Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.4.4(9) – 09/25/2012

Files:  asa844-9-k8.bin, asa844-9-smp-k8.bin

Defects resolved since 8.4.4(5):

 

CSCtj12159

ASA (8.3.2) traceback in Thread Name: DATAPATH-1-1295

CSCts50723

ASA: Builds conn for packets not destined to ASA's MAC in port-channel

CSCtx55814

Newly Added Failover Unit With Lesser License Rejects Configuration

CSCtx82335

Reserve 256 byte block pool for ARP processing

CSCtz06058

ASA NAT: LU allocate xlate failed (for NAT with service port)

CSCtz41928

Traceback: timer assert due to nf_block timer race condition

CSCtz46845

ASA 5585 with IPS inline -VPN tunnel dropping fragmented packets

CSCua28838

ASA:IKEv2 tunnel failure due to IPsec rekey collision

CSCua44704

DAP:Continue/Quarantine messages display French characters incorrectly

CSCua58478

Traceback in Thread Name: CERT API

CSCua60417

8.4.3 system log messages should appear in Admin context only

CSCua68934

ASA: May log 305006 regular translation creation failed messages.

CSCua88376

ASA vulnerable to CVE-2003-0001

CSCua91108

ASA unexpected system reboot with Thread Name: UserFromCert Thread

CSCua92556

ASA sip inspect - Pre-allocate SIP NOTIFY TCP secondary channel

CSCua95621

ASA:write standby command brings down port-channel interface on standby

CSCua99003

WebVPN:"My Mail" option doesn't work for OWA2010

CSCub05748

ASA: Page fault traceback in DATAPATH thread with IPsec traffic

CSCub05888

Asa 5580-20: object-group-search access-control causes failover problem

CSCub06626

ASA may traceback while loading a large context config during bootup

CSCub07976

config factory-default does not clear ssl commands

CSCub09280

ASA Content rewrite HTML content was treated as ajax response

CSCub11582

ASA5550 continous reboot when loading asa84x image

CSCub14196

FIFO queue oversubscription drops packets to free RX Rings

CSCub24113

ASA does not check aaa-server use before removing commands

CSCub28198

ASA Webvpn rewriter compression not working

CSCub28721

Standby ASA has duplicate ACEs for webtype ACLs after 'write standby'

CSCub31151

"idle-timeout = 0" is not able to configure with AnyConnect IKEv2

CSCub37344

ASA ospf redistributing failover interface network

CSCub37882

Standby ASA allows L2 broadcast packets with asr-group command

CSCub39677

ASA Webvpn form POST is not rewritten  8.4.1.8 or later

CSCub59136

ASA: Manual NAT rules are not processed in order

CSCub70946

ASA traceback under threadname Dispatch Unit due to multicast traffic

 

 

Revision:  Version 8.4.4(5) – 07/24/2012

Files:  asa844-5-k8.bin, asa844-5-smp-k8.bin

Defects resolved since 8.4.4(1):

 

CSCsy84937

AUTOCOMPLETE attribute is not disabled for SSL VPNs

CSCtg58074

ASA CRYPTO: Hardware Accelerator Archive File Created

CSCtj39083

ASA 8.3.x not passing multicast traffic when RP address is NAT-ed

CSCtj68732

ASA: DHCP-Relay should forward out interface based on internal gi-addr

CSCtn69856

ASA 1550 byte block depletion in ctm_frag_list

CSCtq78296

ASA 5505 prints message %ASA-1-111111 when adding a new vlan interface

CSCtq84922

ASA admin context memory usage is invalid

CSCtr04553

Traceback on clear config all when mem DFP enab or wr standby on active

CSCtr24705

Traceback seen while running packet-tracer due to Page fault

CSCtr35503

IPV6 router advertisements dropped by multicontext firewall

CSCtr65014

vpn-filter removed incorrectly from ASP table blocks L2L traffic

CSCtr79885

ASA with VoIP memory leak 1% per day on binsize 56

CSCtr83416

Incorrect results returned by SNMP object cipSecGlobalActiveTunnels

CSCtr85499

ASA: Radius MS-CHAPV2 with challenge fails

CSCts16081

ASA Multicontext: allocated interface may not be configurable in context

CSCtt02427

5585 producing 402123 logs and denying AC users w/ aaa failing

CSCtu32847

ASA 8.4(2.1) high memory and traceback in aaa_shim_thread

CSCtw99054

VPN: Bytes RCV and XMT incorrect in session disconnect message

CSCtx03901

1550 byte block leak in socks_proxy_datarelay

CSCtx10196

Webvpn : Javascript rewrite causing login button to be inactive

CSCtx33347

Standby ASA traceback while trying to replicate xlates

CSCtx42698

Traceback in Thread Name: Dispatch Unit

CSCtx52020

Traceback in Thread Name: rtcli async executor process

CSCtx55176

Packet fragmentation issue on IPSec Over TCP

CSCtx60431

Traceback in Thread Name: Dispatch Unit due to Websense URL Filtering

CSCtx83820

ASA 8.x AAA Authentication Listener HTTP Redirect not working with IE9

CSCtx84986

Different PowerSupply number between show inventory/environment

CSCtx86924

ASA: Traceback in purgatory in release of DSH (datastructure handle)

CSCtx98905

ASA traceback with Thread Name: dhcp_daemon

CSCty00372

IPV6 extension header inspection On the ASA 8.4.2 does not work

CSCty03086

To-the-box traffic fails from hosts over L2L vpn tunnel & AnyConnect VPN

CSCty04934

logging debug-trace has issues with lines starting with numbers

CSCty12813

ASA 5585: Traceback after Reload when TCP syslog server unavailable

CSCty27179

NAT Migration Fails with Large Policy NAT ACLs

CSCty33946

ASA5580 traceback after upgrade to 8.4.3.2

CSCty38807

VPN Remote user address assignment failed after RADIUS authentication

CSCty41149

Failover Cluster License Must be Cleared When Failover is Unconfigured

CSCty45900

NAT rules specifying an interface of any removed if an interface deleted

CSCty47007

CSC: Secondary goes to pseudo standby state when failover is enabled

CSCty62368

Traceback with Netflow configuration

CSCty63897

ASA5585-standby traceback during hitless upgrade: 8.4.2.8-->8.4.3

CSCty67141

ASA Traceback when applying Regexes via script

CSCty70661

HTTP Inspection does not understand verb without trailing LWSP

CSCty74915

Chassis serial number is incorrect in call-home message on 5585 platform

CSCty80349

ASA IKEV2 :Unable to establish site to site VPN for specific ident-pairs

CSCty93931

ASA generates traceback message when connected with L2TP/IPsec

CSCty95468

ENH: Add Command to Allow ARP Cache Entries from Non-Connected Subnets

CSCty95742

ASA-4-402116 - error message displays outer instead of inner packet

CSCtz00753

Active ASA5505 interface remains in Waiting state

CSCtz01680

IDFW: SYSLOG 746012 appears twice

CSCtz05457

authentication in esmtp inspection breaks

CSCtz11129

ASA Radius Acct-Delay-Time does not work

CSCtz12435

ASA - dhcp relay - option 252 is not passed down to the clients

CSCtz14107

AJAX - Mis-rendered page layout on IE over WebVPN

CSCtz15503

ASA: Assert tracebacks with GTP inspection

CSCtz26123

ASA traceback in SiteMinder SSO when users log into ssl vpn web portal

CSCtz27402

ASA WebVPN URL Rewrite Failing - Form action with special characters

CSCtz31686

SNMP ciscoRasTooManySessions trap is sent from Standby ASA

CSCtz32065

Traceback in Thread Name accept/http

CSCtz34603

ASA: webvpn removes secure tag from cookies sent by remote server

CSCtz39418

multiple clients can connect with "vpn-simultaneous-logins 1"

