect VPN with large ACL

CSCub99704

WebVPN - mishandling of request from Java applet

CSCuc06857

Accounting STOP with caller ID 0.0.0.0 if admin session exits abnormally

CSCuc09055

Nas-Port attribute different for authentication/accounting Anyconnect

CSCuc12119

ASA: Webvpn cookie corruption with external cookie storage

CSCuc12967

OSPF routes were missing on the Standby Firewall after the failover

CSCuc16670

ASA - VPN connection remains up when DHCP rebind fails

CSCuc24547

TCP ts_val for an ACK packet sent by ASA for OOO packets is incorrect

CSCuc24919

ASA: May traceback in Thread Name: fover_health_monitoring_thread

CSCuc28903

ASA 8.4.4.6 and higher: no OSPF adj can be build with Portchannel port

CSCuc32843

ACL not getting migrated correctly (FWSM to ASA-SM with migration tool)

CSCuc34345

Multi-Mode treceback on ci/console copying config tftp to running-config

CSCuc45011

ASA may traceback while fetching personalized user information

CSCuc46026

ASA traceback: ASA reloaded when call home feature enabled

CSCuc46270

ASA never removes qos-per-class ASP rules when VPN disconnects

CSCuc48355

ASA webvpn - URLs are not rewritten through webvpn in 8.4(4)5

CSCuc50544

Error when connecting VPN: DTLS1_GET_RECORD Reason: wrong version number

CSCuc55719

Destination NAT with non single service  (range, gt, lt) not working

CSCuc56078

Traceback in threadname CP Processing

CSCuc60950

Traceback in snpi_divert with timeout floating-conn configured

CSCuc61985

distribute-list does not show in the router config.

CSCuc63592

HTTP inspection matches incorrect line when using header host regex

CSCuc72408

ASA 5580 page fault in thread CERT API during pki validation

CSCuc75090

Crypto IPSec SA's are created by dynamic crypto map for static peers

CSCuc75093

Log indicating syslog connectivity not created when server goes up/down

CSCuc78176

Cat6000/15.1(1)SY- ASASM/8.5(1.14) PwrDwn due to SW Version Mismatch

CSCuc79825

5580 - Thread Name: CP Midpath Processing eip pkp_free_ssl_ctm

CSCuc80080

ASA Unexpectedly Reloads in 'DATAPATH' Thread

CSCuc83059

traceback in fover_health_monitoring_thread

CSCuc83323

XSS in SSLVPN

CSCto50963

ASA SIP inspection - To: in INVITE not translated after 8.3/8.4 upgrade

CSCtr04553

Traceback while cleaning up portlist w/ clear conf all or write standby

CSCtr65927

dynamic policy PAT fails with FTP data due to latter static NAT entry

CSCtx32727

GTP inspect not working in Asymmetric Routing Envirement with ASR group:

CSCtx55513

ASA: Packet loss during phase 2 rekey

CSCty59567

Observing traceback @ ipigrp2_redist_metric_incompatible+88

CSCtz70573

SMP ASA traceback on periodic_handler for inspecting icmp or dns trafic

CSCua13405

Failover Unit Stuck in Cold Standby After Boot Up

CSCua22709

ASA traceback in Unicorn Proxy Thread while processing lua

CSCub50435

Proxy ARP Generated for Identity NAT Configuration in Transparent Mode

CSCub58996

Cisco ASA Clientless SSLVPN CIFS Vulnerability

CSCub63148

With inline IPS and heavy load ASA could drop ICMP or DNS replies

CSCub98434

ASA: Nested traceback in Thread Dispatch Unit - cause: SQLNet Inspection

CSCuc14644

SIP inspect NATs Call-ID in one direction only

CSCuc40450

error 'Drop-reason: (punt-no-mem) Punt no memory' need to be specific

CSCuc55719

Destination NAT with non single service  (range, gt, lt) not working

CSCuc65775

ASA CIFS UNC Input Validation Issue

CSCuc66362

CP Processing hogs in SMP platform causing failover problems, overruns

CSCuc74333

EZVPN: User gets unexpected IUA prompt

CSCuc74758

Traceback: deadlock between syslog lock and host lock

CSCuc92292

ASA may not establish EIGRP adjacency with router due to version issues

CSCuc95774

access-group commands removed on upgrade to 9.0(1)

