Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.3.1(6) – 06/15/2010

Files:  asa831-6-k8.bin, asa831-6-smp-k8.bin

Defects resolved since 8.3.1.4:

 

CSCsm98354

No accounting packet for some commands

CSCtc22965

FIPS ASA will not pass FIPS POST in 8.2

CSCtd93962

NAT with ACL statements causing long time to reboot.

CSCte15729

5580 traceback at CP process while running 600 calls on 2 trunks

CSCte91045

Dhcpd incorrectly sends DHCPNAK

CSCtf23469

ASA 8.0.5+ webvpn FTP bookmarks no longer will pass embedded user/pass

CSCtf42412

Saving files in microsoft word on sharepoint through webvpn fails

CSCtf63794

ASA traceback when adding static nat command

CSCtf67172

Links using macro substitution in portal bookmarks greyed out in 8.3.1

CSCtf69301

Copy /pcap capture fails when packet larger than 2k

CSCtf73359

ASA uses different source IP for data traffic of passive FTP connection

CSCtf89372

Manual NAT rule (inside,any) source static always takes precedence

CSCtg11699

ASA high CPU in DHCP Proxy thread

CSCtg14125

ASA: cannot create _vpn object-group

CSCtg14750

Dynamic-filter syslogs 338004 and 338008 show '0' for src and dest ports

CSCtg20177

Clientless WebVPN not working with SAP Release 3 adobe forms

CSCtg25510

ASA tracebacks in Thread Name: IPsec message handler

CSCtg29897

ASDM is not able to upload DAP selection configuration

CSCtg36637

HEAD requests blocked from a web folder handler processing

CSCtg39859

ASA MAC Smart tunnel file upload fails after about 200 KB

CSCtg45851

Traceback: CP Processing

CSCtg45916

Don't do DAP re-validation at svc re-key and new tunnel generation

CSCtg46175

Xlate Idle Timer Incorrectly Refreshed by Dropped Packets

CSCtg48603

ASA traceback in Thread Name: Dispatch Unit

CSCtg61032

RDP ActiveX Plugins fails with 8.3.1 when ASA has CA Heirarchy

CSCtg63818

Memory leak when using certs for SSL AAA

CSCtg74608

WEBVPN: PDF form button doesn't work with secure link

CSCtg79235

OCSP: Need allow some slop on time check for OCSP response

 

 

Revision:  Version 8.3.1(4) – 05/14/2010

Files:  asa831-4-k8.bin, asa831-4-smp-k8.bin

Defects resolved since 8.3.1.1:

 

