Cisco ASA 5500 Series
Common problems
This section describes common problems with the ASA, with possible causes and recommended actions,
Note |
Send traps northbound, and not to Prime Collaboration Assurance. |
- Symptom
The context configuration was not saved, and was lost when you reloaded.
Possible cause
You did not save each context within the context execution space. If you are configuring contexts at the command line, you did not save the current context before you changed to the next context.
Recommended action
Save each context within the context execution space using the copy start run command. Load the startup configuration as your active configuration. Then change the password and then enter the copy run start command. Or use the write memory all command to save all contexts. This can take significant time on a large system.
- Symptom
You cannot make a Telnet or SSH connection to the ASA interface.
Possible cause
You did not enable Telnet or SSH to the ASA.
Recommended action
Enable Telnet or SSH to the ASA.
- Symptom
You cannot ping the ASA interface.
Possible cause
You disabled ICMP to the ASA.
Recommended action
Enable ICMP to the ASA for your IP address using the icmp command.
- Symptom
You cannot ping through the ASA, although the access list allows it.
Possible cause
You did not enable the ICMP inspection engine or apply access lists on both the ingress and egress interfaces.
Recommended action
Because ICMP is a connectionless protocol, the ASA does not automatically allow returning traffic through. In addition to an access list on the ingress interface, you either need to apply an access list to the egress interface to allow replying traffic, or enable the ICMP inspection engine, which treats ICMP connections as stateful connections.
- Symptom
Traffic does not pass between two interfaces on the same security level.
Possible cause
You did not enable the feature that allows traffic to pass between interfaces at the same security level.
Recommended action
Enable the feature.
- Symptom
IPsec tunnels do not duplicate during a failover to the standby device.
Possible cause
The switch port that the ASA is plugged into is set to 10/100 instead of 1000.
Recommended action
Set the switch port that the ASA is plugged into to 1000.
For more information about troubleshooting for the Cisco ASA 5500 Series, see: