Windows 10: Cisco ASDM ‘This app can’t run on your PC’
Jul19

Windows 10: Cisco ASDM ‘This app can’t run on your PC’

KB ID 0001574 Problem Whys isn’t Java dead yet? šŸ™ Anyway, I tried to connect to a clients ASDM today, and from my Windows 10 machine, I got the following error; This app can’t run on your PC To find a version for your PC, check with the software publisher. Solution If you are launching straight for the desktop open theĀ properties of the ASDM shortcut, and look at the ‘Target’ value. Change it to;...

Read More
Cisco IOS: Ether-Channel Trunks
Apr08

Cisco IOS: Ether-Channel Trunks

KB ID 0001533 Problem This is a subject that every time I need to create an Ether-Channel I end up checking beforehand, so it’s about time I wrote it up. We are combining two different things, an Ether-channel, (an aggregation of links) and a Trunk (the ability to carry many VLANS). If you are NOT from a Cisco background then you might want to read though the following post first to avoid confusion about the world...

Read More
Cisco ASA VPN to Cisco Router “MM_WAIT_MSG3”
Mar27

Cisco ASA VPN to Cisco Router “MM_WAIT_MSG3”

KB ID 0001531 Problem While migrating a VPN tunnel from an ASA 5520 firewall to a new 5516-X I got this problem. The other end was a Cisco router (2900). As soon as I swapped it over, it was stuck at MM_WAIT_MSG3, and phase 1 would not establish; NUFC-ASA5516x(config-tunnel-ipsec)# show crypto isa IKEv1 SAs: Active SA: 6 Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey) Total IKE SA: 6 1 IKE Peer: 1.1.1.1 Type :...

Read More
Cisco ASA: “Wrong Serial Number?”
Mar27

Cisco ASA: “Wrong Serial Number?”

KB ID 0001530 Problem Cisco have done this for a while, the first time I saw it was years ago on a 5585, but all the NGFW models now have a ‘Serial Number” and a “Chassis Serial Number”. Normally you don’t care unless you need to log a TAC call online. So you issue a show version command, take a note of the serial number, and then it says, there’s no record of that serial number? Solution Just to be...

Read More
Cisco 5506-X / 5512-X SFR Unsupported
Feb26

Cisco 5506-X / 5512-X SFR Unsupported

KB ID 0001522 Problem After upgrading an ASA 5506-X to Version 9.10, I was about to re-image the FirePOWER SFR module. I went to load the boot image and this happened; sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.3.0-3.img ^ ERROR: % Invalid input detected at ‘^’ marker. At first I thought “Oh great, the syntax has changed, there’s another post to update”. But no, the command is...

Read More
Microsoft Azure ā€˜Route Basedā€™ VPN to Cisco ASA
Feb13

Microsoft Azure ā€˜Route Basedā€™ VPN to Cisco ASA

KB ID 0001515 Problem This coversĀ the, (more modern) Route based VPN to a Cisco ASA that’s using a VTI (Virtual Tunnel Interface). Ā  Virtual Network Gateway Options With VPN’s into Azure you connect to a Virtual Network Gateway, of which there are TWO types Policy Based, and Route Based. This article will deal with Route Based, for the older Policy Based option, see the following link; Microsoft Azure To Cisco ASA Site to...

Read More