======Cisco - Firewall - Miscellaneous====== [[https://www.cisco.com/c/en/us/products/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-listing.html|Cisco - End-of-Life and End-of-Sale Notices]] for ASA hardware EoL dates. \\ [[https://www.cisco.com/c/en/us/products/security/asa-firepower-services/eos-eol-notice-listing.html|End-of-Life and End-of-Sale Notices]] for ASA software. [[https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|Cisco - Cisco ASA Compatibility]] \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asa-vpn-compatibility.html|Cisco - Supported VPN Platforms, Cisco ASA Series]] [[https://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/asaroadmap.html|Cisco - Navigating the Cisco ASA Series Documentation]] =====PIX===== // The predecessor of the Cisco ASA series firewalls. // [[https://www.youtube.com/watch?v=BPN2nU1v6l4|YouTube - Cisco PIX 501 compact 4 port firewall #teardown]] on 2023-02-18 by [[https://www.youtube.com/@computersales|Computers Cats and More]]. \\ =====ASA===== [[https://www.cisco.com/c/en/us/support/security/adaptive-security-appliance-asa-software/series.html|Cisco Secure Firewall ASA]] \\ [[https://www.cisco.com/c/en/us/support/security/adaptive-security-device-manager/series.html|Cisco Secure Firewall ASDM]] [[wp>Cisco_ASA|Cisco ASA]] [[https://www.reddit.com/r/Cisco/comments/15jbg81/is_cisco_asa_still_worth_it_in_2023/|Reddit - Is Cisco ASA still worth it in 2023 ?]] \\ [[https://www.reddit.com/r/Cisco/comments/h84yob/why_cisco_asa_isnt_dead_yet/|Reddit - Why Cisco ASA isn’t dead yet ?]] \\ [[https://www.cisco.com/c/en/us/products/security/asa-5500-series-next-generation-firewalls/data_sheet_c78-345385.html|Cisco ASA 5500 Series Adaptive Security Appliances Data Sheet]] \\ [[https://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/series.html|Cisco ASA 5500-X Series Firewalls]] [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config.html|CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.1]] \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config.html|CLI Book 2: Cisco ASA Series Firewall CLI Configuration Guide, 9.1]] \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config.html|CLI Book 3: Cisco ASA Series VPN CLI Configuration Guide, 9.1]] [[https://github.com/jbaines-r7/theway|GitHub - jbaines-r7/theway]] A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829). \\ [[https://github.com/nccgroup/asafw|GitHub - nccgroup/asafw]] Set of scripts to deal with Cisco ASA firmware [pack/unpack etc.] \\ [[https://github.com/nccgroup/asatools|GitHub - nccgroup/asatools]] Main repository to pull all NCC Group Cisco ASA-related tool projects. \\ [[https://research.nccgroup.com/2017/09/20/cisco-asa-series-part-one-intro-to-the-cisco-asa/|NCC Group Research Blog - Cisco ASA series part one: Intro to the Cisco ASA]] \\ [[https://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/products-release-notes-list.html|Cisco ASA 5500-X Series Firewalls - Release Notes]] [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/release/notes/asarn91.html|Release Notes for the Cisco ASA Series, 9.1(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-738645.html|EoS and EoL ASA 9.1, ASDM 7.1]] Last Date of Support: OS SW 2022-08-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/release/notes/asarn92.html|Release Notes for the Cisco ASA Series, 9.2(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-738647.html|EoS and EoL ASA 9.2, ASDM 7.2]] Last Date of Support: OS SW 2022-08-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html|Release Notes for the Cisco ASA Series, 9.4(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-740361.html|EoS and EoL ASA(v) 9.4(x), ASDM 7.4(x)]] Last Date of Support: App SW 2021-08-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/release/notes/asarn96.html|Release Notes for the Cisco ASA Series, 9.6(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-742130.html|EoS and EoL ASA(v) 9.6(x) ASDM 7.6(x)]] Last Date of Support: App SW 2022-09-30. