Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.4.1(11) – 05/20/2011

Files:  asa841-11-k8.bin, asa841-11-smp-k8.bin

Defects resolved since 8.4.1:

 

CSCsg26647

CS: undebug all command doesn't disable debug crypto ca server

CSCsy19222

Conns should update when using dynamic protocol and floating statics

CSCsy93944

Traceback on ACL modify: assertion "status" at "stride_terminal_node.c"

CSCtb63515

Clientless webvpn on ASA cannot save .html attached file with IE6 OWA

CSCtd73901

Linkdown, Coldstart SNMP Traps not sent with certain snmp-server config

CSCte08816

ASA NAT: LU allocate xlate failed error

CSCte76002

Low performance over shared vlans in multi-mode

CSCtf96635

Removing HTTP server caused page fault traceback

CSCtg41691

dynamic-filter database update triggers cpu-hog

CSCtg50770

Mngt-access (ASDM,SSH) to inside intf of 5580 fails over RA VPN session

CSCtg99798

ASA Traceback in Thread Name: snmp / checkheaps

CSCth08903

WebVPN: "Invalid Canary" error for different options in OWA 2010

CSCth08965

WebVPN: Bad performance on Internet Explorer 8 for OWA 2010 Premium

CSCth12612

ASA - VPN load balancing is disabled after failover

CSCth35722

WebVPN CIFS: 'Authentication error', when DFS host is not reachable

CSCth35961

WebVPN: Preview mode for emails works improperly for DWA 8.5.1

CSCth48476

ASA WebVPN doesnt rewrite URL Encoded Data in Location Response Header

CSCth81601

ASA tracebacks in Thread Name: Dispatch Unit

CSCth84519

PIM packet with own source address seen after failover on standby peer

CSCti07859

AC reports 'certificate validation failed' with VPN LB intermittently

CSCti11757

SNMP: ASA responds after two SNMP requests

CSCti13482

BG: Same MAC-address not allowed in two different bridge groups

CSCti16604

ASA fails to  delete an existing object in object-group

CSCti26874

Control-plane feature not working for https traffic to-the-box

CSCti34213

The file name is garbled as downloading through SSLVPN and CIFS.

CSCti54545

EIGRP metrics will not update properly on ASA

CSCti88463

WebVPN: Empty emails content for OWA 2010 through Firefox

CSCti89628

ARP table not updated by failover when interface is down on standby

CSCtj14005

Traceback with thread name netfs_thread_init

CSCtj20691

ASA traceback when using a file management on ASDM

CSCtj25717

CPU Hog in "NIC status poll" when failing over redundant intf members

CSCtj29076

ASR trans FW rewrites wrong dst. MAC when FO peers active on same ASA

CSCtj37404

Traceback in mmp inspection when connecting using CUMA proxy feature.

CSCtj45688

ASA: SYN may change close-wait conn to SYN state

CSCtj47335

Problems with Intranet Page displaying when defined as Home Page w/ASA

CSCtj48788

Page fault traceback on standby in QOS metrics during idb_get_ifc_stats

CSCtj50580

ASA - VPN outbound traffic stalling intermittently after phase 2 rekey

CSCtj55822

ASA webvpn; certain ASP elements may fail to load/display properly

CSCtj58420

Failed to update IPSec failover runtime data on the standby unit

CSCtj62266

ldap-password-management fails if user password contained & (ampersand)

CSCtj73930

IPSec/TCP fails due to corrupt SYN ACK from ASA when SYN has TCP option

CSCtj77222

WebVPN: ASA fails to save HTTP basic authentication credential

CSCtj77909

ASA:  multiple rules in Name Contraints certificate extension fails

CSCtj78200

certificate name contraints parsing fails when encoding is IA5String

CSCtj78425

Customers Application HQMS being broken by Webvpn Rewriter

CSCtj79795

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtj83995

ASA - no names applied to the config when refreshing the config on ASDM

CSCtj84665

Primary stays in Failed state while all interfaces are up

CSCtj85005

ASA as  EasyVPN Client failure on WAN IP Change when using 'mac-exempt'

