Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.8(1)7 – 08/01/2017

Files:  asa981-7-smp-k8.bin

Defects resolved since 9.8(1)5:

 

CSCuw37752

FTP data conn scaling fails with dynamic PAT

CSCuz72137

ASA dropping packets with "novalid adjacency" though valid ARP entry avail

CSCva74756

OSPF Rogue LSA with maximum sequence number vulnerability

CSCvb40875

Default inspect statements are missing on ASA 5500-x and 2100 device running Threat Defense

CSCvb44254

ASA 5506-X Firepower Threat Defense Reset Button

CSCvb75685

EZVPN NEM client can't reconnect after "no vpnclient enable" is entered

CSCvc96614

ASA: IKEv2 ipsec-proposal command removed if more than 9 proposals configured in single command

CSCvd01130

ASA TCP SIP inspection translation not working when IP phone is behind VPN tunnel

CSCvd35811

Traceback in thread name DATAPATH

CSCvd71473

ASA: slow memory leak when using many DNS queries

CSCvd79797

ASA local dns resolution fails when dns server is reachable through a site to site ipsec tunnel

CSCvd80740

FTD-VPN: VPN RRI not getting synced between Master and Slave units

CSCvd89003

ASA traceback observed in Datapath due to SIP inspection

CSCvd92423

ASA Traceback in Unicorn Proxy Thread

CSCvd99945

ASA traceback when customer was authenticating to AnyConnect

CSCve06367

Show Crypto Acclerator shows status as booting for hardware devices

CSCve09249

ASA: Active FTP not working with extended keyword in NAT.

CSCve14758

Standby ASA not learning routes via RIP

CSCve15873

ASA: Multicast packets getting dropped starting code 9.6.3

CSCve18293

ASA traceback observed in datapath

CSCve20346

ASA SNI connection fails after upgrade - no shared cipher

CSCve23033

ICMP Unreachables (PMTU) dropped indicating "Routing failed to locate next hop"

CSCve24088

Smart Licensing ID cert renewal failure should not deregister product instance

CSCve28027

Calls not working with CUCI Lync version 11.6.3 on ASA

CSCve29989

ASA - Traceback in DATAPATH during PAT pool socket allocation

CSCve37948

ASA does not install routes learned via OSPF over IPSec using UDP/4500

CSCve42583

ASA: IPv6 protocol X rule for passing through FW is dropping packets with Invalid IP length message

CSCve43146

AnyConnect new customization creation fails on ASDM for all ASA versions above 9.5(3)

CSCve46883

FTD Diagnostic Interface does Proxy ARP for br1 management subnet

CSCve47393

OSPF Rogue LSA with maximum sequence number vulnerability

CSCve50118

ASA Memory Leak - RSA toolkit

CSCve57150

vpn vlan mapping issue

CSCve57548

ASA- Traceback in 'Thread Name : Datapath' on crypto_SSL functions

CSCve58709

ASA 9.5.1 onwards, Traffic incorrectly routed instead of management interface

CSCve61284

ASA Log message 414003 may be generated with bogus IP data when TCP Syslog Server down

CSCve63762

ASASM: Interface vlans going to admin down after reload.

CSCve71661

FTD - Multicast and BPDU traffic dropped due to dst-l2_lookup-fail

CSCve72155

Memory leak at location "snp_fp_encrypt" when syslog server is reachable over the VPN tunnel

CSCve72227

IPsec SA fail to come up and flap with more than 1000 IPsec SA count in ASA5506/5508/5516

CSCve73556

ASA traceback on websns_rcv_tcp

CSCve97831

CDA agent stucks in 'Probing' when domain-lookup is enable

CSCvf19938

ASAv: Upgrade issues to the 9.7.1.4 and 9.8.1 when installed on Hyper-V Windows Server 2012-R2

 

 

Revision:  Version 9.8(1)5 – 06/26/2017

Files:  asa981-5-smp-k8.bin

Defects resolved since 9.8(1):

 

CSCuy48364

ASA 'show memory' output may not properly report total available memory in 9.5(2) and later

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz72137

ASA dropping packets with novalid adjacency though valid ARP entry avail

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCvb28491

Unable to run show counters protocol ip

CSCvb40875

Default inspect statements are missing on ASA 5500-x and 2100 device running Threat Defense

CSCvc24380

Traceback on thread name IKE Daemon at mqc_enable_qos_for_tunnel

CSCvc27704

Logs lost when TCP is used as transport protocol for Syslogs

CSCvc56526

CEP records edit page take minutes to load

CSCvc56919

Traffic drops for reverse UDP/TCP IPv6 traffic over IPv4 tunnel

CSCvc82270

ASA 1550 block gradual depletion

CSCvc83462

gzip compression not working via Webvpn

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvd14266

ASA traceback in DATAPATH-41-16976 thread

CSCvd15843

Port Forwarding Session times out due to vpn-idle-timeout in group-policy while passing data

CSCvd26699

ASA erroneously triggers syslog ID 201011

CSCvd29150

Mgmt route deletion removes data plane route too.

