Which Firepower To Replace Your ASA 5500-X?

KB ID 0001705

Problem

Well  the ASA5516-X was the last one to go end of sale. You may be able to get stock of the remainder of the ASA5500-X series as people clear their shelves, or they may be available as ‘refurb’ stock but they are disappearing.

So you would think that the replacements would be better documented? Well it’s sketchy at best, and when you look a the data sheets for the new FPR range the links on Cisco website go to the wrong place, or give you little or no guidance 🙁

Solution

I’ve put together the following to help, it’s not sanctioned by Cisco, (though I did engage Cisco Partner GVE to assist me. The following table shows FPR models that run ASA code, (not FTD code). I’m not a fan personally of the FTD solution, and I wont be deploying it anywhere for a client. But Standard Asa code keeps my support and network techs happy.

If you disagree with any of my recommendations, please post below, and (providing your objection is valid,) and I’ll update it accordingly.

Related Articles, References, Credits, or External Links

NA

Cisco 5506-X / 5512-X SFR Unsupported

KB ID 0001522

Problem

After upgrading an ASA 5506-X to Version 9.10, I was about to re-image the FirePOWER SFR module. I went to load the boot image and this happened;

[box]

sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.3.0-3.img
                                                                                 ^
ERROR: % Invalid input detected at '^' marker.

[/box]

At first I thought “Oh great, the syntax has changed, there’s another post to update“. But no, the command is correct. This is what what pointed me in the right direction.

[box]

Petes-ASA# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   1 ASA 5506-X with FirePOWER services, 8GE, AC, ASA5506            JAD1233AAAA
 sfr Unsupported                                 Unsupported

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version
---- --------------------------------- ------------ ------------ ---------------
   1 6cb2.aede.0106 to 6cb2.aede.010f  2.0          1.1.8        9.10(1)11

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   1 Up Sys             Not Applicable

[/box]

Solution

FirePOWER SFR IS NO LONGER SUPPORTED ON ASA 5506-X and ASA5512-X

Cisco’s official wording from the 9.10 version release says;

“The ASA 5506-X series and 5512-X no longer support the ASA FirePOWER module in 9.10(1) and later due to memory constraints. You must remain on 9.9(x) or lower to continue using this module. “

So downgrade the OS, at time of writing the newest supported is 9.9(2).

Related Articles, References, Credits, or External Links

NA