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa97/release/notes/asarn97.html|Release Notes for the Cisco ASA Series, 9.7(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-738646.html|EoS and EoL ASA 9.7, ASDM 7.7]] Last Date of Support: OS SW 2022-08-31 \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/release/notes/asarn98.html|Release Notes for the Cisco ASA Series, 9.8(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-eol.html|EoS and EoL ASA(v) 9.8(x) ASDM 7.8(x)]] Last Date of Support: App SW 2025-02-28.\\ [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-743169.html|EoS and EoL ASA(v) 9.9(x) ASDM 7.9(x)]] Last Date of Support: App SW 2023-05-31. \\ [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-742275.html|EoS and EoL ASA(v) 9.10(x) ASDM 7.10(x)]] Last Date of Support: App SW 2022-10-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/release/notes/asarn912.html|Release Notes for the Cisco ASA Series, 9.12(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-12x-eol.html|EoS and EoL ASA(v) 9.12(x) ASDM 7.12(x)]] Last Date of Support: App SW 2026-02-28. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/release/notes/asarn913.html|Release Notes for the Cisco ASA Series, 9.13(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-743796.html|EoS and EoL ASA(v) 9.13(x), ASDM 7.13(x)]] Last Date of Support: App SW 2023-06-30.\\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/release/notes/asarn914.html|Release Notes for the Cisco ASA Series, 9.14(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-eol.html|EoS and EoL ASA(v) 9.14(x), ASDM 7.14(x)]] Last Date of Support: App SW 2025-03-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa915/release/notes/asarn915.html|Release Notes for the Cisco ASA Series, 9.15(x)]] and [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-744625.html|EoS and EoL ASA(v) 9.15(x), ASDM 7.15(x)]] Last Date of Support: App SW 2024-06-30. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/release/notes/asarn916.html|Release Notes for the Cisco ASA Series, 9.16(x)]] \\ [[https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/adaptive-security-appliance-9-17x-eol.html|EoS and EoL ASA(v) 9.17(x), ASDM 7.17(x)]] Last Date of Support: App SW 2025-12-31. \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/asa_new_features.html|Cisco Secure Firewall ASA New Features by Release]] [[https://www.petenetlive.com/KB/Article/0001496|PeteNetLive - Cisco ASA: Remove FTD and Return to ASA and ASDM]] \\ [[https://www.petenetlive.com/KB/Article/0000553|PeteNetLive - ASA – Memory Error (Post upgrade to version 8.3)]] \\ [[https://www.alfredtong.com/cisco/how-to-get-the-latest-cisco-asaasdm-firmware-image-and-update-for-free/|NAT Overload - How to get the latest Cisco ASA/ASDM firmware image and update for free!]] \\ [[https://networkproguide.com/download-cisco-ios-updates-free/|NetworkProGuide - How to Download Cisco IOS Updates for Free (Legally)]] \\ [[https://www.rapid7.com/blog/post/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software/|Rapid7 Blog - Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software]] posted on 2022-08-11. [[https://www.youtube.com/watch?v=RsaxwRyaO-o|YouTube - Cisco ASA 5500 Series Family Video Data Sheet]] on 2011-03-15 by [[https://www.youtube.com/@i3webservices|i3webservices]]. [[https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82310-qos-voip-vpn.html|Cisco - QoS on the Cisco ASA Configuration Examples]] \\ [[https://serverfault.com/questions/322621/qos-on-cisco-asa-5505-by-vlan-subnet/322803#322803|Server Fault - QoS on Cisco ASA 5505 by VLAN/subnet]] \\ [[https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/116388-technote-nat-00.html|Cisco - Troubleshoot ASA Network Address Translation (NAT) Configuration]] [[https://github.com/in-transit/regional-asa|GitHub - in-transit/regional-asa]] This script will create network objects based off region/country. Uses delegated statistics files from for example [[https://www.arin.net/reference/research/statistics/nro_stats/|ARIN - Extended Delegation Statistics]]. Via [[https://serverfault.com/questions/281178/how-to-block-a-countries-ip-range-with-a-cisco-asa|server fault - How to block a Countries IP range with a Cisco ASA?]]. [[https://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/licenseroadmap.html|Cisco Secure Firewall ASA Series Feature Licenses]] \\ [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/intro_license.html|CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.1 - Chapter: Managing Feature Licenses]], [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/intro_license.html#10155|Supported Feature Licenses Per Model]] \\ [[https://traceroute.home.blog/2021/05/29/cisco-asa-5505-asdm-stuck-at-17/|The Traceroute Blog - Cisco ASA 5505 ASDM stuck at 17%]] [[https://community.cisco.com/t5/network-security/asa-5515-versus-5515-x/td-p/2467824|Cisco Community - ASA 5515 versus 5515-X]] [[https://hackernet.se/w/Cisco_ASA|HacherNet - Cisco ASA]] [[https://community.cisco.com/t5/security-blogs/asa-and-firepower-hardware-fact-sheet/ba-p/3665136|Cisco Community - ASA and Firepower hardware fact sheet]] lists CPU type, model, and crypto accelerator for several ASA models. [[https://github.com/jbaines-r7/cisco_asa_research|GitHub - jbaines-r7/cisco_asa_research]] Cisco ASA Software and ASDM Security Research. Can [[https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1|Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability]] for CVE-2018-0101 be use to get ASA for Cisco ASA 5500 series from TAC? \\ Another much older one [[https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141008-asa|Multiple Vulnerabilities in Cisco ASA Software]] with many CVE-2014-* CVEs. [[https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-snmp|Cisco Adaptive Security Appliance SNMP Remote Code Execution Vulnerability]] CVE-2016-6366. Affects Cisco ASA 5500 series with fix available in 9.1.7(9) or 9.0.4(40), and PIX series with no fix available. Workaround: limit/disable access to SNMP. \\ [[https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-cli|Cisco Adaptive Security Appliance CLI Remote Code Execution Vulnerability]] CVE-2016-6367. Affects Cisco ASA 5500 series with fix available in 9.0(1), and PIX series with no fix available. [[https://www.youtube.com/watch?v=yvRPY1FnK4A|YouTube - ASA Firewall - Cisco ASA Firewall Full Course | 2022]] by [[https://www.youtube.com/@KnowledgePowerS|Knowledge Power]] on 2020-12-29. [[https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/200150-Cisco-Guide-to-Harden-Cisco-ASA-Firewall.html|Cisco - Use Guide to Secure ASA Firewall]] \\ [[https://sec.cloudapps.cisco.com/security/center/resources/asa_integrity_assurance.html|Cisco - ASA Integrity Assurance]] ====5505==== [[https://www.cisco.com/c/en/us/support/security/asa-5505-adaptive-security-appliance/model.html|Cisco - ASA 5505]] [[https://www.youtube.com/watch?v=XXkx8jBasmg|YouTube - Cisco ASA5505 firewall teardown an detailed overview for CCNA security lab and repair]] on 2016-02-11 by [[https://www.youtube.com/@DonkeyLearningIT|Donkey Learning IT]]. asa924-33-k8.bin is the latest and last release for the 5505(non-X) model. and you shouldnt (I wouldnt) install ASDM past asdm-771-151.bin, but YMMV. Source: [[https://www.reddit.com/r/networking/comments/t2cv22/asa5505_setup/|Reddit - r/networking - ASA5505 Setup]] [[https://github.com/jjkirn/ASDM|GitHub - jjkirn/ASDM]] Cisco ASA 5505 Adaptive Security Appliance. How to resolve Cisco ASDM-IDM Java Web Application issues with Oracle JRE. ====5506-X==== [[https://pei.com/configure-cisco-asa-5506-replace-5505/|PEI - Cisco ASA 5506: Configuring the Interfaces to Replace the ASA 5505]]. In short: Clear the current inside interface, create a port-channel, and add the desired number of interfaces to it. ====5510==== [[https://www.reddit.com/r/Cisco/comments/w28mw3/does_asa5510_have_vga_pins/|Reddit - Does ASA-5510 have VGA pins?]]