CSCsd99542

Configure fail state link without IP addr causes LAND attack syslogs

CSCso65967

SIP builds many secondary conns with register msg but no registrar

CSCso82706

'show mroute' output has null Outgoing Interface List for (S,G) entry

CSCtb20340

Removed ACL permits inbound packets

CSCtc30025

PP: Incorrect Entry Installed in ASP Table for proxy-server command

CSCtd29482

Traceback with Logging flash-bufferwrap configured and heavy logging

CSCtd36422

TCP proxy in SIP inspection causing 1550 block deplete temporarily

CSCtd55121

4GE-SSM will not transmit all fragments

CSCtd86281

FTP download for files larger than 2GB doesn't work properly

CSCte29198

mcast pkts can interfere w/ other punts on the DP-to-CP queue

CSCte45632

Standby ASA shows ready when its has no communication to active ASA

CSCte55194

"possible channel leak" when loading with large configuration

CSCte58070

ASA 8.2 webvpn custom login page shows Javascript error with IE

CSCte62729

ASA5580 traceback in Thread Name: fover_FSM_thread

CSCte64811

ASA 8.04 - certificate chain not being sent during rekey w/ IPSEC RA

CSCte65315

WebVPN user-storage does not work if user logon as DOMAIN\Username

CSCte72114

SSH process may exist after being orphaned from SSH session

CSCte98818

LDAP authentication stops operating to Win2008 srvr after sometime

CSCtf06292

ASA doesn't handle chunk encoding correctly

CSCtf22332

Thread Name: netfs_thread_init

CSCtf24681

SNAP frames are sent from Management interface in Transparent mode ASA

CSCtf25808

ICMP error messages dropped in multi-context asymmetric routing mode

CSCtf28464

Memory Leak In CIFS can casue memory depletion

CSCtf28467

Copy to disk0 without ":", prefills dest as disk0, cant delete/view file

CSCtf29867

Memory leak happens due to huge number of LDAP authentication failure

CSCtf30557

show failover command authorization not available

CSCtf33469

ASA 8.0.5 1550 block depletion with ASDM open

CSCtf42516

ASA 5580 8.2(2) traceback with traffic across 10 Gig interfaces

CSCtf46612

Option to change Pane Title missing from customization editor

CSCtf47041

Active ASA unit tracebacks in Thread Name: ssh

CSCtf48558

IPSec traffic not working after failover

CSCtf49095

ldap-dn password is in the clear within running config

CSCtf49636

asa standby unit reboots after acl config changes

CSCtf52703

ASA/w 4-GE-SSM shows module status unresponsive after power surge

CSCtf54034

DHCP learned route may not be removed at end of lease time

CSCtf54627

Certificate map fails to match with case sensitive SAN

CSCtf55116

quiting "show controller" command with 'q' key triggers failover

CSCtf55261

ASA5580  high frequency tracebacks after upgrade 8.1.2 to 8.2.2

CSCtf60571

ASA 8.2.2 memory leak in inspect

CSCtf62302

RST sent over L2L is dropped by peer due to tcp-rstfin-ooo

CSCtf67122

ASA crashes when trying to print syslog 444110 in Thread Name: ms-client

CSCtf68934

Standby Unit not getting session replicated, rerr TCP and UDP increasing

CSCtf69322

ISAKMP Packet decode for IKE-Frag shows incorrect Frag ID (byte-swap)

CSCtf72654

timebased license of shared license participant feature is broken

CSCtf73728

ASA PKI: OCSP request does not contain host header

CSCtf81534

Received unexpected event EV_TERMINATE in state MM_SND_MSG6_H

CSCtf85135

Add nano sleep to cp process suspend handling

CSCtf91831

call-home send CMD email - may fail with Lone CR or LF in headers

CSCtg01286

ASA 8.3 fails to connect L2TP IPSec client with NAT-T

CSCtg13981

ASA doesn't set correct MIME type for CSS files

CSCtg17779

Flows torndown over VPN tunnel log 302014 with Flow closed by inspection

CSCtg21370

%ASA-5-711005 generated when a L2TP client connects

CSCtg28821

ASA:  AAA Session limit [2048] reached when xauth is disabled for vpn

CSCsd99542

Configure fail state link without IP addr causes LAND attack syslogs

CSCso65967

SIP builds many secondary conns with register msg but no registrar

CSCso82706

'show mroute' output has null Outgoing Interface List for (S,G) entry

CSCtb20340

Removed ACL permits inbound packets

CSCtc30025

PP: Incorrect Entry Installed in ASP Table for proxy-server command

CSCtd29482

Traceback with Logging flash-bufferwrap configured and heavy logging

CSCtd36422

TCP proxy in SIP inspection causing 1550 block deplete temporarily

CSCtd55121

4GE-SSM will not transmit all fragments

CSCtd86281

FTP download for files larger than 2GB doesn't work properly

CSCte29198

mcast pkts can interfere w/ other punts on the DP-to-CP queue

CSCte45632

Standby ASA shows ready when its has no communication to active ASA

CSCte55194

"possible channel leak" when loading with large configuration

CSCte58070

ASA 8.2 webvpn custom login page shows Javascript error with IE

CSCte62729

ASA5580 traceback in Thread Name: fover_FSM_thread

CSCte64811

ASA 8.04 - certificate chain not being sent during rekey w/ IPSEC RA

CSCte65315

WebVPN user-storage does not work if user logon as DOMAIN\Username

CSCte72114

SSH process may exist after being orphaned from SSH session

CSCte98818

LDAP authentication stops operating to Win2008 srvr after sometime

CSCtf06292

ASA doesn't handle chunk encoding correctly

CSCtf22332

Thread Name: netfs_thread_init

CSCtf24681

SNAP frames are sent from Management interface in Transparent mode ASA

CSCtf25808

ICMP error messages dropped in multi-context asymmetric routing mode

CSCtf28464

Memory Leak In CIFS can casue memory depletion

CSCtf28467

Copy to disk0 without ":", prefills dest as disk0, cant delete/view file

CSCtf29867

Memory leak happens due to huge number of LDAP authentication failure

 