CSCtz41926

RA VPN license client fails to request more licenses from the server

CSCtz43942

skinny-inspect intermittently uses odd port for RTP stream

CSCtz44586

ASA VPN IPSEC load balancing causes 1550 block depletion

CSCtz47144

ASA: webvpn secure content should not be cached in local disks

CSCtz56971

ASA SCH - Traceback in thread name: sch_prompt anonymous reporting

CSCtz57006

IPv6 traffic to standby fails in transparent mode

CSCtz58744

Java applet failing at launch over Clientless WebVPN

CSCtz59915

ASA assigned IP address from DHCP to VPN clients randomly fails

CSCtz63143

ASA sip inspect - duplicate pre-allocate secondary pinholes created

CSCtz64589

ASA: Downloading capture via HTTP returns incorrect content-length

CSCtz71022

(VPN-Secondary) Failed to update IPSec failover runtime data on the stan

CSCtz78693

ASA SSLVPN Java RDP Plugin traceback with socket write error exception

CSCtz79983

Incorrect MPF conn counts cause %ASA-3-201011 and DoS condition

CSCtz80888

ASDM Session Replication during Failover

CSCtz81677

Aggregate Auth does not send "88" error code for radius-reject-message

CSCtz82438

Syslog %ASA-4-402123 Printed incorrectly for webvpn traffic

CSCtz82865

SNMP MIB: Equivalent of "show xlate count" command

CSCtz83605

Clientless SSL VPN causes UAC on Win 7 to fail when CSD and ST are used

CSCtz85987

IKEv2 tunnels fail in one direction following rekey-on-data

CSCtz86333

ASA may reload with traceback in Thread Name: vpnfol_thread_msg

CSCtz87164

Deny lines in NAT exemption ACL causes ASA config migration to fail

CSCtz92315

ASA Authorization fails with LDAP for user with any expiration date set

CSCtz92779

ASA accept IKEv2 AC reconnect request once then tear it down

CSCtz92900

ASA generates "The ASA hardware accelerator encountered an error"

CSCtz94135

Syslog 324001 Reason string missing when pkt dropped because of Null TID

CSCtz94191

ASA cut-though proxy stops working if using FQDN ACL

CSCtz97792

Block depletion, embedded web client transmit queue

CSCtz98516

Observed Traceback in SNMP while querying GET BULK for 'xlate count'

CSCtz99950

ASA VPN client connection fails if  'name' is configured the same as TG

CSCua02570

ASA nointeractive trustpoint auth fails with Incorrect fingerprint

CSCua05034

WebVPN:  OWA server sending error message due to missing Canary Value

CSCua12570

Clientless: failed ntlm authentication leads to iobuffer uninitialized

CSCua12688

debug ctl-provider causes traceback

CSCua12795

ASA: High CPU with DTLS sessions and 'crypto engine large-mod-accel'

CSCua16597

Webvpn: RDP ActiveX plugin causes high cpu with IE

CSCua21363

1550 byte block depletion related to TCP

CSCua24960

Traceback in CP Midpath Processing - SSL DHE cipher

CSCua28838

ASA:IKEv2 tunnel failure due to IPsec rekey collision

CSCua29269

ASA: WebVPN Rewrite issue - drop down menu rendering is incorrect

CSCua30564

CPU-hog during line-protocol-up event of 4GE-SSM ports

CSCua35666

ASA: traceback in Thread Name: IPsec message handler,Syslog 602305.

CSCua44445

ASA sends too large TCP payload when ASA MSS < Client MSS

CSCua44530

ASA RA tunnel fails when vlan is set in grppol and XAUTH disabled

CSCua44704

DAP:Continue/Quarantine messages display French characters incorrectly

CSCua45611

pki: import from terminal fails when 'quit' embedded in certificate

CSCua50160

ASA: Page fault traceback in lu_rx with failover and GTP inspection

CSCua58718

ASA pre-defined objects have incorrect port values

CSCua61386

Websense URL Filtering triggers syslog 216004

CSCua62162

Clientless SSL VPN rewriter fails with javascript

CSCua64808

logging debug-trace has issues with radius debugs

CSCua67463

Anyconnect fails to connect after ASA failover due to IP conflict

CSCua72585

Error returned while removing pfs from dynamic crypto map

CSCua74427

Some AAA Server Group names result in blank AAA config

CSCua75061

ASA (8.4.4) Traceback in Thread Name: IKE Daemon, Syslog 402142

CSCua76973

ASA: Some NAT configuration removed on failover upgrade to 8.4(4)

CSCua83032

Some parts of the WebVPN login susceptible to HTTP Response Splitting

CSCua86676

aaa-radius: ASA sending duplicate Radius access request

CSCua89506

ipsecvpn-ikev2: assert Traceback  in Thread Name: IKEv2 Daemon

CSCua92333

Flowcontrol status is OFF on ASA, after enabling it on ASA and switch.

CSCua98019

Cisco script injected in html tags, JS conditional comments

CSCub10537

4096 byte block depletion due to ak47_np_read

CSCub23459

On upgrade to 8.4(4)3 Twice NAT statements may override routing table

 

 

 

Revision:  Version 8.4.4(1) – 06/18/2012

Files:  asa844-1-k8.bin, asa844-1-smp-k8.bin

Defects resolved since 8.4.4:

 

CSCua27134

Traceback in Thread Name: Dispatch Unit

CSCua39593

ASA doesn't fail for Quack auth error with SpykerI/O& Falcon card