Release Notes for the Cisco Secure Firewall ASA, 9.22(x)

This document contains release information for ASA software version 9.22(x).


Note


9.22(1) was not released. The first release was 9.22(1.1).


Important Notes

  • No support in ASA 9.22(1) and later for the Firepower 2100—ASA 9.20(x) is the last supported version.

  • Smart licensing default transport changed in 9.22—In 9.22, the smart licensing default transport changed from Smart Call Home to Smart Transport. You can configure the ASA to use Smart Call Home if necessary using the transport type callhome command. When you upgrade to 9.22, the transport is automatically changed Smart Transport. If you downgrade, the transport is set back to Smart Call Home, and if you want to use Smart Transport, you need to specify transport type smart . Note also that the licensing URL for Smart Transport is https://smartreceiver.cisco.com (compared to tools.cisco.com), so be sure to allow that URL on upstream routers.

  • For models with built-in-switches, subinterfaces can't use VLAN 1 in 9.22 and later—For models with built-in switches, you cannot create a subinterface using VLAN 1. VLAN 1 is reserved for the logical VLAN interface for switch ports. If you upgrade a 1010 to 9.22(1) or later, and you have assigned VLAN 1 to a subinterface, you must first change the VLAN ID for your subinterface to a new VLAN. After upgrading, if present, VLAN 1 will be removed from the subinterface.

New Features

This section lists new features for each release.


Note


New, changed, and deprecated syslog messages are listed in the syslog message guide.


New Features in ASA 9.22(3)

Released: March 26, 2026

Feature

Description

Firewall Features

Changed output for the show access-list element-count and show asp table network-object commands.

The show access-list element-count command now shows 2 counts: total number of objects, and total number of access control entries.

The show asp table network-object count information includes new counters for the number of additions to the source table and number of those additions to the source table that are duplicate. In addition, the Hitcnt (hit count) column was removed.

New/Modified commands: show access-list element-count , show asp table network-object

High Availability and Scalability Features

ASAc High Availability and SR-IOV feature enablement

This enables High Availability (HA) support for ASA container (ASAc) deployments in Docker and Kubernetes environments. Two ASAc container instances can be deployed on separate Docker hosts and configured as a primary–secondary failover pair.

SR-IOV feature supports single Root I/O virtualization (SR-IOV) interfaces in ASAc container deployments within Docker and Kubernetes environments.

Administrative, Monitoring, and Troubleshooting Features

SSH X.509 certificate authentication

You can now use an X.509v3 certificate to authenticate a user for SSH (RFC 6187).

For the Firepower 4100/9300, you need version 2.16(2.109+).

New/Modified commands: aaa authorization exec ssh-x509 , ssh authentication method , ssh trustpoint sign, ssh username-from-certificate , validation-usage ssh-client

Also in 9.20(4), 9.24(1).

AES-256-GCM SSH cipher

The ASA supports the AES-256-GCM cipher for SSH. It is enabled by default for all and high encryption levels.

New/Modified commands: ssh cipher encryption

Also in 9.20(4), 9.24(1).

Message-of-the-day (motd) banner shows the failover state and the last failover time

When using failover, if you configure the banner motd command, then the banner shows information about the failover state and the last failover time of the unit you are logging into. This information is useful if you are performing actions at the CLI, such as troubleshooting, and a failover occurs between sessions.

New or modified commands: banner motd

Also in 9.24(1).

Automated Certificate Management Environment (ACME) protocol for TLS device certificates.

You can configure Automated Certificate Management Environment (ACME) protocol to ASA trustpoint to manage the TLS device certificates. ACME enables simplified certificate management through auto renewal, domain validation, and easy enrolling and revoking of certificates. You can choose to use the Let's Encrypt CA server or use any other ACME server for the authentication. ACME uses http01 method for authentication.

New or modified commands: crypto ca trustpoint enrollment protocol crypto ca authenticate

Also in 9.23(1).

Display of UDP's initiator and responder values in connection status output

For UDP traffic flows, the ASA displays the initiator and responder field values in the connection detail status. These field values indicate the direction of communication, which helps in troubleshooting network connectivity issues.

New/Modified commands: show conn detail

Also in 9.20(4), 9.24(1).

Block depletion monitoring in failover and standalone units

When block depletion occurs, the ASA collects troubleshooting logs and sends out a syslog. For failover, the ASA fails over to the standby unit. The ASA can also force a crash and reload to recover from depletion.

Added/modified commands: fault-monitor , block-depletion .

Also in 9.23(1).

New Features in ASA 9.22(2)

Released: April 10, 2025

There are no new features in this release.

New Features in ASA 9.22(1.1)

Released: September 16, 2024


Note


9.22(1) was not released.


Feature

Description

Platform Features

Secure Firewall 1210/1220

The Secure Firewall 1210/1220 is a compact desktop firewall with a built-in switch and, depending on the model, Power over Ethernet+ (PoE+).

  • Secure Firewall 1210CE—Includes 8 1Gbps RJ-45 copper data ports.

  • Secure Firewall 1210CP—Includes PoE+ on four of those ports.

  • Secure Firewall 1220CX—Includes two additional 10Gbps SFP+ ports and higher performance.

ASA Virtual Supports Dual-Arm Deployment Mode on AWS with GWLB

ASA Virtual now supports the dual-arm deployment mode on AWS with GWLB. This mode enables ASA Virtual to directly forward internet-bound traffic to the internet through the internet gateway after traffic inspection, while also performing network address translation (NAT).

The dual-arm mode differs from the single-arm mode, which helps in routing inspected outbound traffic back to the GWLB, and then to the internet through the internet gateway.

The dual-arm mode supports forwarding of inspected traffic from ASA Virtual to the internet in both single VPC and multiple VPC network environments.

The advantages of the dual-arm mode in ASA Virtual are:

  • Minimize traffic hops, thereby reducing traffic latency and improving throughput performance.

  • Consolidate and inspect outbound traffic from multiple VPCs before forwarding it to the internet.

  • Provide a cost-effective solution because of reduced infrastructure requirements.

For more information, see Cisco Secure Firewall ASA Virtual Getting Started Guide, 9.22.

Deploy the Cisco Secure Firewall ASA container (ASAc) in a Kubernetes or Docker Environment

A container is a software package that bundles up code and associated requirements such as system libraries, system tools, default settings, and so on, to ensure that the application runs successfully in a computing environment. You can deploy the ASA container (ASAc) in an open-source Kubernetes or Docker environment.

ASA Virtual on VMware ESXi support

ASA Virtual on VMware now supports ESXi version 8.0.

For more information, see Cisco Secure Firewall ASA Virtual Getting Started Guide, 9.22.

Firewall Features

Object group search optimization.

The object group search feature has been enhanced to reduce object lookup time when evaluating access control rules to match connections and to reduce CPU overhead. There are no changes to configuring object group search, the optimized behavior happens automatically.

We added the following commands in the device CLI, or enhanced command output: clear asp table network-object , debug ac logs , packet-tracer , show access-list , show asp table network-group , show object-group .

High Availability and Scalability Features

Secure Firewall 3100 and 4200 maximum cluster nodes increased to 16.

For the Secure Firewall 3100 and 4200, the maximum nodes were increased from 8 to 16.

Secure Firewall 3100 and 4200 cluster Individual interface mode

Individual interfaces are normal routed interfaces, each with their own Local IP address used for routing. The Main cluster IP address for each interface is a fixed address that always belongs to the control node. When the control node changes, the Main cluster IP address moves to the new control node, so management of the cluster continues seamlessly.

Load balancing must be configured separately on the upstream switch.

New/Modified commands: cluster interface-mode individual

ASA Virtual Clustering deployment support on the AWS Multi-Availability Zone

You can now deploy and configure the ASA virtual cluster across multiple availability zones in an AWS region. The cluster also has dynamic scaling capability (Autoscale), which helps in scaling up or scaling down virtual devices based on demand.

Extending the ASA virtual cluster across multiple availability zones in an AWS region enables continuous traffic inspection and dynamic scaling during disaster recovery.

For more information, see Deploy a Cluster for the ASA Virtual in a Public Cloud.

MTU ping test on cluster node join

When a node joins the cluster, it checks MTU compatibility by sending a ping to the control node with a packet size matching the cluster control link MTU. If the ping fails, a notification is generated so you can fix the MTU mismatch on connecting switches and try again.

Interface Features

For models with built-in-switches, subinterfaces can't use VLAN 1

For models with built-in switches, you cannot create a subinterface using VLAN 1. VLAN 1 is reserved for the logical VLAN interface for switch ports.

If you upgrade a 1010 to 9.22(1) or later, and you have assigned VLAN 1 to a subinterface, you must first change the VLAN ID for your subinterface to a new VLAN. After upgrading, VLAN 1 will be removed from the subinterface.

License Features

Smart Transport is the default Smart Licensing transport

Smart Licensing now uses Smart Transport as the default transport. You can optionally enable the former type, Smart Call Home, if necessary.

New/Modified commands: transport proxy , transport type , transport url

ASAvU (Unlimited) license to deploy ASA virtuals with 32 cores and 64 cores

ASAvU license achieves maximum throughput on deployments with 32 cores and 64 cores and is supported only on VMware and KVM.

New/Modified commands: throughput level unlimited

Administrative, Monitoring, and Troubleshooting Features

Disable the USB port (disk1)

By default, the type-A USB port (disk1) is enabled and could not be disabled. You can now disable USB port access for security purposes on the following models:

  • Firepower 1000

  • Secure Firewall 3100

  • Secure Firewall 4200

This setting is stored in firmware and requires a reload. Moreover, if the USB port is disabled and you downgrade to a version that does not support this feature, the port will remain disabled and you cannot re-enable it without erasing the NVRAM.

Note

 

This feature does not affect the type-B USB console port, if present.

New/Modified commands: usb-port disable , show usb-port

Block depletion monitoring in failover and standalone units

When block depletion occurs, the ASA collects troubleshooting logs and sends out a syslog. For failover, the ASA fails over to the standby unit. The ASA can also force a crash and reload to recover from depletion.

Added/modified commands: fault-monitor , block-depletion .

VPN Features

DTLS Crypto Acceleration

Cisco Secure Firewall 4200 and 3100 series support DTLS cryptographic acceleration. The hardware performs DTLS encryption and decryption, and improves the throughput of the DTLS-encrypted and DTLS-decrypted traffic. The hardware also performs optimization of the egress-encrypted packets to improve latency.

New/Modified commands: flow-offload-dtls , flow-offload-dtls egress-optimization

Upgrade the Software

This section provides the upgrade path information and a link to complete your upgrade.

Upgrade Path: ASA Appliances

What Version Should I Upgrade To?

On the Cisco Support & Download site, the suggested release is marked with a gold star. For example:

Figure 1. Suggested Release
Suggested Release

View Your Current Version

To view your current version and model, use one of the following methods:

  • ASDM: Choose Home > Device Dashboard > Device Information.

  • CLI: Use the show version command.

Upgrade Guidelines

Be sure to check the upgrade guidelines for each release between your starting version and your ending version. You may need to change your configuration before upgrading in some cases, or else you could experience an outage.

For guidance on security issues on the ASA, and which releases contain fixes for each issue, see the ASA Security Advisories.

Upgrade Paths

This table provides upgrade paths for ASA.


Note


ASA 9.20 was the final version for the Firepower 2100.

ASA 9.18 was the final version for the Firepower 4110, 4120, 4140, 4150, and Security Modules SM-24, SM-36, and SM-44 for the Firepower 9300.

ASA 9.16 was the final version for the ASA 5506-X, 5508-X, and 5516-X.

ASA 9.14 was the final version for the ASA 5525-X, 5545-X, and 5555-X.

ASA 9.12 was the final version for the ASA 5512-X, 5515-X, 5585-X, and ASASM.

ASA 9.2 was the final version for the ASA 5505.

ASA 9.1 was the final version for the ASA 5510, 5520, 5540, 5550, and 5580.


Table 1. Upgrade Path

Current Version

Interim Upgrade Version

Target Version

9.20

Any of the following:

→ 9.22

9.19

Any of the following:

→ 9.22

→ 9.20

9.18

Any of the following:

→ 9.22

→ 9.20

→ 9.19

9.17

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

9.16

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

9.15

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.14

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.13

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.12

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.10

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.9

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.8

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.7

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.6

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.5

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.4

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.3

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

9.2

Any of the following:

→ 9.22

→ 9.20

→ 9.19

→ 9.18

→ 9.17

→ 9.16

Upgrade Path: ASA Logical Devices for the Firepower 4100/9300

  • FXOS: From FXOS 2.2.2 and later, you can upgrade directly to any higher version. (FXOS 2.0.1–2.2.1 can upgrade as far as 2.8.1. For versions earlier than 2.0.1, you need to upgrade to each intermediate version.) Note that you cannot upgrade FXOS to a version that does not support your current logical device version. You will need to upgrade in steps: upgrade FXOS to the highest version that supports your current logical device; then upgrade your logical device to the highest version supported with that FXOS version. For example, if you want to upgrade from FXOS 2.2/ASA 9.8 to FXOS 2.13/ASA 9.19, you would have to perform the following upgrades:

    1. FXOS 2.2 → FXOS 2.11 (the highest version that supports 9.8)

    2. ASA 9.8 → ASA 9.17 (the highest version supported by 2.11)

    3. FXOS 2.11 → FXOS 2.13

    4. ASA 9.17 → ASA 9.19

  • Firewall Threat Defense: Interim upgrades may be required for Firewall Threat Defense, in addition to the FXOS requirements above. For the exact upgrade path, refer to the Firewall Management Center upgrade guide for your version.

  • ASA: ASA lets you upgrade directly from your current version to any higher version, noting the FXOS requirements above.

Table 2. Firepower 4100/9300 Compatibility with ASA and Firewall Threat Defense

FXOS Version

Model

ASA Version

Firewall Threat Defense Version

2.16

Firepower 4112

9.22 (recommended)

9.20

9.19

9.18

9.17

7.6 (recommended)

7.4

7.3

7.2

7.1

Firepower 4145

Firepower 4125

Firepower 4115

9.22 (recommended)

9.20

9.19

9.18

9.17

7.6 (recommended)

7.4

7.3

7.2

7.1

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

2.14(1)

Firepower 4112

9.20 (recommended)

9.19

9.18

9.17

9.16

9.14

7.4 (recommended)

7.3

7.2

7.1

7.0

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.20 (recommended)

9.19

9.18

9.17

9.16

9.14

7.4 (recommended)

7.3

7.2

7.1

7.0

6.6

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

2.13

Firepower 4112

9.19 (recommended)

9.18

9.17

9.16

9.14

7.3 (recommended)

7.2

7.1

7.0

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.19 (recommended)

9.18

9.17

9.16

9.14

7.3 (recommended)

7.2

7.1

7.0

6.6

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

2.12

Firepower 4112

9.18 (recommended)

9.17

9.16

9.14

7.2 (recommended)

7.1

7.0

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.18 (recommended)

9.17

9.16

9.14

9.12

7.2 (recommended)

7.1

7.0

6.6

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.18 (recommended)

9.17

9.16

9.14

9.12

7.2 (recommended)

7.1

7.0

6.6

6.4

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.11

Firepower 4112

9.17 (recommended)

9.16

9.14

7.1 (recommended)

7.0

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.17 (recommended)

9.16

9.14

9.12

7.1 (recommended)

7.0

6.6

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.17 (recommended)

9.16

9.14

9.12

9.8

7.1 (recommended)

7.0

6.6

6.4

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.10

Note

 

For compatibility with 7.0.2+ and 9.16(3.11)+, you need FXOS 2.10(1.179)+.

Firepower 4112

9.16 (recommended)

9.14

7.0 (recommended)

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.16 (recommended)

9.14

9.12

7.0 (recommended)

6.6

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.16 (recommended)

9.14

9.12

9.8

7.0 (recommended)

6.6

6.4

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.9

Firepower 4112

9.14

6.6

Firepower 4145

Firepower 4125

Firepower 4115

9.14

9.12

6.6

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.14

9.12

9.8

6.6

6.4

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.8

Firepower 4112

9.14

6.6

Note

 

6.6.1+ requires FXOS 2.8(1.125)+.

Firepower 4145

Firepower 4125

Firepower 4115

9.14 (recommended)

9.12

Note

 

Firepower 9300 SM-56 requires ASA 9.12(2)+

6.6 (recommended)

Note

 

6.6.1+ requires FXOS 2.8(1.125)+.

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.14 (recommended)

9.12

9.8

6.6 (recommended)

Note

 

6.6.1+ requires FXOS 2.8(1.125)+.

6.4

6.2.3

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.6(1.157)

Note

 

You can now run ASA 9.12+ and FTD 6.4+ on separate modules in the same Firepower 9300 chassis

Firepower 4145

Firepower 4125

Firepower 4115

9.12

Note

 

Firepower 9300 SM-56 requires ASA 9.12.2+

6.4

Firepower 9300 SM-56

Firepower 9300 SM-48

Firepower 9300 SM-40

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.12 (recommended)

9.8

6.4 (recommended)

6.2.3

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.6(1.131)

Firepower 9300 SM-48

Firepower 9300 SM-40

9.12

Not supported

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.12 (recommended)

9.8

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.3(1.73)

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.8

Note

 

9.8(2.12)+ is required for flow offload when running FXOS 2.3(1.130)+.