 

Revision:  Version 8.3.1(1) – 04/12/2010

Files:  asa831-1-k8.bin, asa831-1-smp-k8.bin

Defects resolved since 8.3.1:

 

CSCsw85251

dhcp-network-scope ip that matches interface can cause route deletion

CSCsz48653

WARNING: The vlan id entered is not currently configured under any int

CSCsz62566

ASA 8.0(4) traceback in Dispatch Unit due to stack corruption

CSCta02877

Traceback in unicorn thread (outway_buffer_i)

CSCtb10530

Remove "sysopt nat-convert enable | start" support for broadview/main

CSCtb23281

ASA: SIP inspect not opening pinhole for contact header of SIP 183 msg

CSCtb36994

tcp-intercept doesn't start 3WH to inside

CSCtc16148

SLA monitor fails to fail back when ip verify reverse is applied

CSCtc81874

Traceback: CTM message handler - L2TP and crypto reset - stack overflow

CSCtd32984

SNAP frame with MAC address learned on management-only interface is sent

CSCtd36473

IPsec: Outbound context may be deleted prematurely

CSCtd37097

AnyConnect 2.4 can't connect but both auths are successful

CSCtd53356

ASA traceback when new DHCPD commands entered

CSCtd55032

ASA running 8.0.4.32 traceback in Thread Name: Dispatch Unit

CSCtd56249

CTA does not respond for EAP from ASA 8.0.5 with NAC

CSCtd60720

Error event causes Syslog 199011 "Close on bad channel in process/fiber"

CSCtd74691

VPN session not replicate to Standby after Failover State Link failure

CSCtd86281

FTP download for files larger than 2GB doesn't work properly

CSCtd87194

ASA5580 drops outbound ESP pkt if original pkt needs to be fragmented

CSCtd94385

ASA: Unable to pass traffic through an Airlink router w DTLS enabled

CSCte05514

CA ServiceDesk hidden frame not showing

CSCte08753

Fails to export Local CA Cert after rebooting ASA

CSCte11340

ASA SSL/TLS client sends TLSv1 handshake record in SSLv3 compat mode

CSCte15462

Disable URL entry should only disable http/https

CSCte25727

ASA unable to assign users policy when cancelling change password option

CSCte25741

ASA doesn't allow username length of <4 characters

CSCte38909

msgid in Language Localization are not synchronized

CSCte38942

SSL sockets stuck in CLOSE_WAIT status using webvpn

CSCte43903

ASA5580 traceback in thread DATAPATH-2-476, eip rt_timer_cancel_callback

CSCte57663

VPN user cannot ping to inside interface with management-access config

CSCte58070

ASA 8.2 webvpn custom login page shows Javascript error with IE

CSCte58507

AC Essentials not enabled w/ active ssl session should provide msg

CSCte65315

WebVPN user-storage does not work if user logon as DOMAIN\Username

CSCte72846

OWA 2003 To, CC, BCC buttons in address book does not work with webvpn

CSCte92557

ASA HW client: deny rule for DHCP should account for remote subnets

CSCte94184

FO: "service resetoutside" exists only in standby unit after failover

CSCtf02322

ASA - Memory depleting 1% per day due to snmp-server ipsec configuration

CSCtf02712

Traceback in Dispatch Unit (Old pc 0x08180444 ebp 0xc793d980)

CSCtf13556

Slow memory leak in WebVPN related to CIFS cache

CSCtf49620

IKE not passing Cert attr to LDAP server causing Authorization failure