. In short: no it does not, VGA pins seem to only be found on 5500-X models. ====5520==== [[https://www.youtube.com/watch?v=LqGQaQWUo8M|YouTube - Cisco ASA 5520 Firewall #teardown]] on 2021-10-13 by [[https://www.youtube.com/@computersales|Computers Cats and More]]. ====5550==== [[https://www.youtube.com/watch?v=U7za_ThOyYw|YouTube - Cisco ASA 5550 series adaptive security appliance #teardown]] on 2023-05-31 by [[https://www.youtube.com/@computersales|Computers Cats and More]]. ====5580==== [[https://www.cisco.com/c/en/us/support/security/asa-5580-adaptive-security-appliance/model.html|Cisco ASA 5580 Adaptive Security Appliance]] \\ [[https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/end_of_life_c51-642590.html|EOL/EOS for the Cisco ASA 5580 Adaptive Security Appliance]], Last Date of Support is July 31, 2017. [[https://software.cisco.com/download/home/281191384/type|Cisco Software Download - ASA 5580 Adaptive Security Appliance]] \\ [[https://www.cisco.com/web/software/280775065/109852/ASA-904-Interim-Release-Notes.html|Cisco ASA Interim Release Notes - 9.0 series]] [[https://www.youtube.com/watch?v=MEfuqtue4ck|YouTube - Let's Look - Cisco ASA 5580 - Appliance Server]] on 2017-04-21 by [[https://www.youtube.com/@krypticnexus|Anthony Cress]]. \\ [[https://www.youtube.com/watch?v=LLPWLIhOx64|YouTube - Cisco ASA 5580 Adaptive Security Appliance Video Data Sheet]] on 2011-06-08 by [[https://www.youtube.com/@TechSuperstore|TechSuperStore]]. \\ ====5585-X==== [[https://www.cisco.com/c/en/us/obsolete/security/cisco-asa-5585-x-adaptive-security-appliance.html|Cisco ASA 5585-X Adaptive Security Appliance - Retirement Notification]] \\ [[https://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/eos-eol-notice-c51-740021.html|End-of-Sale and End-of-Life Announcement for the Cisco ASA 5585-X Adaptive Security Appliance]], Last Date of Support: HW: May 31, 2023. \\ [[https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118824-configure-firepower-00.html|Cisco - Install a SFR Module on an ASA 5585-X Hardware Module]] [[https://www.youtube.com/watch?v=0hnpF-hzdZA|YouTube - Partial disassembly of a Cisco ASA 5585-X Adaptive Security Appliance #teardown.]] on 2022-06-21 by [[https://www.youtube.com/@computersales|Computers Cats and More]]. \\ [[https://www.youtube.com/watch?v=5DteXNqZcQI|YouTube - SSP-40 module out of a Cisco ASA 5585-X Adaptive Security Appliance #teardown]] on 2023-02-11 by [[https://www.youtube.com/@computersales|Computers Cats and More]]. \\ ====5506, ASA 5506W, ASA 5506H, ASA 5508, and ASA 5516 clock signal issue==== Problem Description The Adaptive Security Appliance (ASA) 5506, ASA 5506W, ASA 5506H, ASA 5508, and ASA 5516 might fail after 18 months or longer in operation due to a clock signal component failure. Once the component has failed, the system will stop functioning, will not boot, and is not recoverable. Problem Symptom The security appliances no longer function and, subsequently, the system fails to boot. In addition, the LED status indicators on the security appliance illuminate as follows: * Power LED is green * Status LED is amber and blinking ^Product ID^Possibly Affected VID^Fixed VID^ |ASA5506|V03 or earlier|V04 or later| |ASA5506H|V03 or earlier|V04 or later| |ASA5506W|V05 or earlier|V06 or later| |ASA5508|V04 or earlier|V05 or later| |ASA5516|V04 or earlier|V05 or