6.2.3 (recommended)

Note

 

6.2.3.16+ requires FXOS 2.3.1.157+

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.3(1.66)

2.3(1.58)

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.8

Note

 

9.8(2.12)+ is required for flow offload when running FXOS 2.3(1.130)+.

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

2.2

Firepower 4150

Firepower 4140

Firepower 4120

Firepower 4110

9.8

Firewall Threat Defense versions are EoL

Firepower 9300 SM-44

Firepower 9300 SM-36

Firepower 9300 SM-24

Note on Downgrades

Downgrade of FXOS images is not officially supported. The only Cisco-supported method of downgrading an image version of FXOS is to perform a complete re-image of the device.

Open and Resolved Bugs

The open and resolved bugs for this release are accessible through the Cisco Bug Search Tool. This web-based tool provides you with access to the Cisco bug tracking system, which maintains information about bugs and vulnerabilities in this product and other Cisco hardware and software products.


Note


You must have a Cisco.com account to log in and access the Cisco Bug Search Tool. If you do not have one, you can register for an account. If you do not have a Cisco support contract, you can only look up bugs by ID; you cannot run searches.


For more information about the Cisco Bug Search Tool, see the Bug Search Tool Help & FAQ.

Open Bugs in Version 9.22(x)

The following table lists select open bugs at the time of this Release Note publication.

Identifier

Headline

CSCws68206

ASA on hyper-v: couldn't configure VLAN after upgrade

CSCwt25171

Inconsistent LINA hostname synchronization between ASA/FTD HA/failover units

CSCwt51095

ASA/FTD Traceback and reload in BGP

CSCwt55393

ASA may traceback and reload in Thread Name "lina_get_block_mask"

CSCwt55431

FPR42xx - Multi-Instance FTD fails to start with error "Insufficient shaping queue, resource allocation is pending"

CSCwt55776

BGP unexpectedly removes all routes from BGP table during failover tests.

CSCwt57790

ciscossh stack: OTP-based SSH authentication via RADIUS fails

CSCwt58822

Few FQDN's only sending IPV6 request but not IPV4 request

CSCwt62145

ARP requests are not forwarded to all FTDs on the chassis in multi-instance deployment

CSCwt63593

FTD is not resolving several FQDN's for ACL's after upgrade to 7.6.4

CSCwt66012

show inventory reports transceiver PID as numeric internal value instead of Cisco SKU

Resolved Bugs

This section lists resolved bugs per release.

Resolved Bugs in Version 9.22(3)

The following table lists select resolved bugs at the time of this Release Note publication.

Identifier

Headline

CSCvh98118

"logging debug-trace persistent" fails for "debug ip ..." related debugs

CSCvm76755

DP-CP arp-in and adj-absent queues need to be separated

CSCwa38880

Order of access-list/ access-group is different in standby unit. Full sync happens during node-join.

CSCwb07908

Standby FTD/ASA sends DNS queries with source IP of 0.0.0.0

CSCwd92327

on 2k platform, external authentication fails for users starting with number

CSCwf04460

The fxos directory disappears after cancelling show tech fprm detail command with Ctr+c is executed.

CSCwf25454

Stale anyconnect entries causing issues with routing

CSCwf72285

DAP: debug dap trace not fully shown after 3000+ lines

CSCwh10931

ASA/FTD traceback and reload when invoking "show webvpn saml idp" CLI command

CSCwh53745

ASA: unexpected logs for initiating inbound connection for DNS query response

CSCwi72410

Member interface admin status is not updated on Lina after enabling port-channel interface

CSCwk07934

Clock skew between FXOS and Lina causes SAML assertion processing failure

CSCwk09488

Incorrect syslog generated on failure to process SGT from ISE during RA authentication

CSCwk34786

Victoria-DT CX: support of 10 port-channels on 1220 CX model

CSCwk42676

Virtual ASA/FTD may traceback and reload in thread PTHREAD

CSCwk47035

CMI is disabled if pre-CMI nameif on diagnostic interface is MANAGEMENT

CSCwk74566

Disable csd/hostscan invokation for clientless/webvpn flow

CSCwk93762

Device traceback and reload thrice with Panic at spin_lock_fair_mode_enqueu and nlp_init().

CSCwm47108

CSF1200 DT may randomly go unresponsive during normal course of operation

CSCwm80210

MI: core.lina.async_thr is generated after reboot

CSCwm80732

ASA/FTD - Traceback and reload Due to Race Condition in TCP Proxy

CSCwm83088

Cisco FXOS and UCS Manager Software Stored Cross-Site Scripting Vulnerability

CSCwn19190

Memory fragmentation resulted in huge pages unavailable for lina

CSCwn27583

High lina CPU and/or Traceback and reload in spin_lock_get_actual_internal

CSCwn27872

Big chunk of Memory of around 25KB is being allocated on Stack in "eigrp_interface_ioctl" API

CSCwn32978

Traceback and reload in Thread Name Datapath

CSCwn36712

NAT divert for 8305 on standby not updating post failover causing the Primary, standby FTD to show offline on FMC

CSCwn38761

DNS FQDN obj doesn't go unresolved upon FQDN obj deleted on server/intf to reach sever is down in 7.7

CSCwn39081

SNMP walk results in ASCII value for IPSEC Peer instead of an IP address.

CSCwn40572

MI: Vlan info is not applied at FXOS level when Virtual MAC is configured

CSCwn40702

ASA traceback and reload in freeb_core_local_internal

CSCwn45510

S2S VPN tunnel Child SA unsuccessful renegotiation

CSCwn46855

LINA may observe random traceback with Netflow configured

CSCwn47308

Critical health alerts 'user configuration(FSM.sam.dme.AaaUserEpUpdateUserEp)' on FPR 1100/2100/3100

CSCwn50760

ASA Traceback after upgrade to 9.20.3.7

CSCwn51845

Tracebacks observed in a cluster member running ASA 9.20.3.4

CSCwn59032

FCM GUI became inaccessible after upgrading to ASA 9.18.4.22 | FPR 2130 Platform Mode

CSCwn59379

Bandwidth information of a port-channel is not getting updated if an interface member goes down.

CSCwn60726

Traceback and reload with Thread Name: vtemplate process

CSCwn61041

Traceback and reload during clear bgp * ipv6 unicast involving watchdog

CSCwn61232

Memory block corruption: RAVPN SSL/IKEV2 auth failure, AAA SHIM available fibers exhausted

CSCwn64025

ASA: IPv6 EIGRP routes learned from other neighbors are missing in updates after failover

CSCwn69075

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Heap Corruption Vulnerability

CSCwn69076

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF DoS Vulnerability

CSCwn69079

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Memory Exhaustion Vulnerability

CSCwn69081

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF DoS Vulnerability

CSCwn69488

ASA/FTD - Traceback and Reload in Threadname IP RIB Update

CSCwn71596

Intf Link down (Init, mac-link-down) seen - EtherChannel Membership in Down/Down/Down state after unplug/replug of the cable

CSCwn71946

show blocks old core local can lead to unexpected reload.

CSCwn78569

Set limit for the number of glibc arenas in lina to avoid ASA/FTD system overhead memory issues

CSCwn79553

Unreachable LDAP/AD referrals may cause delays or timeouts in external authentication on FTD

CSCwn80400

Slow download speeds with AnyConnect over TLS on networks with high latency

CSCwn80419

Need the SVC Rx/Tx queue as a configurable option

CSCwn80765

ISA3000 with ASA Refuses SSH Access If CiscoSSH is Enabled

CSCwn81118

RTSP packets getting stuck in transmit queue leading to 9k blocks exhaustion.

CSCwn81784

Choosing clause 91 FEC via the FMC sets fec 544 instead of fec 528 on QSFP-100G-CU3M

CSCwn81995

Traceback and Reload caused by Memory corruption with SNMP inspection enabled

CSCwn84557

Lina traceback and reload due to "spin_lock_fair_mode_enqueue"

CSCwn87513

ASA clock is out of sync 2 hours when timezone is configured to Europe/Dublin which is GMT.

CSCwn90327

FP1150 ASA/FTD - Traceback and reload triggered by watchdog timer

CSCwn90900

High ASA/FTD memory usage due to polling of RA VPN related SNMP OIDs

CSCwn90958

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability

CSCwn91612

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability

CSCwn91996

WM-DT- FXOS Critical Faults seen due to PortMgr IPC Communication failure.

CSCwn92248

FPR2100 & FPR1100: Port-channel interfaces flap with LACP

CSCwn92894

Occasionally, 'show chunkstat top-usage' output does not show all entries

CSCwn93319

ASA/FTD may traceback and reload in Thread Name "DATAPATH"

CSCwn95939

Generate syslog if received CRL is older than cached CRL

CSCwn95945

Generate syslog if received CRL signature validation fails

CSCwn96929

ASA: Traceback and Reload Under Thread Name SSH

CSCwn96963

FTD generates syslog 430002 as VPN Routing without VPN hairpin

CSCwn97630

FTD reboot and traceback in DATAPATH due to IPv6 packet processing

CSCwn98402

Debuggability: FP2100 port-channel interfaces flap after upgrade

CSCwo00102

Snort3 trimming packets with invalid sequence number due to bad window size information received

CSCwo00225

VNI source MTU is not IPv6 aware after upgrade if configured prior to upgrade

CSCwo00332

Firepower wiping SSL trustpoint config after reloading.

CSCwo00444

Nitrox Engine (Crypto Accelerator) problem affecting crypto hardware offload on FPR3100/4200 platforms

CSCwo00702

Community lists should not throw an error until the last item in the list is being deleted

CSCwo00880

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability

CSCwo01557

ASA traceback and reload on DATAPATH thread due to memory corruption

CSCwo01785

Memory leak in RAVPN

CSCwo05712

Serviceability Enhancement - Make FXOS disk errors more descriptive

CSCwo08042

ASAv reloaded unexpectedly with traceback on Unicorn Proxy Thread

CSCwo08306

Command authorization fallback to Local only works for users with privilege 15.

CSCwo08724

Active HA unit goes into failed state before peer unit gets into a ready state during snort failure

CSCwo09060

SSL trustpoint with 4096 bit RSA keys not allowed by ASA if renewed via CLI

CSCwo09195

Traceback and reload during the deployment after disabling FQDNs.

CSCwo09439

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-3-4280'

CSCwo09618

Enabling debugs with EEM fails

CSCwo15021

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15022

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15023

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15024

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15026

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15027

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

CSCwo15715

IKEv2 Rekeys fail due to fragmentation during the IKE Rekey

CSCwo16488

FXOS allows booting and starting an image installation using a Patch image

CSCwo18838

ASA/FTD may traceback and reload in Thread Name 'lina_exec_startup_thread'

CSCwo18850

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense Software HTTP Server Remote Code Execution Vulnerability

CSCwo19762

Unable to rejoin data node in cluster after re-enabling mac-address auto in multi-context mode

CSCwo21767

Port scan alerts not getting generated for custom configuration

CSCwo22091

FTD sending "0.0.0.0" NAS-IP-Address attribute when authenticating/authorizing using Radius

CSCwo24772

debug packet-condition does not work as expected

CSCwo24856

9K block depletion causing slowdown of all traffic through firewall

CSCwo25236

Suddenly customer lost SSH access to the ASA

CSCwo26258

Default Route Changes from Management0 to Management1 After Reload or Upgrade on FPR 4200 Series

CSCwo27260

Unit taking ~13 secs to become active

CSCwo31094

Virtual ASA Traceback and Reload Caused by Disk Access Issues with NFS Enabled

CSCwo33815

FMC: Deployment takes longer than expected when removing SNMP hosts from Platform Settings

CSCwo35783

Enhance Debugging for add/update/withdraw of routes with neighbors

CSCwo35788

Serviceability Enhancement - New 'show bgp internal' command for advanced debugging

CSCwo35938

IPv6 Management communication is lost due to a missing management-only multicast route.

CSCwo36485

ASA/FTD traceback and reload in vaccess_nameif_action thread

CSCwo40957

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability

CSCwo41250

Traceback & Reload in thread named: DATAPATH-1-23988 during low memory condition

CSCwo42102

show tech-support fprm detail command is getting stuck for longer duration

CSCwo42230

Memory leak leading to split brain

CSCwo42326

ENH: Include SystemID in "show system detail" in techsupport file

CSCwo44267

Firepower hits route limit due to ASP table resource exhaustion affecting traffic forwarding

CSCwo44732

ARP is silently dropping packet for an unreachable next hop

CSCwo45497

Counter from IKEV2 stats does not match the number of tunnels in VPN-Sessiondb

CSCwo45848

SecGW: Data node fails to join the cluster with cluster_ccp_make_rpc_call failed to clnt_call error

CSCwo46142

Port-channel member interface flap renders it as an inactive member

CSCwo47978

ASA may traceback and reload in Thread Name 'fover_parse'

CSCwo48439

Traceback & Reload in Thread Name Unicorn Admin Handler

CSCwo49425

Logging recipient-address not overriding the logging mail message severity levels

CSCwo49744

DNS and default gateway are removed on FTD managed through data interface

CSCwo49926

Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability

CSCwo49928

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo49932

Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Authentication Denial of Service Vulnerability

CSCwo49934

Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Memory Exhaustion Denial of Service Vulnerability

CSCwo50417

Warwick Avenue: LLDP neighbours are not discovered if MGMT 1/2 interface is down

CSCwo53752

ASA FTD traceback in Checkheaps process after enabling "controller monitor internal-interfaces free-blocks 100" command

CSCwo54996

Traffic failure due to 9344 blocks leak

CSCwo57740

'${dsk_a} missing or inoperable. Rebooting Blade.' error does not specify missing or inoperable disk

CSCwo58033

[Cluster] CPU Utilization of 100% when NAT Pool exhaustion happens in a context.

CSCwo58191

FTD: Large Delay in packets being inspected by snort

CSCwo58260

Add "built" and "teardown" messages for the GRE | IPinIP connections to the Lina syslog

CSCwo59534

Memory corruption leading to lina assertion and traceback

CSCwo60609

DNS doctoring not working correctly if the doctoring rule is of type dynamic and has any interface

CSCwo61241

Logical App Stuck in 'Start Failed' Due to checkSystemCPUs Failure

CSCwo65060

FTD HA | Same MAC for port-channels causing network outage.

CSCwo66872

snmp_logging_thread is utilizing high CPU in control plane

CSCwo71052

FPR1010 Ethernet1/1 trunk port is not passing Vlan traffic after a reload

CSCwo72352

Memory leak: ASA Fragment size 72 causing memory exhaustion in MEMPOOL_GLOBAL_SHARED POOL

CSCwo73886

Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Unauthenticated Memory Exhaustion Denial of Service Vulnerability

CSCwo73888

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability

CSCwo73889

Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Lua Interpreter Denial of Service Vulnerability

CSCwo73891

Cisco Secure Firewall ASA Software and Secure FTD Software Remote Access SSL VPN Authenticated Memory Exhaustion Denial of Service Vulnerability

CSCwo74009

Cisco FXOS and UCS Manager Software Command Injection Vulnerability

CSCwo74496

BFD flap due to ASA not processing incoming BFD packets after unrelated BFD peers go down

CSCwo75483

SNMP polling to chassis is unsuccessful with FTD Multi-instance in HA used as SNMP agent

CSCwo75810

SNMP configuration is not applied consistently across same FTDs type and version

CSCwo76165

Deployment failure due to rsync

CSCwo76436

3100 Marvell 4.3.14 CPSS patch for the interface mac stuck issue seen with peer switch reloads

CSCwo76559

ASA/FTD traceback and reload with SNMP Notify Thread seen on 3110

CSCwo77665

Portscan event in FMC displays incorrect source/destination when set to 'low' setting

CSCwo78969

Traceback in thread name DATAPATH when a unit is re-joining the cluster

CSCwo79028

Post-Failover FQDN Resolution Deferred Until Next DNS Poll Interval

CSCwo79798

Cryptochecksum changed after reloading.

CSCwo80223

BFD packets are not dropped for single-hop BFD sessions received via alternate path

CSCwo82639

Local user details not replicated to data nodes in a cluster setup.

CSCwo82658

ASDM: Displays Error of Keypair already exists when adding an identity certificate.

CSCwo84467

L3 Clustering where BGP immediately comes up while DATA node is still in bulk sync

CSCwo87763

ASA/FTD: Primary standby unit becomes Active after reload in HA set up

CSCwo87938

backout change preventing enabling clustering in FIPS mode

CSCwo88011

ASA SSH login fails at the first attempt when it is integrated with DUO

CSCwo88204

ASA/FTD traceback and reload triggered by the Smart Call Home process in sch_dispatch_to_url.

CSCwo88518

If command replication fails to any nodes in cluster, send kick the node out from cluster to fmc

CSCwo89233

Command replication failure to cluster nodes on command commit noconfirm revert-save after access-list, additional debugs

CSCwo90678

ASA: MAC address of the port-channel interface changes leading to ping failure

CSCwo90802

SSH Login Fails Across All Contexts After Removing SSH Configuration from One Context or Deleting a Context

CSCwo91436

FPR 4125 Multi instance: High Snort and System Core CPU Usage (100%) Triggering FMC Critical Alerts

CSCwo91748

Lina: Traceback in thread name ssh on executing show access-list after ACL deletion

CSCwo91965

ASAv restarts unexpectedly

CSCwo94483

LINA stays inactive without reloading after traceback on non-CP thread

CSCwo95496

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability

CSCwo97439

ACL: ASA may show false "OOB Access-list config change detected" warning after AAA authorization command is applied

CSCwo98752

Traceback in threadname DATAPATH while trying to re-join cluster.

CSCwo99690

Error Encountered While Disabling the 'Call-Home Reporting Anonymous' Option in Call-Home Configuration

CSCwp00977

FTD Intermittent Syslog Alert: mcelog daemon is not running. Restarting the daemon.

CSCwp01015

ASA/FTD traceback and reload in function mp_percore

CSCwp04235

ASA traceback and reload

CSCwp05866

Cisco Secure Firewall Adaptive Security Appliance Software Multiple Context Mode SCP Unauthorized File Access Vulnerability

CSCwp06882

high CPU usage after ASA upgrade from 9.20.3.9 to 9.20.3.16 running on Hyper-V

CSCwp06890

SFF_SFP_10G_25G_CSR_S modules from Finisar ports bouncing when connected.

CSCwp08772

ASA: tls-proxy maximum-session command error

CSCwp10123

ESP packets encapsulating subsequent fragments are dropped with ASP unexpected-packet drop reason

CSCwp10957

SSL error causing connection to Cisco Smart Software Manager (CSSM) to terminate

CSCwp11382

ASA/FTD: the ssl trust-point command deleted after a reload

CSCwp13016

FTD/ASA SSH: Terminal monitor is not showing logs

CSCwp13540

Wrong URL incorrectly displayed for file upload with Japanese text in file path for client-less VPN

CSCwp14123

Tmatch memory is mostly consumed by ARP-DP.

CSCwp16529

Negative value displayed for buffer drops when using " show cluster info load-monitor details"

CSCwp16739

ASA crashinfo files not generated on FP4200 devices

CSCwp17700

Syslog format is not properly printed when EMBLEM format is enabled at least in one syslog host

CSCwp22214

Multiple mail drops and enq failures are seen while traffic is going through the box.

CSCwp22612

Policy deploy failing on FTD when trying to remove Umbrella DNS Configuration

CSCwp22743

wpk - 1gsx link remains up on wpk but on switch side it shows as not connected

CSCwp25033

An ICMP not reachable storm might cause high CPU on a two units FTD cluster

CSCwp26815

CPU usage by "WebVPN Timer Process" on standby ASA device

CSCwp28801

WA HA: Error while fetching metadata for FTD HA.

CSCwp29401

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability

CSCwp32469

Error : Msglyr::ZMQWrapper::registerSender() : Failed to bind ZeroMQ Socket

CSCwp33077

SAML IdP entityID increase from capped 128 character maximum

CSCwp33410

dmesg and kern.log file flooded with Tx Queue=0 logs

CSCwp34610

IKEv2-EAP Authentication Fails with Windows and MacOS Native VPN Clients

CSCwp36133

Clarify the working of Fallthrough to Interface PAT (Destination Interface) as it is not working as expected

CSCwp37284

"CSRF Token Mismatch" error seen when users click logout from Clientless VPN page

CSCwp39319

ASA Memory leak while processing large CRLs.

CSCwp60849

ASA Core file generated is corrupted

CSCwp60896

ASA Clock reverts to UTC after device reload

CSCwp64615

ASA/FTD: ASP drop capture for 'invalid-ip-length' or 'sp-security-failed' does not work with match criteria

CSCwp66721

Memory leak in SSL crypto causing high Lina memory usage on lower-end devices

CSCwp67356

HA state should not transition from ColdStandby to Active

CSCwp68059

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting Vulnerability

CSCwp87708

FP1140 Critical FXOS fault alerts (F1000413) after upgrade

CSCwp89969

Prolonged delays in firewall restart/reboot completion

CSCwp90780

Restoring .tgz context file causes allocated interfaces to be removed from 'system' configuration

CSCwp92390

FTD - SNMP Walk of FXOS FTD OID Tree Returns Empty or Times Out

CSCwp93368

LINA traceback Observed on FTDv Firewalls Deployed in Azure: snp_vxlan_encap_and_send_to_remote_peer

CSCwp97402

WA: Traceback and reload due to lock contention on the tmatch table during deployment with large snmp config

CSCwp97862

If failover IPSEC PSK is 78 characters or greater HA breaks with "Could not set failover ipsec pre-shared-key"

CSCwp99130

FPR42xx - SNMP poll reports incorrect FanTray Status at Down while actually operational

CSCwq01516

Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability

CSCwq02055

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability

CSCwq07441

Memory Leak observed on FP2110 running ASA due to monitoring interface configured in HA

CSCwq07808

FP3105 Traceback and Reload after changing the speed on Ethernet interface

CSCwq13032

3100/4200: 1G Management interface flapping after upgrade

CSCwq16926

Traceback and Reload while two processes attempt to free a TD subnet structure

CSCwq17612

Misleading "failover reset" log printed on console when reload triggered by HA.

CSCwq18679

ASA from CSM/CLI - no access-list ACL_name line line_nr remark on last ACL line shows message - "Specified remark does not exist"

CSCwq21101

Invalid host header reveals ASA interface IP address

CSCwq22206

S2S VPN is not recovering after IPSEC-Rekey event

CSCwq23394

FTD may drop traffic in the Azure cloud at mlx5 driver level.

CSCwq26863

FP2110 - ntpd process constantly crashing

CSCwq27217

ASA: Traceback and reload on threat detection, interfaces unstable after that

CSCwq29375

ASA/FTD - Assert triggered during FP_PUNT replace (aaa account match)

CSCwq29706

Traceback and reload after editing SNMP config, with tmatch

CSCwq31342

FPR4200 | FPR3100 Multi Instance Chassis Deployment Failed in DNS configuration

CSCwq31988

Errors on all interface of FPR1010 | line protocol is down ( not associated with supervisor )

CSCwq32085

FP3100/4200 rebooting after generating crypto_archive with error on console "KC ILK issue detected"

CSCwq35960

OSPF: High CPU, Route flaps, Lina Traceback and Reload in High Availability Setup.

CSCwq36466

expat/xml FW rebooted itself and no crashinfo generated

CSCwq39942

CVE-2025-32463: sudo: Sudo before 1.9.17p1 allows local users to obtain

CSCwq39943

CVE-2025-32462: sudo: Before 1.9.17p1, allows users to execute commands on unintended machines.

CSCwq40256

Inbound IPsec packets are dropped by IPsec offload when the crypto map ACL is using specific ports.

CSCwq43711

Idle SSH sessions persist beyond the configured timeout without graceful termination by Fin flag

CSCwq44834

Multicast and broadcast packets do not reach all multi-instance firewalls via shared interface on 3100/4200

CSCwq46058

ASA SNMP Response Issue - Responses Sent Only for Odd OIDs, Not for Even

CSCwq46143

SSE-ASAc Recommit the fix got reverted during sync

CSCwq46544

debug menu tls-offload option <> to be provided to resolve slow download speed using curl to download large file with SSL Decrypt Resign Policy

CSCwq47622

Lina Traceback and Reload after enabling 'TLS Server Identity Discovery'

CSCwq48842

FTD: Packets Dropped due to tcp-seq-past-win due to delayed packet through Snort

CSCwq50189

ASAv deploy failed - console stuck at continuous

CSCwq50373

ASA/FTD in HA, snmptranslate process during the boot-up causing High CPU and IPC timeouts, causing split-brain.

CSCwq50506

Cisco Secure Firewall ASA Software and Secure FTD Software IKEv2 DoS Vulnerability

CSCwq51981

FTD packer-tracer showing remark rule id in access-list for a rule not getting hit

CSCwq52188

FTD Traceback while executing 'asp load-balance per-packet'

CSCwq52255

SSH login to FTD management IP address lands in FXOS shell instead of FTD CLISH due to missing /mnt/boot/application/*.def file

CSCwq53328

Multicast and unicast packets do not reach the correct instance for random subinterfaces

CSCwq54109

FTD 3130 HA Lina tracebacks at ikev2_bin2hex_str

CSCwq55887

FMC 7.6 NAT Source and IP Not Populating within Unified Event Viewer

CSCwq56279

7.6 - Firepower 3100 series - Upgrading an HA pair from a version without the fix for CSCwo00444 to 7.6 causes one firewall to go into a traceback/reload loop

CSCwq60586

FTD upgrade failed due to bundle image existence verification failure

CSCwq64843

Deployment Failure After Removing An Object From ACL Used in DAP

CSCwq65955

FPR 4200: HA link arp packets getting dropped, internal uplink linkChange counters incrementing

CSCwq70133

Password Expiry Age does not reset after Password Change

CSCwq70773

show asp rule-engine issues with complete and run time

CSCwq72113

WA - add port-info statistics for 2nd uplink in 4245 & mgmt 1/2

CSCwq72156

SNMP traps are not sent to one of multiple SNMP servers, in certain conditions

CSCwq73656

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Memory Corruption Vulnerability

CSCwq73994

ASA : Performance and high CPU usage seen on Hyper-V

CSCwq74204

IKEv1 L2Lvpn fails in phase 2 with "Rejecting IPsec tunnel: no matching crypto map entry" after upgrade

CSCwq74443

HA Primary/Active unit goes to disabled state as "HA state progression failed due to app sync timeout" in build 10.0.0-196

CSCwq74738

RAVPN SSL/IKEV2 AUTH FAILURE: AAA PROCESS MISHANDLING BROKEN FIBER CLASS

CSCwq74986

FTD: Instance stuck in Boot Loop

CSCwq77481

1140 FTD HA primary failed to reboot after executing the reload command from expert mode

CSCwq78991

Firewall joins a cluster although gets incomplete ACL policy rules during replication

CSCwq79815

Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability

CSCwq79831

Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability

CSCwq81480

FTD MI: SNMP polling fails to work after the upgrade

CSCwq82095

SAML response rejected with message for certain IDPs

CSCwq82225

Drop counter doesn't increment for embryonic related drops in 'show service policy'

CSCwq85028

Packet Captures show misleading information when blocked due to TCP server unavailable.

CSCwq85473

FP 4115 ASA Cluster: GTP inspection causing high lina CPU 70% - 90%+ depend on traffic

CSCwq85986

FP4225: Interface with SFP - 10/25G_LR_S (or CSR_S) is not coming up after reboot of peer side.

CSCwq88796

Firepower: SSH access lost after timezone change in platform mode

CSCwq90072

ASDM Parsing Failure on Two Contexts

CSCwq92373

WA MI: Two apps went to Not Responding state with reason: Error in App Instance ftd. sma reported fault: Instance xxx is disabled due to restart loop. Please consider reinstalling this app-instance.

CSCwq92728

ASA client IP missing from TACACS+ authorization request in SSH

CSCwq95241

Reboots on FP2130 due to missing heimdall PID

CSCwq95810

"no http server basic-auth-client ASDM" allows ASDM connections to ASA.

CSCwq96870

Interfaces are coming up when the Firepower is shutting down

CSCwq98101

Policy deployment fails when inline-set is configured on FTD HA

CSCwq98648

Low RAM allocation on ASAv can trigger unexpected behavior in 'asdm image' command

CSCwr01482

FPR4215 "Not supported" alarm occurred, when insert the SFPs

CSCwr05406

Traceback in HA stby node while snmpwalk on natAddrMapTable

CSCwr05468

"longer-prefixes" filter on "show route" command not filtering correctly

CSCwr05837

SNMP process continuously restarts

CSCwr06290

ASA/FTD: Traceback in thread name CP Processing due to DCERPC inspection

CSCwr10732

Connection blocking active although "logging permit-hostdown' is set

CSCwr10747

ASA/FTD may traceback and reload due to memory exhaustion

CSCwr12965

Both the units in HA changed the encryption algorithm simultaneously

CSCwr14186

add context for cmd-invalid-encap asp-drop type in the "show asp drop" command usage

CSCwr15611

ASA/FTD - 1550 Block Depletion Due to Instability of TCP Syslog Channel(s)

CSCwr15697

Block 80 depletion ssl_decrypt_cb

CSCwr19123

FPR HA ESP sequence number discrepancy when standby changes to Active resulting in Anti-replay drops

CSCwr21375

FTD port status not reflecting properly on FMC.

CSCwr21683

Deployment changed performance profile, unable to retrieve running configuration

CSCwr21835

Dataplane <> Control Plane may be overwhemed in the event of a massive influx of traffic with no existing ARP Adj present

CSCwr21948

WCCP redirection not working as expected on transparent FTD

CSCwr22256

Traceback seen while FQDN list expands more than 200 entries for a resolved ip

CSCwr22508

Device doesn't boot and gets stuck after a successful upgrade

CSCwr24999

FP3140 FTD HA Upgrade Getting Stuck

CSCwr26857

File policy stops working due to SMB tcp conn terminated after 1hr for unknown reason despite not idle

CSCwr27095

Anyconnect users incorrectly get the prompts, based on the previous tunnel-group

CSCwr28908

ASA: Traceback and reload after saving asdm image

CSCwr29314

Show crypto accelerator shows max crypto throughput is 6 Gbps For 3K & 225Mbps for FTDv

CSCwr31136

SNMP OID Polling for Chassis temperature not giving response

CSCwr31782

Secure Client SAML - External Browser May Prompt for a Certificate when using IKEv2-IPsec and Certificate Mapping

CSCwr35582

Continuous logs_archive.asa-interface-idb.log getting generated on ASA

CSCwr36159

FXOS:ASA SSH login fails at the first attempt when it is integrated with DUO

CSCwr42577

ASA/FTD may traceback and reload citing Thread Name 'lina' as the faulting thread.

CSCwr42969

Dynamic Offloaded Flows Interrupted midstream

CSCwr43586

Intermittent drop of self-originated ICMP TTL exceeded messages with reason "Unable to obtain connection lock (connection-lock)"

CSCwr43613

FTD/ASA may traceback and reload

CSCwr48605

Lina traceback due to the incorrect option being received in the packet.

CSCwr49028

Secure client tunnel group authentication is affected when using SDI protocol

CSCwr49171

Interlaken (ILK) link between the Nitrox and KC2 failure, causing traffic backpressure / traffic outage

CSCwr50466

ASA/FTD: Wrong value shown for X509_STORE_CTX in 'show ssl objects'

CSCwr51629

RTSP Flows are dropped with drop reason "First TCP packet not SYN"

CSCwr55089

ASA/FTD - Traceback and Reload in Threadname DATAPATH

CSCwr57552

Rate limit conn-limit SNMP traps

CSCwr58661

Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability

CSCwr58862

ASA/FTD: SCEP enrollment fails with SCEP server reachable over VPN and sourced from inside interface

CSCwr59870

ASAv on Hyper-v encountering boot loop issues when running netvsc driver

CSCwr61303

Lina: Traceback and reload webvpn_session_release

CSCwr61452

ASA traceback and reload due to memory corruption in IPsec SA pointers

CSCwr62800

High network latency observed on ASAv

CSCwr62993

FTD traceback and reload on DATAPATH

CSCwr65540

ASA traceback while disabling GTP inspection

CSCwr66525

WPK node rebooted with lina core while trying to form cluster in snp_nat_allocate_port

CSCwr71075

FP2140 running FTD traceback during deployment

CSCwr72101

Lina: Traceback and reload for watchdog on BGP

CSCwr74361

ASAv memory leak leading to reload

CSCwr74420

FTD - FTD RADIUS authentication fails with "bad authenticator" after disabling Management Interface Convergence

CSCwr78255

Inconsistent Cluster State: All Nodes Acting as Data Nodes with No Control Node

CSCwr79344

ASA/FTD traceback and reload in Lina

CSCwr81266

Unable to remove certificate-group-map

CSCwr81840

VPN-MT: ASA (99.22.3.39) crashed with one TLS session

CSCwr83527

FP2110 Critical fault alerts for remote users

CSCwr84332

ASA/FTD traceback and reload in L2 vaccess_nameif_action thread

CSCwr84343

ASA/FTD Traceback and reload in L2 table creation failure

CSCwr85470

FTD silently drops out of order packets

CSCwr87102

Problems may arise when an automated script attempts to deploy to add or delete an SNMP user in a multi-context environment.