CSCtj90315

ASA traceback in transparent mode due to tcp reset

CSCtj93922

Standby unit sends ARP request with Active MAC during config sync

CSCtj95695

Webvpn: Java-Trustpoint cmd error, doesn't accept MS code-signing cert

CSCtj96108

Group enumeration possible on ASA

CSCtj97800

a space inserted behind video port number after SIP inspect with PAT on

CSCtk00068

Watchdog timeout traceback following "show route"

CSCtk04293

Webvpn, SSO with Radius, CSCO_WEBVPN_PASSWORD rewritten with OTP, 8.3

CSCtk10185

OWA login page strip "\" from "domain\username"

CSCtk10911

HA replication code stuck - "Unable to sync configuration from Active"

CSCtk12556

timeout command for LDAP in aaa-server section doesn't work

CSCtk12864

Memory leak in occam new arena

CSCtk15258

ASA traceback in Thread Name:radius_rcv_auth

CSCtk15538

IKE Session : Cumulative Tunnel count always shows Zero

CSCtk34526

SSH processes stuck in ssh_init state

CSCtk36272

Add support to NAT CLI for PAT-Pools and round-robin algorithm

CSCtk54282

Webvpn memory pool may report negative values in "% of current" field.

CSCtk61257

ASA locks up port with mus server command

CSCtk61443

OpenSSL Ciphersuite Downgrade and J-PAKE Issues

CSCtk62536

WebVPN incorrectly rewrite logout link of Epic app through Firefox

CSCtk63515

MUS debugs are running with no mus configured

CSCtk84716

IKE proposal for L2TP over IPSec global IKE entry match is duplicated

CSCtk95435

ASA rewriter: radcontrols based AJAX/ASP website not working properly

CSCtk96848

snmpwalk for crasLocalAddress reports: No Such Instance currently exists

CSCtl05205

Error entering object group with similar name as network object

CSCtl06889

Failover interface monitoring only works with the first ten interfaces.

CSCtl09314

"clear conn" behaviour is inconsistent with "show conn"

CSCtl10398

Traceback in Dispatch Unit due to dcerpc inspection

CSCtl10877

ASA reload in thread name rtcli when removing a plugin

CSCtl17877

SSL handshake - no certificate for uauth users after 8.2.3 upgrade

CSCtl18462

ASA not posting correct link with Protegent Surveillance application

CSCtl18814

UTC time not shown when clock set through user configuration

CSCtl20963

DAP ACL in L2TP doesn't get applied after successful connection

CSCtl20966

The javascript is truncated when accessing via WebVPN portan on ASA

CSCtl21314

vpn-filter removed incorrectly from ASP table with EzVPN hw clients

CSCtl21765

Cut-through Proxy - Inactive users unable to log out

CSCtl51919

ASA 8.3 with Static NAT - passes traffic with translated IP in the acl

CSCtl54976

Redundant switchover occurs simultaneously on failover pair

CSCtl56719

Default "username-from-certificate CN OU" doesn't work after reload

CSCtl57784

ASA TCP sending window 700B causing CSM deployment over WAN slow

CSCtl58069

ASA - Traceback in thread DATAPATH-6-1330

CSCtl66155

Invalid internal Phone Proxy trustpoint names generated by imported CTL

CSCtl66339

Traceback in DATAPATH-2-1361, eip snp_fp_punt_block_free_cleanup

CSCtl72355

ASA WEBVPN: POST plugin - Can not find server  .plugins.   or DNS error

CSCtl74435

VPN ports not removed from PAT pool

CSCtl77907

Lister channel gets lost on aborted new connection

CSCtl86372

IKE fails to initialize when minimal data is sent to pub int.

CSCtl87114

'show mem' reports erroneous usage in a virtual context

CSCtl95958

Timeout needs twice time of configured timeout for LDAP in aaa-server

CSCtn01794

IPv6 ping fails when ping command includes interface name.

