Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.1.1(4) – 03/14/2013

Files:  asa911-4-smp-k8.bin

Defects resolved since 9.1.1:

 

CSCti38856

Elements in the network object group are not converted to network object

CSCtj87870

Failover disabled due to license incompatible different Licensed cores

CSCtr04553

Traceback @snp_ifc_purg_cb w/ clear conf all or write standby

CSCtr17899

Some legitimate traffic may get denied with ACL optimization

CSCtr65927

dynamic policy PAT fails with FTP data due to latter static NAT entry

CSCts15825

RRI routes are not injected after reload if IP SLA is configured.

CSCts50723

ASA: Builds conn for packets not destined to ASA's MAC in port-channel

CSCtw56859

Natted traffic not getting encrypted after reconfiguring the crypto ACL

CSCtx55513

ASA: Packet loss during phase 2 rekey

CSCty18976

ASA sends user passwords in AV as part of config command authorization.

CSCtz46845

ASA 5585 with IPS inline -VPN tunnel dropping fragmented packets

CSCtz47034

ASA 5585- 10 gig interfaces may not come up after asa reload

CSCtz56155

misreported high CPU

CSCtz64218

ASA may traceback when multiple users make simultaneous change to ACL

CSCtz70573

SMP ASA traceback on periodic_handler for inspecting icmp or dns trafic

CSCtz79578

Port-Channel Flaps at low traffic rate with single flow traffic

CSCua20850

5500X Software IPS console too busy for irq can cause data plane down.

CSCua35337

Local command auth not working for certain commands on priv 1

CSCua44723

ASA nat-pat: 8.4.4 assert traceback related to xlate timeout

CSCua60417

8.4.3 system log messages should appear in Admin context only

CSCua87170

Interface oversubscription on active causes standby to disable failover

CSCua91189

Traceback in CP Processing when enabling H323 Debug

CSCua93764

ASA: Watchdog traceback from tmatch_element_release_actual

CSCua99091

ASA: Page fault traceback when copying new image to flash

CSCub04470

ASA: Traceback in Dispatch Unit with HTTP inspect regex

CSCub08224

ASA 210005 and 210007 LU allocate xlate/conn failed with simple 1-1 NAT

CSCub11582

ASA5550 continous reboot with tls-proxy maximum session 4500

CSCub14196

FIFO queue oversubscription drops packets to free RX Rings

CSCub16427

Standby ASA traceback while replicating flow from Active

CSCub23840

ASA traceback due to nested protocol object-group used in ACL

CSCub37882

Standby ASA allows L2 broadcast packets with asr-group command

CSCub58996

ASA: Page fault traceback in Unicorn Proxy Thread with WebVPN

CSCub61578

ASA: Assert traceback in PIX Garbage Collector with GTP inspection

CSCub62584

ASA unexpectedly reloads with traceback in Thread Name: CP Processing

CSCub75522

ASA TFW sends broadcast arp traffic to all interfaces in the context

CSCub84164

ASA traceback in threadname Logger

CSCub89078

ASA standby produces traceback and reloads in IPsec message handler

CSCub99578

High CPU HOG when connnect/disconnect VPN with large ACL

CSCub99704

WebVPN - mishandling of request from Java applet

CSCuc06857

Accounting STOP with caller ID 0.0.0.0 if admin session exits abnormally

CSCuc09055

Nas-Port attribute different for authentication/accounting Anyconnect

CSCuc12119

ASA: Webvpn cookie corruption with external cookie storage

CSCuc12967

OSPF routes were missing on the Standby Firewall after the failover

CSCuc16670

ASA - VPN connection remains up when DHCP rebind fails

CSCuc24547

TCP ts_val for an ACK packet sent by ASA for OOO packets is incorrect

CSCuc24919

ASA: May traceback in Thread Name: fover_health_monitoring_thread

CSCuc28903

ASA 8.4.4.6 and higher: no OSPF adj can be build with Portchannel port

CSCuc32843

ACL not getting migrated correctly (FWSM to ASA-SM with migration tool)

CSCuc34345

Multi-Mode treceback on ci/console copying config tftp to running-config

CSCuc45011

ASA may traceback while fetching personalized user information

CSCuc46026

ASA traceback: ASA reloaded when call home feature enabled

CSCuc46270

ASA never removes qos-per-class ASP rules when VPN disconnects

CSCuc48355

ASA webvpn - URLs are not rewritten through webvpn in 8.4(4)5

CSCuc50544

Error when connecting VPN: DTLS1_GET_RECORD Reason: wrong version number

CSCuc55719

Destination NAT with non single service  (range, gt, lt) not working

CSCuc56078

Traceback in threadname CP Processing

CSCuc60950

Traceback in snpi_divert with timeout floating-conn configured

CSCuc61985

distribute-list does not show in the router config.

CSCuc63592

HTTP inspection matches incorrect line when using header host regex

CSCuc75090

Crypto IPSec SA's are created by dynamic crypto map for static peers

CSCuc75093

Log indicating syslog connectivity not created when server goes up/down

CSCuc78176

Cat6000/15.1(1)SY- ASASM/8.5(1.14) PwrDwn due to SW Version Mismatch

CSCuc79825

5580 - Thread Name: CP Midpath Processing eip pkp_free_ssl_ctm

CSCuc83059

traceback in fover_health_monitoring_thread

CSCuc83323

XSS in SSLVPN

CSCuc83828

ASA Logging command submits invalid characters as port zero

CSCuc89163

Race condition can result in stuck VPN context following a rekey

CSCuc95774

access-group commands removed on upgrade to 9.0(1)

CSCuc98398

ASA writes past end of file system then can't boot

CSCud02647

traffic is resetting uauth timer

CSCud16590

ASA may traceback in thread emweb/https

CSCud17993

ASA-Traceback in Dispatch unit due to dcerpc inspection

CSCud24452

ASA TACACS authentication on Standby working incorrectly

CSCud29045

ASASM forwards subnet directed bcast back onto that subnet

CSCud32111

Deny rules in crypto acl blocks inbound traffic after tunnel formed

CSCud36686

Deny ACL lines in crypto-map add RRI routes

CSCud37992

SMP ASA traceback in periodic_handler in proxyi_rx

CSCud41507

Traffic destined for L2L tunnels can prevent valid L2L from establishing

CSCud41670

ASA nested traceback with url-filtering policy during failover

CSCud57759

DAP: debug dap trace not fully shown after +1000 lines

CSCud67282

data-path: ASA-SM: 8.5.1 traceback in Thread Name: SSH

CSCud84454

ASA in HA lose shared license post upgrade to 9.x

CSCue03220

Anyconnect mtu config at ASA not taking effect at client

CSCue32221

LU allocate xlate failed (for NAT with service port)

CSCue99041

Smart Call Home sends Environmental message every 5 seconds for 5500-X