CSCwr88208

ASA/FTD: Fragmentation issue for IKE_Auth packets

CSCwr88733

Collecting "show tech-support fprm" results in corefile in TAR process

CSCwr94517

ASA traceback and reload while removing capture

CSCwr95213

BEMS01922035: asa-app-agent: FP2130 9.20.4 ASA ha pair just one unit crashes once it is active - DOLLAR ACADEMY (ASA 699917514)

CSCwr96082

ASA: Traceback and reload on ARP code when the pinged device is unreachable

CSCws02848

High cpu on block depletion

CSCws03492

ASP ACL rule (dhcp network scope) fail to be removed during "no nameif" or interface deletion process

CSCws03807

Memory leak in virtual-access nameif strings

CSCws03882

ASA timestamp getting stuck for syslog messages until the device sync up with NTP

CSCws04453

ASAv Traceback and Reload 30 secs - 5 mins after the BGP neighbor relationship is formed with the peer

CSCws05886

ASA may traceback during manual failover

CSCws06991

Few FQDNs are not resolving after FTD upgrade

CSCws19908

snmpEngineBoots does not increase when ASA reloads

CSCws21415

Inotify user watch limits require adjustment for 3100 and 4200 platforms running MI FTDs

CSCws25638

FPR 3110 MI (shared subinterface) - Traffic outage when disabling multicast routing on one FW instance

CSCws26357

Multiple issues with either Interface not coming up or CRC errors with 25/50G LR SFP

CSCws26783

FTD/ASA: Traceback and reload on memory corruption caused by “occam_arena__get_block”

CSCws27870

LINA May Encounter Traceback and Reload if SSH Session Uses ChaCha20-Poly1305 Cipher

CSCws31035

Lina Traceback and reload in Thread: "cli_xml_request_process"

CSCws31657

SNMP polling fails to work after upgrade

CSCws33462

Faults generated during first boot on 6.x can't be cleared

CSCws35491

The identity cert will miss "ca" if the same cert also installed as device-certificate. Reboot will fail to install identity cert

CSCws35715

ASA/FTD responding without relay_sig parameter in SAML dupicate request

CSCws35788

Lina engine traceback, due to assertion in datapath.

CSCws36457

While in App-Sync phase, cluster node does not transition to disabled state when CCL interface goes down

CSCws39799

Traceback and reload in threadname datapath due to flow-offload.

CSCws47928

Lina crash on FTDv

CSCws59816

ASA: Traceback with Thread Name DATAPATH-0-13302

CSCws61024

Appliance enters into fail-safe mode due to warnings thrown by nat config.

CSCws62173

License registration still fails with ssl trustpoint and smart transport mode configured despite fix for CSCwp10957

CSCws65199

ASA/FTD does not accept "id-kp-ipsecIKE" or "anyExtendedKeyUsage" in EKU for usage type IPSEC VPN Peer

CSCws65834

Lina: asacli Traceback & reload due to SSH/SCP initiated from firewall exec mode

CSCws74734

FTD installing two default routes coming over EIGRP having different metrics

CSCws82462

ASA/FTD assert crash after applying capture type isakmp command from LINA CLI

CSCws86023

ASA/FTD may traceback and reload in spin_lock_check_for_deadlock

CSCws86306

Unable to retrieved SNMP OID crasActGrpName (1.3.6.1.4.1.9.9.392.1.3.22.1.1)

CSCws99145

Azure ASAv Interface speed auto-negotiation not working

CSCwt01221

Crash at Process Name: lina <ctm_cryptodev_terminate_session+168>

CSCwt01395

Traffic is not hitting the expected rule, instead hitting default deny rule.

CSCwt12566

Cluster Control Link (CCL) Capture with match statement only captures one direction (ingress) packets

CSCwt17245

Cisco Secure Firewall 3100/4200 performs dynamic flow-offload on unsupported versions

CSCwt20722

Auto-rejoin timer not starting for a unit which has left the cluster.

Resolved Bugs in Version 9.22(2)

The following table lists select resolved bugs at the time of this Release Note publication.

Identifier

Headline

CSCwb67583

ASDM Access Issue When SSL VPN And HTTP Server Is Configured On Same Port

CSCwb77894

Firepower 1000/2100 may boot to ROMMON mode

CSCwe88492

Banner login does not display when configured

CSCwf04460

The fxos directory disappears after cancelling show tech fprm detail command with Ctr+c is executed.

CSCwf25454

Stale anyconnect entries causing issues with routing

CSCwh17965

[Display]FXOS: PC member interface is shown as down & unassociated/unassigned after reload

CSCwh71161

ASA|FTD: Traceback & reload in thread Name: update_mem_reference

CSCwh82305

Lina core at swapcontext on Standby FTD during policy deployment

CSCwi49884

TCP MSS is changed back to the default value when a VTI or loopback interface is created

CSCwi98274

unzip 5.52 is from 2005 is contains multiple vulnerabilities

CSCwj15125

ASA/FTD may traceback and reload in Thread Name 'lina' related to Netflow timer infra

CSCwj21985

Debug: Eth1/1 flapping unexpectedly

CSCwj72013

PAT communication via using PAT pool fails for about 40 seconds when a device joins a cluster

CSCwj74716

tpk_mi upgrade failed from 7.4.1.1 > 7.6.0 000_start/000_00_run_cli_kick_start.sh.

CSCwj81031

snmpd core seen in ASA/FTD

CSCwj98648

Failure to read the signature keys (mult-instance deployment)

CSCwj98673

Fail to start a disabled container on chassis reboot and misses to log the activity to Heimdall

CSCwk08241

FTD is not resolving FQDN for ACLs intermittently

CSCwk10884

Connectivity failure due to mismatch between l2_table and subinterface mac address

CSCwk16332

ASA/FTD traceback and reload with high rate of SIP connections

CSCwk22574

Remove SGT frames/packets to allow VTI decryption

CSCwk30049

ASA/FTD May traceback & reload citing Thread Name 'lina' as the faulting thread.

CSCwk35710

FTD/LINA may traceback and reload when "show capture" command is executed in EEM script

CSCwk37371

SGT INLINE-TAG added after upgrade to 7.4.x

CSCwk40335

Trigger Alert/Warning when the associated FQDN IDs of an IP address surpasses the set limit of 8

CSCwk42676

Virtual ASA/FTD may traceback and reload in thread PTHREAD

CSCwk45975

TLS1.3 Decryption configuration on SSL policy is affecting DND traffic.

CSCwk46737

ASA on HA: alloc_ch() alloc from chunk mem Failed message on one context in Standby device

CSCwk47035

CMI is disabled if pre-CMI nameif on diagnostic interface is MANAGEMENT

CSCwk52890

FTD / ASA High Memory Usage Due to HTTP-based Path Monitoring

CSCwk61157

FTD LINA Traceback and Reload dhcp_daemon Thread

CSCwk63011

Incorrect network module slot and status information in "show module" command output

CSCwk63586

App instance stuck in STOP_FAILED with error message

CSCwk63733

HA-monitored interfaces are going into "waiting" state and subsequently to "Failed"

CSCwk67859

FTD and FXOS: RADIUS Protocol Spoofing Vulnerability (Blast-RADIUS): July 2024

CSCwk70078

Failures and records are not seen in show failover statistics after simulating failures

CSCwk71866

ASA: Site-to-Site VPN between contexts on the same device drops traffic due to 'ipsec-tun-down'

CSCwk71992

BlastRADIUS vulnerability phase-1 fix for pix-asa - Message Authenticator

CSCwk74813

Cisco Adaptive Security Appliance and Firepower Threat Defense TLS Denial of Service Vulnerability

CSCwk75035

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vul

CSCwk75406

FMC in CC-mode audit over syslog not working

CSCwk75956

ASA/FTD may traceback and reload in Thread Name SSH

CSCwk76362

FTDv traceback in Thread name - PTHREAD

CSCwk78030

ASA/FTD: Memory Exhaustion due to Threat-Detection

CSCwk79288

Partition "/opt/cisco/config" gets full due to btmp file not getting logrotated

CSCwk82557

FTD upgrade to 7.4.2 via FDM is blocked

CSCwk82571

VPN Client Application version and OS is not displayed for the FTD Standby peer under User Activity

CSCwk86582

'ENDPOINT_TIME_OUT_OF_SYNC' Error Causing SAML Auth to Not Complete

CSCwk87457

ASA/FTD may traceback and reload in Process Name "lina" after device was reloaded

CSCwk88182

FTDv50 traceback during normal operation at PTHREAD-8141 spin_lock_fair_mode_enqueue

CSCwk88201

S2S VPN with 3rd party broken after upgrading FPR 9.20

CSCwk88225

Critical fault : [FSM:FAILED]: user configuration(FSM:sam:dme:AaaUserEpUpdateUserEp)

CSCwk89836

ASA/FTD may traceback and reload in Thread Name 'strlen'

CSCwk94382

FTD: Lina might fail to respond to CONFIG_XML_REQUEST leading to stuck deployments

CSCwk96912

FTD: Username missing in syslog message ID 302013 after upgrade to 7.4.1

CSCwm01544

Lina traceback and reload in data-path thread

CSCwm02801

Unstable HA causing depolyment failure

CSCwm03142

IPv6 Neighbor Discovery failure on shared interface in multi instance setup

CSCwm03287

FP4245 - NPU Accelerator changed speed of 100Gb interface to 10Mb

CSCwm04021

ASA|FTD Traceback & reload in process name lina

CSCwm04650

Increase memory usage leading to tracebacks in Lina.

CSCwm05520

Disable cluster syn cookie decoding when FTD cluster is deployed with inline-set

CSCwm05960

Generated Cryptochecksum changes without configuration change

CSCwm06393

Changes in port-channel membership or member status may cause periodic OSPF/EIGRP adjacency flaps

CSCwm07389

CGroups errors in ASA Syslog during every reboot

CSCwm07419

ldap.conf does not get generated using hostname

CSCwm08231

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability

CSCwm08232

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability

CSCwm08235

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability

CSCwm13141

FTD CLISH/CLI gets locked up when trying to run any show command

CSCwm13199

SIP traffic is affected due to unexpected behavior with NAT untranslations.

CSCwm14509

Wrong drops seen with Invalid length for 23, 24 and 25 IE-Types during GTP inspection

CSCwm14561

ASA/FTD may traceback and reload in Thread Name 'fover_parse'

CSCwm14729

CSF 3100 series not rebooting after power outage, requiring manual power cycle

CSCwm28007

Browser redirects to blank page when the user clicks the WebVPN bookmark

CSCwm30731

The ASA's OSPF routing table is not properly synchronized with the neighbors

CSCwm33229

SAML Force re-authentication Is Not Enforcing User To re-enter Credentials Upon Retrying To Connect

CSCwm33529

FXOS MTU Handling for Front Panel and Uplink Ports on Firepower devices require improvement

CSCwm33613

Default Group Policy is applied when receiving multiple Group Policies in SAML assertion attributes

CSCwm34333

FTD -  Multi-Instance, docker0 interface overlap with private network 172.17.0.0/16

CSCwm35035

SAML Auth Request by FTD Will Always Be Signed By Sha1 Irrelevant Of the Algorithm Configured

CSCwm35624

Long boot time seen with one AC rule having object-group and other plain ACL's

CSCwm35730

LINA may traceback in Thread Name: Datapath with NAT config

CSCwm35751

FPR3100: Interface may go to half duplex speed is hardcoded to 100mbps

CSCwm36631

FTD Secondary Unit got stuck in Bulk sync state.

CSCwm37455

ASA/FTD will allow local IP pool with invalid netmask

CSCwm41847

Serviceability to capture PDTS writing/reading block to help root cause CSCwm36314

CSCwm42000

FTD/ASA may traceback and reload in DATAPATH thread

CSCwm42745

Dynamic Site-to-Site tunnels stuck in IN-NEG state When IKE_AUTH Is Missed

CSCwm44412

FTD inline-set ignore reverse flag for inject/rewrite

CSCwm49153

Cisco Adaptive Security Appliance Software SSH Server Resource DoS Vulnerability

CSCwm49154

FXOS fault F1738 seen in deploymet with Error: CSP_OP_ERROR. CSP signature verification error

CSCwm49213

Show mod functionality needs to be fixed after change was reverted in CSCwk63011 due to regression

CSCwm49410

Misconfigured Cross-Origin-Opener-Policy

CSCwm49721

ASA Traceback and Reload due to MEMORY CORRUPTION WAS DETECTED

CSCwm49782

enhance sma 2nd cruz heartbeat logging

CSCwm50591

ASA/FTD: Inbound IPsec packets are dropped when IPsec offload is enabled with VTI and sub-interface

CSCwm50936

100GB interface flaps with Innolight QSFPs in both ends

CSCwm52264

Not able to remove or clear Fault "The password encryption key has not been set."

CSCwm52931

ASA/FTD may traceback and reload in Thread Name "fover_parse"

CSCwm52973

TPK Low End FPR3100:Changing interface speed from 1g to 100mbps/100mps to 1g bring downs the link

CSCwm56864

show run access-list command returns warning

CSCwm60536

SQLNet traffic getting dropped intermittently in Clustering data unit.

CSCwm61282

ASA/FTD: RA VPN tunnel causing memory leak leading to traceback & Reload

CSCwm61693

Enable NFS Client 4.1 in the kernel to debug NFS and EFS mount issues: SIGKILL(9) to stunnel

CSCwm63868

FTD - Missing routes on BGP advertised-routes after FTD HA failover event

CSCwm64553

Incompatible members warning message after Po member interface flaps unable to rejoin Po

CSCwm68211

ASA traceback and reload on thread snmp_inspect

CSCwm70835

ASA traceback and reload due to stack overflow while using APCF file

CSCwm71265

ASA traceback and reload on thread DATAPATH when processing gtpv1 end marker msg for PDP

CSCwm74289

NAT traps have to be rate-limited

CSCwm78351

Potential High CPU usage in Multi-Context Cluster setup with unconditional execution of capture code

CSCwm81280

Evaluation of ssp for mod_nuova logs authentication tokens

CSCwm83088

Cisco FXOS and UCS Manager Software Stored Cross-Site Scripting Vulnerability

CSCwm85228

ASA/FTD may traceback and reload in Thread Name "IKEv2 Daemon" while joining failover

CSCwm88812

4200/3100/1200 hardware allow to change AppAgent timer

CSCwm89523

'no capture /all' failed to disable capture completely in the backend, causing high datapath CPU

CSCwm90900

GTP inspection drops packet with error Reason:(IE-Type:CAUSE(2) IE is missing)

CSCwm90905

GTP inspection drops packet with error ERROR-DROP:MsgType:32

CSCwm91176

Cisco ASA/FTD Firepower 3100/4200 Series TLS 1.3 Cipher Denial of Service Vulnerability

CSCwm91406

FTD HA Standby Reloads Repeatedly After Upgrade to 7.4.2.1

CSCwm92397

LINA core observed pointing to "IP RIB Update" thread

CSCwm95070

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwm96280

FTD device stuck in rommon mode after pressing reset button

CSCwm96652

Cluster assigning wrong nat for unit, traffic not being forwarded properly back to unit

CSCwm97054

ASA/FTD traceback and reload with high rate of SIP connections

CSCwm98278

TCP Conn not being flagged as Half-Closed after receiving the ACK for the FIN.

CSCwn00475

Memory Blocks 80 and 9344 leak due to priority-queue

CSCwn01281

GTP inspection not allowing GTP data packets if session create response has cause type 18

CSCwn03446

When capture enabled on cluster interface, it always includes CCL IP along with the configured rule

CSCwn03835

ASA/FTD may traceback and reload in Thread Name 'SSH Ctxt Thread'

CSCwn11728

FPR9K-SM-56 module intermittently lock up and cause traffic impact.

CSCwn13187

ASA upgrade failing from 9.20.2.21 to the target version 9.20.3.4

CSCwn13672

Bind ESP to VTI Tunnel Source Interface To Avoid Additional Route-Lookup Post Encryption

CSCwn14130

FTD cluster to traceback and reload after extended PAT is enabled

CSCwn14447

ASA/FTD may traceback and reload in Thread Name 'ldap_client_thread'

CSCwn15104

FTD reload with traceback on swapcontext function

CSCwn16320

Syslog servers below in FTD logging send hostname info as per emblem config for first syslog server

CSCwn17121

ASA/FTD may traceback and reload in Thread Name 'cli_xml_request_process'.

CSCwn19190

memory fragmentation resulted in hugepages unavailable for lina

CSCwn19639

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability

CSCwn19706

Admin users are prompted to change local password when authenticating to external server

CSCwn19739

HA would bring data interfaces up while moving from cold standby to failed state

CSCwn20024

ASA may traceback and reload in Thread Name 'ssh'

CSCwn20642

Discrepancy in VPN bytes with RA VPN user activity report

CSCwn21584

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Web Services Denial of Service Vulnerability

CSCwn22036

FTD: Management0/0 status went down, line protocol is up after upgrade

CSCwn22456

GTPv2 IE-type 157 (Signaling Priority Indication) is dropped with reason as unknown IE type

CSCwn22565

ERROR: cannot set default route for broadcast packets.

CSCwn24577

ASA booting process may freeze when including 'no pim' or 'no igmp' config

CSCwn26165

FTD/ASA May Traceback and Reload - During Deployment / Radius changes - Due to Radius Packets

CSCwn27819

Jumbo frame packets are being fragmented

CSCwn31240

Traceback and reload due to webvpn dtls flow offload enabled

CSCwn31588

MI: Instances going in split brain when assigned RP with CPU cores between 14-70 on FPR42xx

CSCwn31653

FTD may traceback and reload in Thread Name "FPRLI_FPR4K-SM-32"

CSCwn34259

Monitored interfaces may go in waiting state after upgrade to 9.20.3.7

CSCwn34659

Firewall not initiating TCP request even after receiving the TC bit set in DNS response

CSCwn34707

Multiple Unicorn Admin Handler processes consume all the control plane CPU.

CSCwn35495

Primary FTD instance MAC address is not updated correctly in FXOS during failover

CSCwn39780

FTD Deployment Resilience: Skip non-critical / non-existing commands to avoid deployment failures.