CSCuc96911

ASASM platform is not exempt from MAC move wait timer

CSCuc98398

ASA writes past end of file system then can't boot

CSCud20080

ASA Allows duplicate xlate-persession config lines

CSCud21307

Traceroute through the ASA does not work properly, always shows dest IP

CSCud21714

BTF traceback in datapth when apply l4tm rule

CSCud28106

IKEv2: ASA does not clear entry from asp table classify crypto

CSCud32111

Deny rules in crypto acl blocks inbound traffic after tunnel formed

CSCud41507

Traffic destined for L2L tunnels can prevent valid L2L from establishing

CSCud42001

Smart Tunnel hangs when list contains more than 80 entries

CSCud43999

Prioritize Failover Control Packets on ASA5585-X CPU Uplinks

CSCud50997

ASA IKEv2 fails to accept incoming IKEV2 connections

CSCud57759

DAP: debug dap trace not fully shown after +1000 lines

CSCud62661

STI Flash write failure corrupts large files

CSCud64725

VPNLB: Lost packet during IKEv1 not retransmitted

CSCud64817

ASA 9.x dropping case sensitive DNS PTR requests

CSCud65506

ASA5585: Traceback in Thread Name:DATAPATH when accessing webvpn urls

CSCud67392

ASA hitless upgrade from 8.2 to 8.4 - ERROR: unable to download policy

CSCud69251

traceback in ospf_get_authtype

CSCud69535

OSPF routes were missing on the Active Firewall after the failover

CSCud70273

ASA may generate Traceback while running packet-tracer

CSCud74941

ASA LDAP Mapping should not map 0 to values with no match

CSCud77352

Upgrade ASA causes traceback with assert during spinlock

CSCud81304

TRACEBACK, DATAPATH-8-2268, Multicast

CSCud84827

ASA 5580 running 8.2(5)13 traceback

CSCud85382

Threat Detection Syslogs from System Context in Multi-context Mode

CSCud85831

Netbios insp translating ip in answer field to mapped ip of WINS server

CSCud86142

Anyconnect using Ikev2 is missing username in syslog messages

CSCud90534

ASA traceback with Checkheaps thread

CSCud98455

ASA: 256 byte blocks depleted when syslog server unreachable across VPN

CSCud99081

Control-plane access-list doesn't filter Anyconnect traffic

CSCue00850

Traceback: snp_syslog fails to recognise parent syslog flow

CSCue01840

ASA-1-743002 message is seen without prior ASA-1-743001 message

CSCue02226

ASA 9.1.1 - WCCPv2 return packets are dropped

CSCue03220

Anyconnect mtu config at ASA not taking effect at client

CSCue04309

TCP connection to multicast MAC - unicast MAC S/ACK builds new TCP conn

CSCue05458

16k blocks near exhaustion - process emweb/https (webvpn)

CSCue09762

Revert change in subnetting rules for splittunnel policy for smarttunnel

CSCue11669

ASA 5505 not Forming EIGRP neighborship after failover

CSCue15533

ASA:Traceback while deleting trustpoint

CSCue17876

Some java applets won't connect via smart tunnel on windows with jre1.7

CSCue18975

ASA: Assertion traceback in DATAPATH thread after upgrade

CSCue25524

Webvpn: Javascript based applications not working

CSCue31622

Secondary Flows Lookup Denial of Service Vulnerability

CSCue32221

LU allocate xlate failed (for NAT with service port)

CSCue33354

Mac version Smart Tunnel with Safari 6.0.1/6.0.2 issue

CSCue35150

ASA in multicontext mode provides incorrect SNMP status of failover

CSCue35343

Memory leak of 1024B blocks in webvpn failover code

CSCue36084

RADIUS Memory Leak on ASA using AD-Agent

CSCue41939

IKEv2 reply missing 4bytes of 0's after UDP header

CSCue48276

ASA drops packets with IP Options received via a VPN tunnel

CSCue54264

WebVPN: outside PC enabled webvpn to management-access inside interface

CSCue55461

ESMTP drops due to MIME filename length >255

CSCue56901

secondary-authentication-server-group cmd breaks Ikev1/IPsec RA VPN auth

CSCue59676

ASA shared port-channel subinterfaces and multicontext traffic failure

CSCue62470

mrib entries mayy not be seen upon failover initiated by auto-update

CSCue62691

ASASM Traceback when issue 'show asp table interface' command

CSCue63881

ASA SSHv2 Denial of Service Vulnerability

CSCue67198

Crypto accelerator resets with error code 23

CSCue67446

The ASA hardware accelerator encountered an error (Bad checksum)

CSCue73708

Group enumeration still possible on ASA

CSCue74372

Anyconnect DTLS idle-timeout is being reset by transmit traffic only

CSCue77969

Character encoding not visible on webvpn portal pages.

CSCue82544

ASA5585 8.4.2 Traceback in Thread Name aaa while accessing Uauth pointer

CSCue84586

re-write fails for javascript generated URL with "\"

CSCue88560

ASA Traceback in Thread Name : CERT API

CSCue98716

move OSPF from the punt event queue to its own event queue

CSCue99041

Smart Call Home sends Environmental message every 5 seconds for 5500-X

CSCuf06633

ASA traceback in Thread Name: UserFromCert

CSCuf07810

DTLS drops tunnel on a crypto reset

CSCuf27008

Webvpn: Cifs SSO fails first attempt after AD password reset

CSCuf27811

ASA: Pending DHCP relay requests not flushed from binding table

CSCuf29783

ASA traceback in Thread Name: ci/console after write erase command

CSCuf34123

ASA 8.3+ l2l tunnel-group name with a leading zero is changed to 0.0.0.0

CSCuf58624

snmp engineID abnormal for asa version 8.4.5 after secondary asa reload

CSCuf65912

IKEv2: VPN filter ACL lookup failure causing stale SAs and traceback

CSCuf77294

ASA traceback with Thread Name: DATAPATH-3-1041

CSCuf77606

ASA-SM traceback in Thread Name: accept/http

CSCuf85295

ASA changes user privilege by vpn tunnel configuration

CSCuf90410

ASA LDAPS authorization fails intermittently

CSCug08285

Webvpn: OWA 2010 fails to load when navigating between portal and OWA

CSCug13534

user-identity will not retain group names with spaces on reboot

CSCug14707

ASA 8.4.4.1 Keeps rebooting when FIPS is enabled: FIPS Self-Test failure

CSCug19491

ASA drops some CX/CSC inspected HTTP packets due to PAWS violation

CSCug23311

cannot access Oracle BI via clentless SSL VPN

CSCug29809

Anyconnect IKEv2:Truncated/incomplete debugs,missing 3 payloads

CSCug30086

ASA traceback on thread Session Manager