CSCtn02684

ASA SAP purchasing app may display incorrectly over webvpn

CSCtn07431

L2L IPv6 tunnel with failover not supported Syslog Broken

CSCtn08326

ESMTP Inspection Incorrectly Detects End of Data

CSCtn09117

ASA 8.2.4 402126: CRYPTO: The ASA created Crypto Archive File

CSCtn11061

ASA 5520 traceback in thread emweb/https

CSCtn20148

EIGRP default-route is not displayed w/ "ip default-route" route removed

CSCtn25702

URLs in Hidden Input Fields not Rewritten Across WebVPN

CSCtn27365

ASASM: ASDM causes traceback during context creation

CSCtn40210

FTP transfer fails on Standby ASA - uses wrong IP add. in PORT command

CSCtn41118

ASA fails over under intensive single-flow traffic

CSCtn42704

One-to-many NAT with "any" interface not working with PPTP and FTP

CSCtn53896

ASA: police command with exceed-action permit will not replicate to Stby

CSCtn57080

Bookmark macro in post parameters is not replaced with correct user/pass

CSCtn60457

ASA 8.4.1 traceback on thread name ldap_client_thread with kerberos

CSCtn61148

ASA stops handling ikev2 sessions after some time

CSCtn65995

ASA(8.3) adds a trailing space to the object name and the description

CSCtn66992

egress ACL packet drops erroneously counted on ingress interface

CSCtn69941

VPN ports not removed from PAT pool (UDP cases)

CSCtn74649

BTF DNS-Snooping TTL maxes out at 24 hours, less than actual TTL

CSCtn74652

Search query timeout/errors in SAP purchasing portal via clientless

CSCtn75476

ASA Traceback in Thread Name: snmp

CSCtn79449

Traceback: Thread Name: DATAPATH-3-1276

CSCtn80637

"Clear conf all" reboots ASA with EIGRP authentication key configuraiton

CSCtn84047

ASA: override-account-disable does not work without password-management

CSCtn84312

AnyConnect DTLS Handshake failure during rekey causes packet loss

CSCtn89300

ASA: Memory leak in PKI CRL

CSCtn90643

Traceback while replicating xlates on standby

CSCtn93052

WebVPN: Office WebApps don't work for SharePoint 2010 in IE

CSCtn96841

"ip local pool" incorrectly rejected due to overlap with existing NAT

CSCtn99847

Easy VPN authentication may consume AAA resources over time

CSCto05036

DTLS handshake fails on ASA when client retransmits ClientHello

CSCto05478

asa traceback on 8.3.2.13 Thread Name: Dispatch Unit

CSCto05640

call-home config auto repopulates after reboot

CSCto08752

ASA traceback in 8.4.1 with memory failure errors on IKE daemon

CSCto09465

FTP transfers fail with NAT configured on multi-core ASAs (5580/5585)

CSCto11365

ASA: Ldap attributes not returned for disabled account

CSCto14043

ASA may traceback when using trace feature in capture

CSCto15003

ASA 8.4.1 traceback in Thread Name: ssh with Page fault

CSCto16917

DAP terminate msg not showing for clientless, cert only authentication

CSCto23713

ASA uses a case-sensitive string compare with IBM LDAP server

CSCto34573

ASA: 8.3 upgrade to 8.4, Shared VPN Licensing config lost unable to conf

CSCto48254

ASA reset TCP socket when RTP/RTCP arrives before SIP 200 OK using PAT

CSCto49499

HA: Failover LU xmit/rcv statistics is different on Active and Standby

CSCto62499

OSPF Failover causes 5 second convergence delay

CSCto82315

Traceback in Thread Name: gtp ha bulk sync with failover config

CSCto83156

ASA Sequence of ACL changes when changing host IP of object network

CSCto87674

ST not injected in mstsc.exe on 32-bit Win 7 when started through TSWeb

CSCto96832

Unable to login to SAP application via WebVPN portal

CSCto99389

External Portal Page  Macro substitution fails

CSCtq00144

VPN RA session DAP  processing fails with memberOf from OpenLDAP

CSCtq10528

Host listed in object group TD shun exception gest shunned