CSCwn39826

HA should prevent honouring failover requests while copy/config-sync/rollback is in progress

CSCwn40485

MI: Traffic fails to reach the Secondary FTD when enabled with data-sharing interface

CSCwn40572

MI: Vlan info is not applied at FXOS level when Virtual MAC is configured

CSCwn42949

Implementing forwarder flow on non-owner units handling distributed secondary flow connections

CSCwn44335

FXOS - Download command generates an extra "/" over HTTP and HTTPS GET requests

CSCwn45510

S2S VPN tunnel Child SA unsuccessful renegotiation

CSCwn46426

ASA 21xx: 'sh environment temperature' shows incorrect temperature values

CSCwn46855

LINA may observe random traceback with Netflow configured

CSCwn47308

Critical health alerts 'user configuration(FSM.sam.dme.AaaUserEpUpdateUserEp)' on FPR 1100/2100/3100

CSCwn51845

Tracebacks observed in a cluster member running ASA 9.20.3.4

CSCwn63839

Traceback in thread name Lina on configuring arp permit-nonconnected with BVI

CSCwn65415

ASA: floating-conn not closing UDP conns if conn was created without ARP entry for next hop

CSCwn69075

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF Heap Corruption Vulnerability

CSCwn69081

Cisco Secure Firewall ASA Software and Secure FTD Software OSPF DoS Vulnerability

CSCwn69963

Addressing CVEs reported in unicorn zlib library

CSCwn73351

Asia/Bangkog timezone option not listed in ASA running on firepower1k

CSCwn73399

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwn75667

Banner motd does not display when configured

CSCwn76079

SSH works in admin context but doesn't work in any user context after changing ssh key-exchange

CSCwn79553

Unreachable LDAP/AD referrals may cause delays or timeouts in external authentication on FTD

CSCwn80765

ISA3000 with ASA Refuses SSH Access If CiscoSSH is Enabled

CSCwn90958

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability

CSCwn91612

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability

CSCwn92894

Occasionaly, 'show chunkstat top-usage' output does not show all entries

CSCwn93319

ASA/FTD may traceback and reload in Thread Name "DATAPATH"

CSCwn96929

ASA: Traceback and Reload Under Thread Name SSH

CSCwo00880

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability

CSCwo01557

ASA traceback and reload on DATAPATH thread due to memory corruption

CSCwo08306

Command authorization fallback to Local only works for priv 15 users.

CSCwo09195

Traceback and reload during the deployment after disabling FQDNs.

CSCwo09618

Enabling debugs with EEM fails

CSCwo15021

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15022

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15023

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15024

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15026

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

CSCwo15027

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

CSCwo41250

Traceback & Reload in thread named: DATAPATH-1-23988 during low memory condition

CSCwo47978

ASA may traceback and reload in Thread Name 'fover_parse'

CSCwo49928

Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

Resolved Bugs in Version 9.22(1.1)

The following table lists select resolved bugs at the time of this Release Note publication.

Identifier

Headline

CSCvq48086

ASA concatenates syslog event to other syslog event while sending to the syslog server

CSCvt25221

FTD traceback in Thread Name cli_xml_server when deploying QoS policy

CSCvu24703

FTD - Flow-Offload should be able to coexist with Rate-limiting Feature (QoS)

CSCvx04003

Lack of throttling of ARP miss indications to CP leads to oversubscription

CSCvx37329

Remove Syslog Messages 852001 and 852002 in Firewall Threat Defense

CSCvx44261

SNMPv3: Special characters used in FXOS SNMPv3 configuration causes authentication errors

CSCvx69675

FXOS Major Faults about adapter host and virtual interface being down

CSCvx71936

FXOS: Fault "The password encryption key has not been set." displayed on FPR1000 and FPR2100 devices

CSCvx74133

App-instance showing as Started instead of Online

CSCvz22945

ERROR: Deleted IDB found in in-use queue - message misleading

CSCvz68713

PLR license reservation for ASAv5 is requesting ASAv10

CSCvz70310

ASA may fail to create NAT rule for SNMP with: "error NAT unable to reserve ports."

CSCwa34287

ASA: FPR11xx: Loss of NTP sync following a reload after upgrade

CSCwa35200

Some syslogs for AnyConnect SSL are generated in admin context instead of user context

CSCwa76822

Tune throttling flow control on syslog-ng destinations

CSCwa82791

ENH: Support for snapshots of RX queues on InternalData interfaces when "Blocks free curr" goes low

CSCwa93215

Primary node disconnected from VPN-Cluster when performed HA failover on Primary with DNS lookup

CSCwa99932

ASA/FTD stuck after crash and reboot

CSCwb44848

ASA/FTD Traceback and reload in Process Name: lina

CSCwb94431

MFIB RPF failed counter instead of Other drops increments when outgoing interface list is Null

CSCwb95453

ASA: The timestamp for all logs generated by Admin context are the same

CSCwb95784

cache and dump last 20 rmu request response packets in case failures/delays while reading registers

CSCwc05375

AnyConnect SAML - Client Certificate Prompt incorrectly appears within External Browser

CSCwc28334

Cisco ASA and FTD Software RSA Private Key Leak Vulnerability

CSCwc31953

Prevention of RSA private key leaks regardless of root cause.

CSCwc49655

FTPS getting ssl3_get_record:bad record type during connection for KK and DR rules

CSCwc76419

Unnecessary FAN error logs needs to be removed from thermal file

CSCwc78781

ASA/FTD may traceback and reload during ACL changes linked to PBR config

CSCwc82205

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwc89924

FXOS ASA/FTD SNMP OID to poll Internal-data 'no buffer' interface counters

CSCwd02864

logging/syslog is impacted by SNMP traps and logging history

CSCwd04210

ASA: ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT

CSCwd07098

25G CU SFPs not working in Brentwood 8x25G netmod

CSCwd07278

ASA/FTD tmatch compilation check when unit joins the cluster, when TCM is off

CSCwd09870

AnyConnect SAML using external browser and round robin DNS intermittently fails

CSCwd10822

Failover trigger due to Inspection engine in other unit has failed due to disk failure

CSCwd10880

critical health alerts 'user configuration(FSM.sam.dme.AaaUserEpUpdateUserEp)' on FPR 1100/2100/3100

CSCwd16906

ASA/FTD may traceback and reload in Thread Name 'lina' following policy deployment

CSCwd22413

ASA/FTD: Traceback and reload in Thread Name: EIGRP-IPv4

CSCwd23188

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwd30856

User with no vpn-filter may get additional access when per-user-override is set

CSCwd33054

DHCP Relay is looping back the DHCP offer packet causing dhcprelay to fail on the FTD/ASA

CSCwd34079

FTD: Traceback & reload in process name lina

CSCwd37135

ASA/FTD traceback and reload on thread name fover_fail_check

CSCwd38583

ASA/FTD: Command "no snmp-server enable oid mempool" enabled by default or enforced during upgrades

CSCwd43666

Analyze why there is no logrotate for /opt/cisco/config/var/log/ASAconsole.log

CSCwd46061

FPR 2100: 10G interfaces with 1G SFP goes down post reload

CSCwd46741

fxos log rotate failing to cycle files, resulting in large file sizes

CSCwd46780

ASA/FTD: Traceback and reload in Thread Name: appAgent_reply_processor_thread

CSCwd47278

256 / 1550 Block leak with TLS1.3 session

CSCwd50218

ASA restore is not applying vlan configuration

CSCwd53635

AWS: SSL decryption failing with Geneve tunnel interface

CSCwd56296

FTD Lina traceback and reload in Thread Name 'IP Init Thread'

CSCwd59736

ASA/FTD: Traceback and reload due to SNMP group configuration during upgrade

CSCwd62138

ASA Connections stuck in idle state when DCD is enabled

CSCwd62859

Cisco ASA and FTD AnyConnect SSL/TLS VPN Denial of Service Vulnerability

CSCwd63580

FPR2100: Increase in failover convergence time with ASA in Appliance mode

CSCwd63722

FTDv Single-Arm Proxy behind AWS GWLB drops due to geneve-invalid-udp-checksum with all 0 checksum

CSCwd63961

AC clients fail to match DAP rules due to attribute value too large

CSCwd64480

Packets through cascading contexts in ASA are dropped in gateway context after software upgrade

CSCwd67100

ASA traceback and reload on Datapath process

CSCwd67101

FPR1150 : Exec format error seen and the device hung until reload when erase secure all is executed

CSCwd68088

ASA|FTD: Implement different TLS diffie-hellman prime based on RFC recommendation

CSCwd68745

QEMU KVM console got stuck in "Booting the kernel" page

CSCwd69454

Port-channel interfaces of secondary unit are in waiting status after reload

CSCwd70490

Port-channel member port status flag and membership status are Down if LACPDUs are not received

CSCwd71254

ASA/FTD may traceback and reload in idfw fqdn hash lookup

CSCwd72680

FXOS: FP2100 FTW timeout triggered by high CPU usage during FTD Access Control Policy deploy.

CSCwd74839

30+ seconds data loss when unit re-join cluster

CSCwd77581

Cisco ASA and FTD ICMPv6 Message Processing Denial of Service Vulnerability

CSCwd78624

ASA configured with HA may traceback and reload with multiple input/output error messages

CSCwd80343

MI FTD running 7.0.4 is on High disk utilization

CSCwd81123

High CPU Utilization on FXOS for processes smConlogger

CSCwd81538

FTD Traffic failure due to 9344 block depletion in peer_proxy_tx_q

CSCwd82235

LINA Traceback on FPR-1010 under Thread Name: update_cpu_usage

CSCwd84046

Microsoft SCEP enrollment fails to get ASA identity cert - Unable to verify PKCS7

CSCwd84133

ASA/FTD may traceback and reload in Thread Name 'telnet/ci'

CSCwd84153

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwd84868

Observing some devcmd failures and checkheaps traceback when flow offload is not used.

CSCwd85178

AWS ASAv PAYG Licensing not working in GovCloud regions.

CSCwd85927

Traceback and reload when webvpn users match DAP access-list with 36k elements

CSCwd86535

ASA/FTD: Traceback and Reload on Netflow timer infra

CSCwd86929

Cut-Through Proxy does not work with HTTPS traffic

CSCwd87438

Enhance logging mechanism for syslogs

CSCwd88585

ASA/FTD NAT Pool Cluster allocation and reservation discrepancy between units

CSCwd89095

Stratix5950 and ISA3000 LACP channel member SFP port suspended after reload

CSCwd89811

Traffic fails in Azure ASAv Clustering after "timeout conn" seconds

CSCwd89848

ASA/FTD failure due to heartbeat loss between chassis and blade

CSCwd90894

ASA: After upgrade cannot connect via ssh to interface

CSCwd91421

ASA/FTD may traceback and reload in logging_cfg processing

CSCwd92804

FAN LED flashing amber on FPR2100

CSCwd93376

Clientless VPN users are unable to download large files through the WebVPN portal

CSCwd94096

Anyconnect users unable to connect when ASA using different authentication and authorization server

CSCwd94183

Blade not coming up after FXOS update support on multi-instance due to ssp_ntp.log log rotation prob

CSCwd95415

The Standby Device going in failed state due to snort heartbeat failure

CSCwd95436

Primary ASA traceback upon rebooting the secondary

CSCwd95908

ASA/FTD traceback and reload, Thread Name: rtcli async executor process

CSCwd96493

Link Up seen for a few seconds on FPR1010 during bootup

CSCwd96500

FTD: Unable to configure WebVPN Keepout or Certificate Map on FPR3100

CSCwd96755

ASA is unexpected reload when doing backup

CSCwd96766

FPR41xx/9300: Blade does not capture or log a reboot signal

CSCwd97020

ASA/FTD: External IDP SAML authentication fails with Bad Request message

CSCwd98316

Cisco ASA and FTD Software VPN Packet Validation Vulnerability

CSCwe00864

License Commands go missing in Cluster data unit if the Cluster join fails.

CSCwe01977

ASA/FTD may traceback and reload after a reload with DHCPv6 configured

CSCwe02012

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe03529

FTD traceback and reload while deploying PAT POOL

CSCwe03631

Need to provide rate-limit on "logging history <mode>"

CSCwe03991

FTD/ASA traceback and reload during to tmatch compilation process

CSCwe05913

FTD traceback/reloads - Icmp error packet processing involves snp_nat_xlate_identity

CSCwe06562

FPR1K/FPR2K: Increase in failover time in Transparent Mode with high number of Sub-Interfaces

CSCwe07722

Cluster data unit drops non-VPN traffic with ASP reason "VPN reclassify failure

CSCwe08729

FPR1120:connections are getting teardown after switchover in HA

CSCwe09074

None option under trustpoint doesn't work when CRL check is failing

CSCwe09811

FTD traceback and reload during policy deployment adding/removing/editing of NAT statements.

CSCwe10290

FTD is dropping GRE traffic from WSA

CSCwe10548

ASA binding with LDAP as authorization method with missing configuration

CSCwe11119

ASA: Traceback and reload while processing SNMP packets

CSCwe11754

Nodes randomly fail to join cluster due to internal clustering error

CSCwe11902

FTD: HA crash and interfaces down on FPR4200

CSCwe12407

High Lina memory use due to leaked SSL handles

CSCwe12645

Secondary state flips between Ready & Failed when node is rebooted and mgmt interface is shutdown

CSCwe12705

multimode-tmatch_df_hijack_walk traceback observed during shut/unshut on FO connected switch interfa

CSCwe14174

FTD - 'show memory top-usage' providing improper value for memory allocation

CSCwe14417

FTD: IP SLA Pre-emption not working even when destination becomes reachable

CSCwe14514

ASA/FTD Traceback and reload of Standby Unit while removing capture configurations

CSCwe18462

ASA/FTD: Improve GTP Inspection Logging

CSCwe18467

ASA/FTD: GTP Inspection engine serviceability

CSCwe18472

[FTD Multi-Instance][SNMP] - CPU OIDs return incomplete list of associated CPUs

CSCwe18974

ASA/FTD may traceback and reload in Thread Name: CTM Daemon

CSCwe20043

256-byte memory block gets depleted on start if jumbo frame is enabled with FTD on ASA5516

CSCwe20714

Traffic drop when primary device is active

CSCwe20918

Cisco ASA and FTD Software Remote Access SSL VPN Multiple Certificate Auth Bypass

CSCwe21187

ASA/FTD may drop multicast packets due to no-mcast-intrf ASP drop reason until UDP timeout expires

CSCwe21280

Multicast connection built or teardown syslog messages may not always be generated

CSCwe21884

Write wrapper around "kill" command to log who is calling it

CSCwe22152

SNMPD cores seen in in snmp_sess_close and notifyTable_register_notifications

CSCwe22176

WR6, WR8, LTS18 and LTS21 commit id update in CCM layer (Seq 43)

CSCwe22302

Partition "/opt/cisco/config" gets full due to wtmp file not getting logrotated

CSCwe23039

NTP polling frequency changed from 5 minutes to 1 second causes large useless log files

CSCwe24532

Multiple instances of nvram.out log rotated files under /opt/cisco/platform/logs/

CSCwe25025

8x10Gb netmod fails to come online

CSCwe25342

ASA/FTD - SNMP related memory leak behavior when snmp-server is not configured

CSCwe25412

Azure D5v2 FTDv unable to send traffic - underruns and deplete DPDK buffers observed

CSCwe26342

ASA Traceback & reload citing thread name: asacli/0

CSCwe26612

FTD taking longer than expected to form OSPF adjacencies after a failover switchover

CSCwe28094

ASA/FTD may traceback and reload after executing 'clear counters all' when VPN tunnels are created

CSCwe28407

LINA traceback with icmp_thread

CSCwe28726

The command "app-agent heartbeat" is getting removed when deleting any created context

CSCwe28912

FPR 4115- primary unit lost all HA config after ftd HA upgrade

CSCwe29179

CLUSTER: ICMP reply arrives at director earlier than CLU add flow request from flow owner.

CSCwe29529

FTD MI does not adjust PVID on vlans attached to BVI

CSCwe29583

ASA/FTD may traceback and reload in Thread Name 'None' at lua_getinfo

CSCwe29850

ASA/FTD Show chunkstat top command implementation

CSCwe30228

ASA/FTD might traceback in funtion "snp_fp_l2_capture_internal" due to cf_reinject_hide flag

CSCwe30867

Workaround to set hwclock from ntp logs on low end platforms

CSCwe32058

ASA/FTD may traceback and reload in Thread Name 'ci/console' when checking Geneve capture

CSCwe33130

Supervisor does not reboot unresponsive module/blade due to IERR with minor severity sensor ID 79

CSCwe36176

ASA/FTD: High failover delay with large number of (sub)interfaces and http server enabled

CSCwe37453

Gateway is not reachable from standby unit in admin and user context with shared mgmt intf

CSCwe38029

Multiple traceback seen on standby unit.

CSCwe39425

2100: Power switch toggle leads to ungraceful shutdowns and "PowerCycleRequest" reset

CSCwe40463

Stale IKEv2 SA formed during simultaneous IKE SA handling when missing delete from the peer

CSCwe41336

FDM WM-HA ssh is not working after upgrading 7.2.3 beta with data interface as management

CSCwe41898

ASA: FP2100 FTW timeout triggered by high CPU usage during FTD Access Control Policy deploy.

CSCwe42061

Deleting a BVI in FTD interfaces is causing packet drops in other BVIs

CSCwe44311

FP2100:Update LINA asa.log files to avoid recursive messages-<date>.1.gz rotated filenames

CSCwe44672

Syslog ASA-6-611101 is generated twice for a single ssh connection

CSCwe45093

User with no vpn-filter may get additional access when per-user-override is set (IKEv2 RAVPN)

CSCwe45569

FTD upgrade from 7.0 to 7.2.x and traceback/reload due to management-access enabled

CSCwe45779

ASA/FTD drops traffic to BVI if floating conn is not default value due to no valid adjacency

CSCwe47485

FTD: CLISH slowness due to command execution locking LINA prompt

CSCwe48399

The public API function BIO_new_NDEF is a helper function used for str

CSCwe50946

Management interface link status not getting synced between FXOS and ASA

CSCwe51286

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe51443

ASA Evaluation of OpenSSL vulnerability CVE-2022-4450

CSCwe52120

SSL decrypted conns fails when tx chksum-offload is enabled with the egress interface a pppoe.

CSCwe54529

FTD on FPR2140 - Lina traceback and reload by TCP normalization

CSCwe54999

Protocol Down with lower CPU instances on ESXi 8 for ASAv and FTDv

CSCwe58207

Memory leak observed on ASA/FTD when logging history is enabled

CSCwe58700

ASA/FTD: Revision of cluster event message "Health check detected that control left cluster"

CSCwe59380

FTD: "timeout floating-conn" not operating as expected for connections dependent on VRF routing

CSCwe59737

ASA/FTD reboots due to traceback pointing to watchdog timeout on p3_tree_lookup

CSCwe59809

CCM seq 45 - WR6, WR8, LTS18 and LTS21.

CSCwe59919

FTD Traceback and reload on Thread Name "NetSnmp Event mib process"

CSCwe61928

PIM register packets are not sent to RP after a reload if FTD uses a default gateway to reach the RP

CSCwe61969

ASA Multicontext 'management-only' interface attribute not synced during creation

CSCwe62361

ASA reboots due to heartbeat loss and "Communication with NPU lost"

CSCwe62703

New context subcommands are not replicated on HA standby when multiple sessions are opened.

CSCwe62971

Policy Deploy Failing when trying to remove Umbrella DNS Connector Configuration

CSCwe62997

ASA/FTD traceback in snp_tracer_format_route

CSCwe63067

ASA/FTD may traceback and reload in Thread Name 'lina' due to due to tcp intercept stat

CSCwe63232

ASA/FTD: Ensure flow-offload states within cluster are the same

CSCwe63266

Need fault/error for invalid firmware MF-111-234949

CSCwe64043

Cisco ASA and FTD ACLs Not Installed upon Reload

CSCwe64404

ASA/FTD may traceback and reload

CSCwe64557

ASA: Prevent SFR module configuration on unsuported platforms

CSCwe64563

The command "neighbor x.x.x.x ha-mode graceful-restart" removed when deleting any created context

CSCwe65245

FP2100 series devices might use excessive memory if there is a very high SNMP polling rate

CSCwe65492

KP Generating invalid core files which cannot be decoded 7.2.4-64

CSCwe65516

show xlate does not display xlate entries for internal interfaces (nlp_int_tap) after enabling ssh.

CSCwe65634

ASA - Standby device may traceback and reload during synchronization of ACL DAP

CSCwe66132

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe67751

Last fragment from SIP IPv6 packets has MF equal to 1, flagging that more packets are expected

CSCwe67816

ASA / FTD Traceback and reload when removing isakmp capture

CSCwe68159

Failover fover_trace.log file is flooding and gets overwritten quickly

CSCwe70202

Multiple times the failover may be disabled by wrongly seeing a different "Mate operational mode".

CSCwe70378

Connections not replicated to Standby FTD

CSCwe71220

FTD Crash in Thead Name: CP Processing

CSCwe71284

ASA/FTD may traceback and reload in Thread Name DATAPATH-3-21853

CSCwe72330

FTD LINA traceback and reload in Datapath thread after adding Static Routing

CSCwe72535

Unable to login to FTD using external authentication

CSCwe73116

Cross-interface-access: ICMP Ping to management access ifc over VPN is broken

CSCwe74059

logrotate is not compressing files on 9.16 ASA or 7.0 FTD

CSCwe74089

ASA/FTD may traceback and reload in Thread Name DATAPATH-1-1656

CSCwe74328

AnyConnect - mobile devices are not able to connect when hostscan is enabled

CSCwe74916

Interface remains DOWN in an Inline-set with propagate link state

CSCwe76722

ASA/FTD: From-the-box ping fails when using a custom VRF

CSCwe77123

ASA/FTD : Degradation for TCP tput on FPR2100 via IPSEC VPN when there is delay between VPN peers

CSCwe78977

ASA/FTD may traceback and reload in Thread Name 'pix_flash_config_thread'

CSCwe79072

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe80063

Default DLY value of port-channel sub interface mismatch with parent Portchannel

CSCwe81684

ASA: Standby failure on parsing of "management-only" not reported to parser/failover subsystem

CSCwe82107

health alert for [FSM:STAGE:FAILED]: external aaa server configuration

CSCwe82704

PortChannel sub-interfaces configured as data/data-sharing, in multi-instance HA go into "waiting"

CSCwe83255

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe85432

ASA/FTD traceback and reload on thread DATAPATH-14-11344 when SIP inspection is enabled

CSCwe86225

ASA/FTD traceback and reload due citing thread name: cli_xml_server in tm_job_add

CSCwe87134

ASA/FTD: Traceback and reload due to high rate of SCTP traffic

CSCwe88772

ASA traceback and reload with process name: cli_xml_request_process

CSCwe89030

Serial number attribute from the subject DN of certificate should be taken as the username

CSCwe89256

Firepower Chassis Manager is not accessible with ECDSA certificates

CSCwe89731

Notification Daemon false alarm of Service Down

CSCwe89985

CVIM Console getting stuck in "Booting the kernel" page

CSCwe90095

Username-from-certificate feature cannot extract the email attribute

CSCwe90202

ASA: Standby failure on parsing of "management-only" for dynamic configuraiton changes

CSCwe90720

ASA Traceback and reload in parse thread due ha_msg corruption

CSCwe92324

FPR31xx - SNMP poll reports incorrect FanTray Status at Down while actually operational

CSCwe92905

ngfwManager process continuously restarting leading to ZMQ Out of Memory traceback

CSCwe93137

KP - multimode: ASA traceback observed during HA node break and rejoin.

CSCwe93202

FXOS REST API: Unable to create a keyring with type "ecdsa"

CSCwe93489

Threat-detection does not recognize exception objects with a prefix in IPv6

CSCwe93532

ASA/FTD may traceback and reload in Thread Name 'lina'.

CSCwe93537

Threat-detection does not allow to clear individual IPv6 entries

CSCwe93561

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability

CSCwe93736

ASA not updating Timezone despite taking commands

CSCwe94287

FTD DHCP Relay drops NACK if multiple DHCP Servers are configured

CSCwe95729

Cisco ASA & FTD SAML Authentication Bypass Vulnerability

CSCwe95757

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe96023

ASa/FTD: SNMP related traceback and reload immediately after upgrade from 6.6.5 to 7.0.1

CSCwe96068

ASA: Configurable CLU for Large amount of under/overruns on CLU RX/TX queues

CSCwe97277

Observed ASA traceback and reload when performing hitless upgrade while VPN traffic running

CSCwe97939

ASA/FTD Cluster: Change "cluster replication delay" with max value increase from 15 to 50 sec

CSCwe98319

ASAConfig multiple restarts are leaking 16K memory in every Restart leading to ZMQ Out Of Memory.

CSCwe98687

Cisco FTD Software Software for Cisco Firepower 2100 Series Inspection Rules DoS Vulnerability

CSCwe99040

traceback and reload thread datapath on process tcpmod_proxy_continue_bp

CSCwe99550

Add knob to pause/resume file specific logging in asa log infra.

CSCwf00865

FTD/ASA Hub and spoke (U-turn) VPN fails when one spoke is IPSec flow offloaded and the other isn't

CSCwf01064

TCP ping is completely broken starting in 9.18.2

CSCwf03490

portmanager.sh outputing continuous bash warnings to log files

CSCwf04831

ASA/FTD may traceback and reload in Thread Name 'ci/console'

CSCwf04870

ASA: "Ping <ifc_name> x.x.x.x" is not working as expected starting 9.18.x

CSCwf04983

3100 unit failed to join the cluster with error "configured object (sys/switch-A/slot-2) not found"

CSCwf05295

FTD running on FP1000 series might drop packets on TLS flows after the "Client Hello" message.

CSCwf06377

Setting heartbeat timeout to 6sec for Firepower 4100 and 9300

CSCwf07791

ASA running out of SNMP PDU and SNMP VAR chunks

CSCwf08043

Lina traceback and reload due to fragmented packets

CSCwf08387

LSP version not updated to latest in LINA Prompt in SSP_CLUSTER with 7.2.4 build.

CSCwf08515

FPR3100: ASA/FTD High traffic impact on all data interfaces with high counter of "demux drops"

CSCwf10910

FTD : Traceback in ZMQ running 7.3.0

CSCwf11877

TPK 3110 - Firmware version MISMATCH after upgrade to 7.2.4-144

CSCwf12005

ASA sends OCSP request without user-agent and host

CSCwf12408

ASA: After upgrade to 9.16.4 all type-8 passwords are lost on first reboot

CSCwf12985

FTDv: Traffic failure in VMware Deployments due to dpdk pool exhuastion and rx_buff_alloc_failure

CSCwf14126

ASA Traceback and reload citing process name 'lina'

CSCwf14735

traceback and reload in Process Name: lina related to Nat/Pat

CSCwf14811

TCP normalizer needs stats that show actions like packet drops

CSCwf15858

LDAP authentication over SSL not working for users that send large authorisation profiles

CSCwf15863

Very specific "vpn-idle-timeout" values cause continuous SSL session disconnects and reconnects

CSCwf15902

ASAv in Hyper-V drops packets on management interface

CSCwf16679

HA Serviceability Enh: Maintain HA NLP client stats and HA CTL NLP counters for current App-sync

CSCwf17042

ASDM replaces custom policy-map with default map on class inspect options at backup restore.

CSCwf17389

ASA accepts replayed SAML assertions for RA VPN authentication

CSCwf17814

ASA/FTD may traceback and reload in Thread Name '19', free block checksum failure

CSCwf17858

node is leaving TPK cluster due to interface health check failure

CSCwf20338

ASA may traceback and reload in Thread Name 'DHCPv6 Relay'

CSCwf21106

ASA/FTD: Traceback on thread name: snmp_master_callback_thread during SNMP and interface changes

CSCwf22005

ASA/FTD : Packet-tracer may displays incorrect ACL rule, though produces correct verdict.

CSCwf22483

SSH to Chassis allows a 3-way handshake for IPs that are not allowed by the config

CSCwf23564

Unable to establish BGP when using MD5 authentication over GRE TUNNEL and FTD as passthrough device

CSCwf23868

Update Configuration State if sync is skipped

CSCwf26407

FP2130- Unable to disassociate member from port channel, deployment fails, member is lost on FTD/FMC

CSCwf26534

ASA/FTD: Connection information in SIP-SDP header remains untranslated with destination static Any

CSCwf26939

FTD may fail to create a NAT rule with error: "IPv4 dst real obj address range is huge"

CSCwf27337

KP: Cleanup/Reformat the second (MSP) disk on FTD reinstall

CSCwf28488

Inconsistent log messages seen when emblem is configured and buffer logging is set to debug

CSCwf30716

ASA in multi context shows standby device in failed stated even after MIO HB recovery.

CSCwf30727

ASA integration with umbrella does not work without validation-usage ssl-server.

CSCwf30824

Add CIMC reset as auto-recovery for CIMC IPMI hung issues

CSCwf31701

ASA traceback and reload with the Thread name: **CP Crypto Result Processing**

CSCwf31820

Firewall may drop packets when routing between global or user VRFs

CSCwf33574

ASA access-list entries have the same hash after upgrade

CSCwf33904

[IMS_7_4_0] - Virtual FDM Upgrade fails: HA configStatus='OUT_OF_SYNC after UpgradeOnStandby

CSCwf34500

FTD: GRE traffic is not being load balanced between CPU cores

CSCwf35207

ASA: Traceback and reload while updating ACLs on ASA

CSCwf35233

Cisco Adaptive Security Appliance Software and Firepower Threat Defense DoS

CSCwf35500

FXOS/SSP: System should provide better visibility of DIMM Correctable error events

CSCwf35573

Traffic may be impacted if TLS Server Identity probe timeout is too long

CSCwf36419

ASA/FTD: Traceback and reload with Thread Name 'PTHREAD'

CSCwf36621

access-list: Cannot mix different types of access lists.

CSCwf37160

AnyConnect Ikev2 Login Failed With certificate-group-map Configured

CSCwf38782

Change in syslog message ASA-3-202010

CSCwf39108

Firewall rings may get stuck and cause packet loss when asp load-balance per-packet auto is used

CSCwf39163

ASAv - High latency is experienced on Azure environment for ICMP ping packets while running snmpwalk

CSCwf40594

Wyoming/SFCN ASA: Wrong values shown DBRG in show crypto ssl objects CLI

CSCwf41433

ASA/FTD client IP missing from TACACS+ request in SSH authentication

CSCwf42012

Improper load-balancing for traffic on ERSPAN interfaces on FPR 3100/4200

CSCwf42097

PSEQ (Power-Sequencer) firmware may not be upgraded with bundled FXOS upgrade

CSCwf42144

ASA/FTD may traceback and reload citing process name "lina"

CSCwf43288

Traceback in Thread Name: ssh/client in a clustered setup

CSCwf43537

Lina crash in thread name: cli_xml_request_process during FTD cluster upgrade

CSCwf43850

ECMP + NAT for ipsec sessions support request for Firepower.

CSCwf44537

99.20.1.16 lina crash on nat_remove_policy_from_np

CSCwf44621

Traceback and reload on Thread DATAPATH-6-21369 and linked to generation of syslog message ID 202010

CSCwf47227

Remove Priority-queue command from FTD|| Priority-queue command causes silent egress packet drops

CSCwf47924

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability

CSCwf48599

VPN load-balancing cluster encryption using deprecated ciphers

CSCwf49573

ASA/FTD: Traceback and reload when issuing 'show memory webvpn all objects'

CSCwf50497

DNS cache entry exhaustion leads to traceback

CSCwf51512

2100 Reload due to internal links going down and NPU disconnection

CSCwf51824

FXOS SNMP "property community of sys/svc-ext/snmp-svc is out of range" is unclear to users

CSCwf51933

FTD username with dot fails AAA-RADIUS external authentication login after upgrade

CSCwf52810

ASA SNMP polling not working and showing "Unable to honour this request now" on show commands

CSCwf54418

Reduce time taken to clear stale IKEv2 SAs formed after Duplicate Detection

CSCwf54510

ASA traceback and reload on Thread Name: DHCPRA Monitor

CSCwf56386

vFTD runs out of memory and goes to failed state

CSCwf56811

ASA Traceback & reload on process name lina due to memory header validation

CSCwf57856

FXOS Traceback and reload caused by leak on MTS buffer queue

CSCwf58876

KP2140-HA, reloaded primary unit not able to detect the peer unit

CSCwf59571

FTD/Lina - ZMQ issue OUT OF MEMORY. due to less Msglyr pool memory on certain platforms

CSCwf59643

FTD: HA App sync failure due to fover interface flap on standby unit

CSCwf60311

ASA generating traceback with thread-name: DATAPATH-53-18309 after upgrade to 9.16.4.19

CSCwf60590

"show route all summary" executed on transparent mode FTD is causing CLISH to become Sluggish.

CSCwf62729

Cisco ASA/FTD Firepower 2100 SSL/TLS Denial of Service Vulnerability

CSCwf62820

Failover: standby unit traceback and reload during modifying access-lists

CSCwf62885

FTDv Single-Arm Proxy behind AWS GWLB drops due to geneve-invalid-udp-checksum.

CSCwf63589

FTD snmpd process traceback and restart

CSCwf63872

FTD taking longer than expected to form OSPF adjacencies after a failover switchover

CSCwf64590

Units get kicked out of the cluster randomly due to HB miss | ASA 9.16.3.220

CSCwf69880

Firewall Traceback and reload due to SNMP thread

CSCwf69901

FTD: Traceback and reload during OSPF redistribution process execution

CSCwf71606

Cisco ASA and FTD ACLs Not Installed upon Reload

CSCwf71812

FTD Lina engine may traceback, due to assertion, in datapath

CSCwf72434

Add meaningful logs when the maximums system limit rules are hit

CSCwf72510

Avoid both the devices in HA sends events to FMC

CSCwf73189

FTD is dropping GRE traffic from WSA due to NAT failure

CSCwf73773

Dumping of last 20 rmu request response packets failed

CSCwf75214

ASA removes the IKEv2 Remote PSK if the Key String ends with a backslash "\" after reload

CSCwf75694

ASA - The GTP inspection dropped the message 'Delete PDP Context Response' due to an invalid TEID=0

CSCwf77191

ASA appliance mode - 'connect fxos [admin]' will get ERROR: failed to open connection.