CSCvd33787

Assertion in syslog.c due to uauth

CSCvd43309

Access-lists not being matched for a newly created object-group

CSCvd46633

timeout conn-holddown shows incorrect syntax help

CSCvd49550

ASA with 9.5.1 and above does not show SXP socket when managment0/0 is used as src-ip

CSCvd50107

ASA traceback in Thread name: idfw_proc on running show access-list, while displaying remark

CSCvd55115

ASA in cluster results in incorrect user group mappings between the Master and Slave

CSCvd55999

%ASA-3-216001: internal error in ci_cons_shell: thread data misuse

CSCvd58094

ASA traceback in ARP thread, PBR configured

CSCvd58321

Web folder filebrowser applet code signing certificate expired

CSCvd61308

ASA backup in multicontext fails due to [Running Configurations] ERROR

CSCvd64416

ASA All contexts use the same EIGRP router-ID upon a reload

CSCvd64693

EIGRP routes wrongly being advertising on mgmt routing table vrf after disabling and enabling EIGRP

CSCvd66303

Error deploying ASAv on ESXi vCenter 6.5

CSCvd69804

ASA - Interface status change causes VPN traffic disconnect while using ipsec inner-routing-lookup

CSCvd76939

ASA policy-map configuration is not replicated to cluster slave

CSCvd79863

FTD OSPF with ECMP, packets are sent to peer in down state for existing connections

CSCvd82265

Increase memory allocated to rest-agent on ASAv5

CSCvd87211

ASA traceback when trying to remove configured capture

CSCvd87647

ASA traceback in Thread Name: fover_parse performing upgrade from 9.1.5 to 9.4.3

CSCvd89925

Unable to switch standby unit of the failover pair to active

CSCvd90071

Allow ASAv5 to operate using > 1GB memory

CSCvd90079

ASAv5: Reduce DMA packet memory to 64MB

CSCvd90096

WebVPN forces IE to use IE8 mode

CSCvd97249

FTD: block depletion with continuous SSL traffic and decrypt resign enabled.

CSCvd97568

FTD traceback observed during failover synchronization.

CSCvd99476

The interactive icons on internal bookmark site not showing properly (+CSCO+0undefined)

CSCvd99859

ASA may drop DNS reply containing only additional RR of type TXT

CSCve02854

SFR Backplane is pulling the public address for policy match instead of ASA inside address

CSCve03387

Proxy ARP information for SSH NLP NAT is not updating on the FTD upon failover

CSCve03974

ASA with FirePOWER services module generates traceback and reload

CSCve04326

Slave should have use CCL to forward traffic instead of blackholing when egress interface is down

CSCve04443

ASAv Azure: Allow 750 VPN sessions on ASAv30

CSCve05841

ASA reloaded while joining cluster and active as slave

CSCve07856

CRL verification fails due to incorrect KU after CSCvd41423

CSCve08664

Dist-S2S: tunnels stay up even after passing vpn idle timeout in Multimode

CSCve08947

In multi-context ASA drops traffic sourced from certain ports when interface PAT is used

CSCve12654

ASA clustering to support rollback feature with CSM

CSCve13410

Upgrading the ASA results in No Valid adjacency due to track configure on the route

CSCve15873

ASA: Multicast packets getting dropped starting code 9.6.3

CSCve18880

Username is not fetched from certificate when certificate map is used in clientless portal

CSCve19683

FP4100 SSP 9.6.2 / cluster - Tx queue stuck causing traffic drop to occur

CSCve20438

activate-tunnel-group-scripts not available in 9.6.3.1

CSCve21824

hostscan data-limit service-internal command must be exposed and documented

CSCve23091

Auto-RP packet is dropped due to no-route - No route to host

CSCve23784

ASA may traceback on displaying access-list config or saving running config

CSCve24299

Traceback in Thread Name: IP RIB Update when routes are redistributed

CSCve31809

ASA corrupt dst mac address of return traffic from l2tp client

CSCve31880

network_udpmod_get not releasing shr_lock in rare error case

CSCve34729

ASA interfaces may stop passing traffic after ASA reload with FIPS mode enabled

CSCve42460

NSF IETF/CISCO commands getting removed on reload

CSCve48105

Slave reports Master's interface status as init while it is up