CSCwf78321

ASA: Checkheaps traceback and reload due to Clientless WebVPN

CSCwf78950

FMC process ssp_snmp_trap_fwdr high memory utilization

CSCwf79279

azure vftd node traceback while loading multiple network-service objects during ns_reload.

CSCwf81058

FTD: Firepower 3100 Dynamic Flow Offload showing as Enabled

CSCwf82247

Policy deployment fails when a route same prefix/metric is configured in a separate VRF.

CSCwf82279

Excessive logging of ssp-multi-instance-mode messages to /opt/cisco/platform/logs/messages

CSCwf82742

FTD: SNMP not working on management interface

CSCwf84318

ASA/FTD traceback and reload on thread DATAPATH

CSCwf85757

Cisco ASA Software and FTD Software SAML Assertion Hijack Vulnerability

CSCwf87070

WM RM - SFP port status of 9 follows port of state of SFP 10|11|12

CSCwf87348

When state-link is flapped HA state changed from Standby-ready to Bulk-sync without failover reason

CSCwf88124

Switch ports in trunk mode may not pass vlan traffic after power loss or reboot

CSCwf88552

ASA/FTD: Traceback and reload due to NAT L7 inspection rewrite

CSCwf89959

ASA: ISA3000 does not respond to entPhySensorValue OID SNMP polls

CSCwf92135

ASA: Traceback and reload on Tread name "fover_FSM_thread" and ha_ntfy_prog_process_timer

CSCwf92646

ECDSA Self-signed certificate using SHA384 for EC521

CSCwf92661

ASA|FTD: Traceback & reload due to a free buffer corruption

CSCwf94450

FTD Lina traceback Thread Name: DATAPATH due to memory corruption

CSCwf94677

"failover standby config-lock" config is lost after both HA units are reloaded simultaneously

CSCwf95147

OSPFv3 Traffic is Centralized in Transparent Mode

CSCwf95288

FPR1k Switchport passing CDP traffic

CSCwf96938

FMC: ACP Rule with UDP port 6081 is getting removed after subsequent deployment

CSCwf99303

Management UI presents self-signed cert rather than custom CA signed one after upgrade

CSCwf99434

Failed to transfer new image file to FPR2130 and traceback was observed

CSCwh00692

Traceback @<capture_file_show+605 at ../infrastructure/capture/capture_file_finesse.c:282>

CSCwh02457

Radius authentication stopped working after ASAv on AWS upgrade to any higher version than 9.18.2

CSCwh04365

ASA Traceback & reload on process name lina due to memory header validation - webvpn side fix

CSCwh04395

ASDM application randomly exits/terminates with an alert message on multi-context setup

CSCwh04730

ASA/FTD HA checkheaps crash where memory buffers are corrupted

CSCwh05863

ASA omits port in host field of HTTP header of OCSP request if non-default port begins with 80

CSCwh06452

Interface speed mismatch in SNMP response using OID .1.3.6.1.2.1.2.2

CSCwh08481

ASA traceback on Lina process with FREEB and VPN functions

CSCwh08683

FTDv/AWS - NTP clock offset between Lina and FTD cluster

CSCwh09113

FPR1010 in HA failed to send or receive to GARP/ARP with error "edsa_rcv: out_drop"

CSCwh09968

ASA/FTD: Traceback and reload due to NAT change and DVTI in use

CSCwh10931

ASA/FTD traceback and reload when invoking "show webvpn saml idp" CLI command

CSCwh11764

ASA/FTD may traceback and reload in Thread Name "RAND_DRBG_bytes" and CTM function on n5 platforms

CSCwh12120

Incorrect exit interface choose for VTI traffic next-hop

CSCwh13821

ASA/FTD may traceback and reload in when changing capture buffer size

CSCwh14352

Lina CiscoSSL upgrade to 1.1.1v and FOM 7.3a

CSCwh14863

FTD 7.0.4 cluster drops Oracle's sqlnet packets due to tcp-not-syn

CSCwh15223

Lina crash in snp_fp_tcp_normalizer() when DAQ/Snort sends malformed L3 header

CSCwh15636

ARP learning issues with Multiple-instance running 100G Netmod

CSCwh16301

Incorrect Hit count statistics on ASA Cluster only for Cluster-wide output

CSCwh16759

SNMP is not working on the primary active ASA unit in multi-context environment

CSCwh17576

Site-to-Site VPN tunnel status on FMC shows down even though it is UP from FTD side

CSCwh18967

Include "show env tech" in FXOS FPRM troubleshoot

CSCwh19897

ASA/FTD Cluster: Reuse of TCP Randomized Sequence number on two different conns with same 5 tuple

CSCwh21360

741 - HA & AppAgent - Long term solution for avoiding momentary split-brain situations

CSCwh21381

Logging improvement for messages exchange between LinaConfigTool and xml server

CSCwh21420

ASA unexpected HA failover due to MIO blade heartbeat failure

CSCwh21474

ASA traceback when re-configuring access-list

CSCwh22888

FXOS: Remove enforcement of blades going into degraded state after multiple DIMM correctable errors

CSCwh23100

Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability

CSCwh23567

PAC Key file missing on standby on reload

CSCwh24321

FXOS: Alperton 100G NetMod not being acknowledged properly

CSCwh24932

ASA software on FP3110 showing incorrect serial number in show inventory output

CSCwh25351

FTD VMWare: High disk utilization on /dev/sda8 partition caused by file system corruption

CSCwh27230

Connections are not cleared after idle timeout when the interfaces are in inline mode.

CSCwh27886

Chassis Manager shows HTTP 500 Internal Server error in specific cases

CSCwh28144

Specific OID 1.3.6.1.2.1.25 should not be responding

CSCwh29276

ASA: Traceback and reload when switching from single to multiple mode

CSCwh30346

ASA/FTD: 1 Second failover delay for each NLP NAT rule

CSCwh30676

Ping to the configured systemIP on management interface getting failed in cluster setup.

CSCwh30891

ASA/FTD may traceback and reload in Thread Name 'ssh' when adding SNMPV3 config

CSCwh31495

FTD - Traceback and reload due to nat rule removed by CPU core

CSCwh32118

ASDM management-sessions quota reached due to HTTP sessions stuck in CLOSE_WAIT

CSCwh37733

FTD responding to UDP500 packet with a Mac Address of 0000.000.000

CSCwh38708

ASA "pager line 25" command doesn't work as expected on few terminal applications

CSCwh40106

FTD hosted on KP incorrectly dropping decoded ESP packets if pre-filter action is analyze

CSCwh40294

ASA traceback due to panic event during SNMP configuration

CSCwh41127

ASA/FTD: NAT64 error "overlaps with inside standby interface address" for Standalone ASA

CSCwh42412

FTD Block 9344 leak due to fragmented GRE traffic over inline-set interface inner-flow processing

CSCwh43230

Strong Encryption license is not getting applied to ASA firewalls in HA.

CSCwh43945

FTD/ASA traceback and reload may occur when ssl packet debugs are enabled

CSCwh45108

Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability

CSCwh45450

2100: Interfaces missing from FTD after removing interfaces as members of a port-channel

CSCwh47053

ASA/FTD may traceback and reload in Thread Name 'dns_cache_timer'

CSCwh47701

ASA allows same BGP Dynamic routing process for Physical Data and management-only interfaces

CSCwh48844

FTD: Failover/High Availability disabled with Mate version 0.0 is not compatible

CSCwh49244

"show aaa-server" command always shows the Average round trip time 0ms.

CSCwh49483

ASA/FTD may traceback and reload while running show inventory

CSCwh50221

4200 Series: Portchannel in cluster may stay down sometimes when LACP is in active mode

CSCwh51872

Message asa_log_client exited 1 time(s) seen multiple times

CSCwh53143

ASA:Management access via IPSec tunnel is NOT working

CSCwh54477

The FMC is showing "The password encryption key has not been set" alert for a 11xx/21xx/31xx device

CSCwh55178

FXOS: svc_sam_dcosAG process getting crashed repeatedly on FirePower 4100

CSCwh56290

After rebooting, the future date set on the FPR2100 platform is not reflected (set clock manually)

CSCwh58467

ASA does not sent 'warmstart' snmp trap

CSCwh59199

ASA/FTD traceback and reload with IPSec VPN, possibly involving upgrade

CSCwh59557

Source NAT Rule performing incorrect translation due to interface overload

CSCwh60604

ASA/FTD may traceback and reload in Thread Name 'lina' while processing DAP data

CSCwh60631

Fragmented UDP packet via MPLS tunnel reassemble fail

CSCwh60971

NAT pool is not working properly despite is not reaching the 32k object ID limit.

CSCwh61690

Multicast through the box traffic causing high CPU with 1GBps traffic

CSCwh62731

FTD Upgrade from 6.6.5 to 7.2.5 removing OGS causing rule expansion on boot

CSCwh63211

Lina core at snp_nat_xlate_verify_magic.part and soft traces

CSCwh63588

FTD SNMPv3 host configuration gets deleted from IPTABLES after adding host-group configuration

CSCwh65128

LINA show tech-support fails to generate as part of sf_troubleshoot.pl (Troubleshoot file)

CSCwh66359

ASDM can not see log timestamp after enable logging timestamp on cli

CSCwh66636

Configuring and unconfiguring "match ip address test" may lead to traceback

CSCwh68068

Firepower WCCP router-id changes randomly when VRFs are configured

CSCwh68482

FTD: Traceback and Reload in Process Name: lina

CSCwh68856

Configuration to disable TLS1.3

CSCwh69156

FTD-HA does not fail over sometimes when snort3 crashes

CSCwh69346

ASA: Traceback and reload when restore configuration using CLI

CSCwh69843

WM DT - ASA in transparent mode doesn't send equal IPv6 Router Advertisement packets to all nodes

CSCwh70323

Timestamp entry missing for some syslog messages sent to syslog server

CSCwh70481

Community string sent from router is not matching ASA

CSCwh70628

ASA/FTD may traceback and reload due to watchdog time exceeding the default 15 seconds

CSCwh70905

Secondary lost failover communication on Inside, using IPv6, but next testing of Inside passes

CSCwh71008

CSF 4200: PSU Fan speed is critical

CSCwh71050

FXOS : Duplication of NTP entry results in Error message : Unreachable Or Invalid Ntp Server

CSCwh71589

Coverity 886745: OVERRUN in verify_generic_signature

CSCwh71665

ASA traceback under match_partial_keyword during CPU profiling

CSCwh77348

ASA: Traceback and reload when executing the command "show nat pool detail" on a cluster setup

CSCwh78118

ASA/FTD traceback and reload on process fsm_send_config_info_initiator

CSCwh81366

[Multi-Instance] Second Hard Drive (FPR-MSP-SSD) not in use

CSCwh83021

ASA/FTD HA pair EIGRP routes getting flushed after failover

CSCwh83254

ASA/FTD: Traceback and reload on thread name CP Crypto Result Processing

CSCwh83517

VTI tunnel goes down due to route change detected in VRF scenario

CSCwh84376

In FPR4200/FPR3100-cluster observed core file ?core.lina? observed on device reboot.

CSCwh91419

FTD installation fails on FPR-2K "Error in App Instance FTD. Available memory not updated by blade"

CSCwh91574

FTD: Traceback in threadname cli_xml_request_process

CSCwh92156

Firewall shows misleading SCP file copy failure reasons

CSCwh92345

crypto_archive file generated after the software upgrade.

CSCwh93649

File copy via SCP using ciscossh stack fails with error "no such file or directory"

CSCwh93710

Last Rule hit shows a hex value ahead of current time in ASA and ASDM

CSCwh95010

Unexpected traceback on thread name Lina and device experienced reboot

CSCwh95025

GTP connections, under certain circumstances do not get cleared on issuing clear conn.

CSCwh95175

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwh95443

Datapath hogs causing clustering units to get kicked out of the cluster

CSCwh96055

Management DNS Servers may be unreacheable if data interface is used as the gateway

CSCwh98733

ASA: Traceback and reload during tests of High number of traffic flows and syslog messages

CSCwh99398

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-34-17852'

CSCwi01085

FTD VMWare tracebacks at PTHREAD-3587

CSCwi01323

SNMP OID ifOutDiscards on MIO are always zero despite show interface are non-zero

CSCwi01381

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwi02134

FTD sends multiple replicated NetFlow records for the same flow event

CSCwi02754

FTD 1120 standby sudden reboot

CSCwi02919

SNMP Unresponsive when snmp-server host specified

CSCwi03407

Traceback on FP2140 without any trigger point.

CSCwi03528

Cross ifc access: Revert PING to old non-cross ifc behavior

CSCwi04351

FTD upgrade failling on script 999_finish/999_zz_install_bundle.sh

CSCwi05240

ASA - Traceback the standby device while HA sync ACL-DAP

CSCwi06690

Certificate Encoding Issue when using AnyConnect cert Authentication/Authorisation

CSCwi06797

ASA/FTD traceback and reload on thread DATAPATH

CSCwi11520

FTD OSPFV3 IPV6 Routing: FTD is sending unsupported extended LSA request to neighbor routers

CSCwi12772

ASA cluster traceback Thread Name: DATAPATH-8-17824

CSCwi13134

Hardware bypass not working as expected in FP3140

CSCwi13510

Config-url is accepting directory as the config file

CSCwi15409

ASA/FTD - may traceback and reload in Thread Name 'Unicorn Proxy Thread'

CSCwi15595

ASA traceback and reload during ACL configuration modification

CSCwi18581

Firewall traceback and reload due to SSH thread

CSCwi19015

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-13-6022'

CSCwi19145

FTD/ASA may traceback and reload in PKI, syslog, during upgrade

CSCwi19849

VPN load-balancing cluster encryption using Phase 2 deprecated ciphers

CSCwi20045

ASA/FTD may traceback and reload in Thread Name 'lina' due to a watchdog in 9.16.3.23 code

CSCwi20848

ASA/FTD high memory usage due to SNMP caused by RAVPN OID polling

CSCwi20955

FTD with may traceback in data-path during deployment when enabling TAP mode

CSCwi21625

FailSafe admin password is not properly sync'd with system context enable pw

CSCwi22296

ASA: The logical device may boot into failsafe mode because of an large configuration.

CSCwi24461

Device/port-channel goes down with a core generated for portmanager

CSCwi24880

ASA dropping IPSEC traffic incorrectly when "ip verify reverse-path" is configured

CSCwi26064

ASA : Modifying a route-map in one context affects other contexts

CSCwi26895

ASA SNMP OID cpmCPUTotalPhysicalIndex returning zero values instead of CPU index values

CSCwi27338

Stale asp entry for TCP 443 remains on standby after changing default port

CSCwi29934

Cisco FXOS Software Link Layer Discovery Protocol Denial of Service Vulnerability

CSCwi31091

OSPF Redistribution route-map with prefix-list not working after upgrade

CSCwi31480

Alert: Decommission failed, reason: Internal error is not cleared from FCM or CLI after acknowledge

CSCwi31766

PSU fan shows critical in show environment output while operating normally

CSCwi31966

FTD ADI debugs may show incorrect server_group and/or realm_id for SAML-authenticated sessions

CSCwi32063

ASA/FTD: SSL VPN Second Factor Fields Disappear

CSCwi32759

Username-from-certificate secondary attribute is not extracted if the first attribute is missing

CSCwi33710

ipv6 table flush exception when cli_firstboot installs bootstrap configuration multi instance

CSCwi34125

ASA: Snmpwalk shows "No Such Instance" for the OID ceSensorExtThresholdValue

CSCwi35267

TLS1.3: core decode points to tls_trk_try_switch_to_bypass_aux()

CSCwi36311

use kill tree function in SMA instead of SIGTERM

CSCwi36843

Detailed logging related to reason behind sub-interface admin state change during operations

CSCwi38957

Policy Apply failed moving from FDM to FMC

CSCwi40193

Hairpinning of DCE/RPC traffic during the suboptimal lookup

CSCwi40536

ASA/FTD: Traceback and reload when running show tech and under High Memory utilization condition

CSCwi42295

Radius traffic not passing after ASA upgrade 9.18.2 and above version.

CSCwi42992

ASA/FTD may traceback and reload in Thread Name IKEv2 Daemon

CSCwi43492

ASA traceback and reload on Thread Name: DATAPATH

CSCwi43782

GTP inspection dropping packets with IE 152 due to header length being invalid for IE type 152

CSCwi44208

low memory/stress causing traceback in SNMP

CSCwi44912

ISA3000 Traceback and reload boot loop

CSCwi45630

Snort3 traceback with fqdn traffics

CSCwi45878

ASA/FTD: DNS Load Balancing with SAML does not work with VPN Load Balancing

CSCwi46010

ASA/FTD: Cluster incorrectly generating syslog 202010 for invalid packets destined to PAT IP

CSCwi46023

FTD drops double tagged BPDUs.

CSCwi46641

FTDv may traceback and reload in Thread Name 'PTHREAD-3744' when changing interface status

CSCwi48699

ASA traceback and reload on Thread Name: pix_flash_config_thread

CSCwi49770

ASA|FTD Traceback & reload in thread name Datapath

CSCwi50343

Their standalone FTD running 7.2.2 on FPR-4112 experienced a traceback on the SNMP module

CSCwi53150

Service object-group protocol type mismatch error seen while access-list referencing already

CSCwi53431

Unable to Synch more then 100 environment-data with data unit

CSCwi53987

SSL protocol settings does not modify the FDM GUI certificate configuration or disable TLSv1.1

CSCwi55629

ASA/FTD : Port-channels remain down on Firepower 1010 devices after upgrade

CSCwi56048

Interface fragment queue may get stuck at 2/3 of fragment database size

CSCwi56499

Cut-Through Proxy feature spikes CP CPU with a flood of un-authenticated traffic

CSCwi56667

ASA Traceback and reload on Thread Name "fover_parse" on Standby after Failover Group changes

CSCwi57476

interface idb logging log rotation to FXOS logrotate utility

CSCwi57670

RAVPN SAML: External browser gives misleading message when FTD/ASA fails to parse assertion

CSCwi57783

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability

CSCwi58754

Blocking SMB traffic with reason "Blocked by the firewall preprocessor"

CSCwi59525

Multiple lina cores on 7.2.6 KP2110 managed by cdFMC

CSCwi59831

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwi60285

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwi60430

CVE-2023-51385 (Medium Sev) In ssh in OpenSSH before 9.6, OS command injection might occur if a us

CSCwi61135

Debugs failed to be enabled on SSH session

CSCwi62683

The SSH transport protocol with certain OpenSSH extensions, found in ... (CVE-2023-48795)

CSCwi62796

ASA/FTD Traceback and reload related to SSL/DTLS traffic processing

CSCwi63113

Null pointer dereference in SNMP that results in traceback and reload

CSCwi63743

ASA/FTD may traceback and reload in Thread Name "appAgent_monitor_nd_thread" & Rip: _lina_assert.

CSCwi64829

traceback and reload around function HA

CSCwi65116

DHCPv6:ASA traceback on Thread Name: DHCPv6 CLIENT.

CSCwi66461

WARN msg(speed not compatible, suspended) while creating port-channel on Victoria CE

CSCwi66676

ASA/FTD may traceback and reload in Thread Name 'webvpn_task'

CSCwi67998

Policy deployment failures on TPK MI chassis after redeploying same instance

CSCwi68604

Error logs generated for ssh access to ASA when eddsa is used as kex hostkey

CSCwi68625

Continuous snmpd restarts observed if SNMP host is configured before the IP is configured

CSCwi68833

ASA/FTD: Memory leak caused by Failover not freeing dnscrypt key cache due to unsyned umbrella flow

CSCwi69091

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwi70371

Intermittent Packet Losses When VTI Is Sourced From Loopback

CSCwi70492

Firewall is in App Sync error in pseudo-standby mode and uses IPs from Active unit

CSCwi71998

"Stream: TCP normalization error in NO_TIMESTAMP" is seen when SSL Policy decrypt all is used

CSCwi74214

ASA/FTD traceback and reload in Thread Name: IKEv2 Daemon when moving from active to standby HA

CSCwi75198

Standby FTD experiencing periodic traceback and reload

CSCwi76002

Memory exhaustion due to absence of freeing up mechanism for tmatch

CSCwi76361

Transparent firewall MAC filter does not capture frames with STP-UplinkFast dst MAC consistently

CSCwi76630

FP2100/FP1000: ASA Smart licenses lost after reload

CSCwi77415

ASDM connection lost issue is observed in ASAv device due to config issue

CSCwi78370

41xx/93xx : Update CiscoSSH (Chassis Manager FXOS) to address CVE-2023-48795

CSCwi79037

IKEv2 client services is not getting enabled - XML profile is not downloaded

CSCwi79042

FTD/Lina traceback and reload of HA pairs, in data path, after adding NAT policy

CSCwi79120

some ssh sessions not timing out, leading to ssh and console unable to connect to the FXOS CLI

CSCwi79393

Policy Deployment Fails when removing the Umbrella DNS Policy from Security Intelligence

CSCwi79703

Incorrect Timezone Format on FTD When Configured via FXOS

CSCwi84314

ASA CLI hangs with 'show run' on multiple SSH

CSCwi85689

TLS Server Identify: 'show asp table socket' output shows multiple TLS_TRK entries

CSCwi87382

Traceback and reload on Primary unit while running debugs over the SSH session

CSCwi90040

Cisco ASA and FTD Software Command Injection Vulnerability

CSCwi90399

FTD/ASA system clock resets to year 2023

CSCwi90571

Access to website via Clientless SSL VPN Fails

CSCwi90751

FTD/ASA - SNMP queries using snmpwalk are not displaying all "nameif" interfaces

CSCwi90998

ASA SNMP Polling Failure for environmental FXOS DME MIB (.1.3.6.1.4.1.9.9.826.2)

CSCwi95228

"crypto ikev2 limit queue sa_init" resets after reboot

CSCwi95708

FTD: Hostname Missing from Syslog Message

CSCwi95796

FTD SNMP OID 1.3.6.1.4.1.9.9.109.1.1.1.1.7 always returns 0% for SysProc Average

CSCwi95871

SSH/SNMP connections to non-admin contexts fail after software upgrade

CSCwi95994

Chromium-based browsers have SSL connection conflicts when FIPS CC is enabled on the firewall.

CSCwi97836

ASA traceback and reload after configuring capture on nlp_int_tap and deleting context

CSCwi97839

FTD traceback assert in vni_idb_get_mode and reloaded

CSCwi97948

EIGRP bandwidth is changing after upgrade or after "shutdown"/"no shutdown" commands

CSCwi98284

Cisco ASA and FTD Software Persistent Local Code Execution Vulnerability

CSCwi99429

Policy deployment failure rollback didnt reconfigure the FTD devices

CSCwj02505

ASA Checkheaps traceback while entering same engineID twice

CSCwj03764

In Spoke dual ISP case if ISP2 is down, VTI tunnels related to ISP1 flapping.

CSCwj03937

ENH: FTD Add debug message to indicate "No CRL found in User identity Certificate"

CSCwj04154

Intermittent loss of management traffic due to DHCP service failing to start

CSCwj05151

ASA/FTD may traceback and reload in Thread Name DATAPATH due to GTP Spin Lock Assertion

CSCwj05484

ASA upgrade from 9.16 to 9.18 causing change in AAA ldap attribute values by adding extra slash '\'

CSCwj08015

FTW no longer working in NM3 on Warwick

CSCwj08083

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.1

CSCwj08302

FTD: HostScan scanning results not processed in version 7.4.1

CSCwj08980

ICMP replies randomly does not reaching the sender node when initiated from the node.

CSCwj09110

Upload files through Clientless portal is not working as expected after the ASA upgrade

CSCwj09999

FP 3100 MTU change on management interface is NOT persistent across reboots (returns to default MTU)

CSCwj10451

The secondary device reloaded while rebooting the primary device.

CSCwj10955

Cisco ASA and FTD Software Web Services Denial of Service Vulnerability

CSCwj11331

Web Contents files appear as text/plain when they should be application/octet-stream

CSCwj13910

Crypto IPSEC SA Output Showing NO SA ERROR With IPSEC Offload Enabled

CSCwj14832

SAML: Single sign-on AnyConnect token verification failure is seen after successful authentication

CSCwj16279

username containing '@' character works for asa login but fails for 'connect fxos'

CSCwj17447

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-6-26174'

CSCwj19653

FTD - Trace back and reload due to NAT involving fqdn objects

CSCwj20067

ASA: Warning messages not displayed when Static interface NAT are configured

CSCwj20118

FTDv reloads and generate backtrace after push EIGRP config

CSCwj21880

FTD with Interface object optimization enabled is blocking traffic after renaming of zone names

CSCwj22086

Active unit goes to disabled state when there is a mismatch in firewall mode

CSCwj22235

Lina traceback and reload due to mps_hash_memory pointing to null hash table

CSCwj22990

After upgrading the ASA, “Slot 1: ATA Compact Flash memory” shows a ditterent value

CSCwj25629

Error when running 'show tech-support module detail' on FPR9K

CSCwj25975

FTD/ASA : CSR generation with comma between “Company Name” attribute does not work expected

CSCwj30980

Addition of debugs & a show command to capture the ID usage in the CTS SXP flow.

CSCwj31816

TLS Secure Client sessions cannot be established on FTD Due to RSA-PSS Signing Algorithm

CSCwj31918

Segmentation fault with "logger_msg_dispatch" while HA sync

CSCwj32035

Clientless VPN users are unable to reach pages with HTTP Basic Authentication

CSCwj33487

ASA/FTD may traceback and reload while handling DTLS traffic

CSCwj33580

IKEv2 tunnels flap due to fragmentation and throttling caused by multiple ciphers/proposal

CSCwj33891

ASA/FTD Cluster memory exhaustion caused by NAT process during release of port blocks allocations

CSCwj34204

Disk quota for the corefile should be revisited based on platform

CSCwj34881

Command to show counters for access-policy filtered with a source IP address gives incorrect result

CSCwj34975

Multiple context interfaces fail to pass traffic

CSCwj35701

Dns-guard prematurely closing conn due to timing condition

CSCwj38871

ASA traceback with thread name SSH

CSCwj38928

High latency observed on FPR3120

CSCwj40761

ASA/FTD may traceback in Threadname: **CTM KC FPGA stats handler**

CSCwj43345

SNMP poll for some OIDs may cause CPU hogs and high latency can be observed for ICMP packets

CSCwj44398

when set the route-map in route RIP on FTD, routes update is not working after FTD reload

CSCwj45822

Cisco Secure Client Unable to complete connection. Cisco Secure Desktop not installed on the client.

CSCwj48704

ASA traceback and reload when accessing file system from ASDM

CSCwj49958

Crypto IPSEC Negotiation Failing At "Failed to compute a hash value"

CSCwj50406

All IPV6 BGP routes configured in device flapping

CSCwj54717

Radius secret key of over 14 characters for external authentication does not get deployed (FPR3100)

CSCwj55036

ASA/FTD: A delay in an async crypto command induces a traceback and subsequently a reload.

CSCwj55081

FPR3K loses connectivity to FMC via mgmt data interface on reboot of FPR3K

CSCwj56099

ASA: Running the failsafe-exit command caused the interface to enter a DISABLED state

CSCwj59861

ASA/FTD may traceback and reload in Thread Name 'lina' due to SCP/SSH process

CSCwj60265

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-1-16803'

CSCwj62723

Error message spammed to console on Firepower 2100 devices while enabling SSH config

CSCwj65587

Snmpwalk throws Error messages #"snmp/error: truncating integer value > 32 bits"

CSCwj68096

Console Access Stuck for ASAv hosted in CSP after Upgrade to 9.18.3.56

CSCwj68783

FTD/ASA-HA configs not in sync as the command sync process is sending configs with special chars

CSCwj69632

Default Hashing Algorithm is SHA1 for Firepower Chassis Manager Certificate on 4110

CSCwj69780

SNMP host group content change results in SNMP process termination on management interface

CSCwj72683

ASA - Bookmarks on the WebVPN portal are unreachable after successful login.

CSCwj73053

ASA may traceback and reload in Thread Name 'DATAPATH-21-16432'

CSCwj73061

SNMP OID for CPUTotal1min omits snort cpu cores entries when polled

CSCwj74323

ASAv Memory leak involving PKI/Crypto for VPN

CSCwj77700

FTD LINA Traceback and Reload idfw_proc Thread

CSCwj81743

FTD - Trace back and reload due to NAT involving fqdn objects

CSCwj82285

ASA/FTD may traceback and reload in Thread Name 'sdi_work'

CSCwj82736

TLS Handshake Fails if Fragmented Client Hello Packet is Received Out of Order

CSCwj83185

FTD/ASA : Standby FTD traceback and reload after enabling memory tracking

CSCwj83533

FAN is working as expected but FAN LED is in off state.

CSCwj83634

Seeing message "reg_fover_nlp_sessions: failover ioctl C_FOREG failed"

CSCwj86116

High LINA CPU observed due to NetFlow configuration

CSCwj86320

Standby Unit Interfaces enter "Waiting" Status Post-FTD Upgrade Due to Incorrect "Hello" Message MAC

CSCwj87501

ASA/FTD may traceback and reload in Thread Name 'fover_FSM_thread'

CSCwj87770

FPR2100-ASA Unable to generate CSR without FXOS IP address on SAN field

CSCwj88400

FTD may traceback and reload in process name lina while processing appAgent msg reply

CSCwj89264

FTD HA: Traceback and reload in netsnmp_oid_compare_ll

CSCwj91341

Failsafe mode default values are unattainable on some platforms need adjustment per platform/mode

CSCwj92784

RAVPN: Failure to create SGT-IP mapping due to ID table exhaustion

CSCwj93718

Unable to run "nslookup" command on FXOS

CSCwj95590

Browser redirects to logon page when the user clicks the WebVPN bookmark

CSCwj99362

"show inventory" output shows Name: "power supply 0" on Firepower

CSCwk00604

ASA Fails to initiate AAA Authentication with IKEv2-EAP and Windows Native VPN Client

CSCwk02804

WebVPN connections stuck in CLOSEWAIT state

CSCwk02928

ASA/FTD may traceback and reload in Thread Name PTHREAD

CSCwk04290

FPR 21xx - Traceback in Process Name: lina-mps during normal operations

CSCwk04492

ASA CLI hangs with 'show run' with multiple ssh sessions

CSCwk05800

ASA/FTD SNMP polling fails due to overlapping networks in snmp-server host-group

CSCwk05851

"set ip next-hop" line deleted from config at reload if IP address is matched to a NAME

CSCwk06573

Serviceablity : Improve routing infra debugs and add new for error conditions

CSCwk07934

Clock skew between FXOS and Lina causes SAML assertion processing failure

CSCwk08476

FTD/ASA traceback and reload due to 'show bgp summary' memory leak

CSCwk08576

command to print the debug menu setting of service worker

CSCwk09612

Clock skew: FXOS clock diverges from Lina NTP time ~1-10 secs

CSCwk10884

Connectivity failure due to mismatch between l2_table and subinterface mac address

CSCwk12497

Traceback and reload on active unit due to HA break operation.

CSCwk12698

SNMP polling of admin context mgmt interface fails to show all interfaces across all contexts

CSCwk13812

ASA/FTD incorrectly forwards extended community attribute after upgrade.

CSCwk14657

Bring back support for portal-access-rule for weblaunch for RAVPN sessions

CSCwk14685

FTD : Management interface showing down despite being up and operational

CSCwk14909

Traffic drop with 'rule-transaction-in-progress' after failover with TCM cfgd in multi-ctx mode

CSCwk17637

State Link Stops Sending Hello Messages Post-Failover Triggered by Snort Crash in FTD HA

CSCwk17854

FTD doesn't send Type A query after receiving a refuse error from one DNS server in AAAA query.

CSCwk20882

ESP sequence number of 0 being sent after SA establishment/rekey

CSCwk21561

Add warning message when configuring CCL MTU

CSCwk21562

Radius server configuration for FTD external authentication is not deployed to FTD.

CSCwk22034

Snmpwalk displays incorrect interface speeds for values greater or equal than 10G

CSCwk24176

FTD/ASA - VPN traffic flowing through the device may trigger tracebacks and reloads.

CSCwk25117

ENH: Add application support for blocking consecutive AAA failures on LINA

CSCwk26968

Backup feature does not save/restore DAP configuration in multiple context mode.

CSCwk27175

ASA/FTD: Substantial increase in the time taken to load configuration

CSCwk27830

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwk31371

NAT_HARDEN: CGNAT breaks when mapped ifc is configured as any

CSCwk32501

256/1550 block depletion process fover_thread

CSCwk36312

High cpu on "update block depletion" causing BGP flap terminated on FTD

CSCwk37371

SGT INLINE-TAG added after upgrade to 7.4.x

CSCwk41007

ASA/FTD may traceback and reload in Thread Name 'PTHREAD-1756'

CSCwk44165

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

CSCwk48975

Packet-tracer output incorrectly appends 'control-plane' to drops for data-plane access-group

CSCwk59009

IPv6 SSL Anyconnect access blocked in HA pair

CSCwk59520

Instrument new logs in the startup process to collect more information

CSCwk61157

FTD LINA Traceback and Reload dhcp_daemon Thread

CSCwk62296

Address SSP OpenSSH regreSSHion vulnerability

CSCwk62297

Evaluation of ssp for OpenSSH regreSSHion vulnerability

CSCwk62381

ASA might traceback and reload due to ssh/client hitting a null pointer while using SCP.

CSCwk64418

NTP is not synchronising when using SHA-1 authentication

CSCwk64643

Failover prompt shows state active while the firewall is in Negotiation

CSCwk64709

FXOS upgrade failure due to insufficient free space in /mnt/pss (isan.log consumes most of space)

CSCwk71227

FTD running on FPR 2k with LDAP skips backslash when updating ldap.conf

CSCwk88201

S2S VPN with 3rd party broken after upgrading FPR 9.20

Cisco General Terms

The Cisco General Terms (including other related terms) governs the use of Cisco software. You can request a physical copy from Cisco Systems, Inc., P.O. Box 641387, San Jose, CA 95164-1387. Non-Cisco software purchased from Cisco is subject to applicable vendor license terms. See also: https://cisco.com/go/generalterms.