later| [[https://www.cisco.com/c/en/us/support/docs/field-notices/642/fn64228.html|Cisco - Field Notice: FN - 64228 - ASA 5506, ASA 5506W, ASA 5506H, ASA 5508, and ASA 5516 Might Fail After 18 Months or Longer Due to Clock Signal Component Failure - Replace on Failure]] \\ [[https://www.cisco.com/c/en/us/support/web/clock-signal.html|Cisco - Clock Signal Component Issue]] [[https://community.cisco.com/t5/network-security/clock-signal-repair-pictures-isr4300-asa-isr4400/td-p/3088505/page/2|Cisco Community - Clock-Signal Repair Pictures ISR4300, ASA, ISR4400]] \\ [[https://www.reddit.com/r/Cisco/comments/ub64tv/asa_5506_v05_clock_bug_resurrection/|Reddit - ASA 5506 V05 clock bug resurrection.]] =====ASA Memory===== // Taken from [[https://web.archive.org/web/20171114225430/https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2017-11-14]]. // ^ASA Model^Internal Flash Memory (Default Shipping)^Total DRAM (Default Shipping)^^DRAM Allocated to FW/VPN^DRAM Allocated to Module^ ^ ^ ^Before Feb. 2010^After Feb. 2010^ ^ ^ |5505|128 MB|256 MB|512 MB|512 MB|On module| |5510|256 MB|256 MB|1 GB|1 GB|On module| |5520|256 MB|512 MB|2 GB|2 GB|On module| |5540|256 MB|1 GB|2 GB|2 GB|On module| |5550|256 MB|4 GB|4 GB|4 GB|On module| |5580-20|1 GB|8 GB|8 GB|8 GB|N/A| |5580-40|1 GB|12 GB|12 GB|12 GB|N/A| |5506-X, 5506H-X, 5506W-X|8 GB|4 GB||1.8 GB|2.2 GB| |5508-X|8 GB|8 GB||4 GB|4 GB| |5512-X|4 GB|4 GB||2 GB|2 GB| |5515-X|8 GB|8 GB||4 GB|4 GB| |5516-X|8 GB|8 GB||4 GB|4 GB| |5525-X|8 GB|8 GB||4 GB|4 GB| |5545-X|8 GB|12 GB||6 GB|6 GB| |5555-X|8 GB|16 GB||8 GB|8 GB| |5585-X with SSP-10|2 GB|6 GB||6 GB|On module| |5585-X with SSP-20|2 GB|12 GB||12 GB|On module| |5585-X with SSP-40|2 GB|12 GB||12 GB|On module| |5585-X with SSP-60|2 GB|24 GB||24 GB|On module| |ASASM|8 GB|24 GB||24 GB|N/A| |Firepower 2110, 2120|8 GB|16 GB||16 GB|N/A| |Firepower 2130|8 GB|32 GB||32 GB|N/A| |Firepower 2130|8 GB|64 GB||64 GB|N/A| ====Memory Requirements==== The following sections list the memory requirements for current and legacy models. ===Current Models=== All current models include enough DRAM to run any supported release. There are no DRAM upgrade kits available. You can optionally install external flash memory to store additional images or other files. See the hardware guide for your model for more information. ===Legacy Models=== See the following memory requirements for legacy models: * ASA 5505—With Version 8.3 through 9.1 only the Unlimited Hosts license and the Security Plus license with failover enabled require 512 MB DRAM; other licenses can use 256 MB. For Version 9.2 and later, all ASA 5505 licenses require 512 MB. * ASA 5510, 5520, and 5540—To run 8.3 and later, you need the DRAM amount that shipped by default after February 2010. If you have an earlier unit, you must buy a memory upgrade kit. See Memory Kits. * ASA 5510 through 5550—You might need to upgrade the internal flash memory to 512 MB or add external flash memory if you load multiple images of the AnyConnect client along with one or more images of the ASA software, ASDM, client/server plugins, or Cisco Secure Desktop. In particular, you might need to upgrade for multiple AnyConnect 3.0 and higher clients with optional modules. * ASA 5520s and ASA 5540s manufactured before August 2011 have four DIMM sockets. ASA 5520s and ASA 5540s manufactured after this date have two DIMM sockets. All ASA 5550s have four DIMM sockets. ====Memory Kits==== The following table lists the DRAM (also referred to as DIMM) kits. ^Model^Size^Part Number^ |ASA 5505|512 MB|ASA5505-MEM-512=| |ASA 5510 (If you previously purchased the 512 MB upgrade kit for the ASA 5510 (ASA5510-MEM-512=), you must upgrade to the 1 GB memory upgrade kit to run Version 8.3.)|1 GB|ASA5510-MEM-1GB=| |ASA 5520|2 GB|ASA5520-MEM-2GB=| |ASA 5540|2 GB|ASA5540-MEM-2GB=| |ASA 5550|4 GB|2 x ASA5540-MEM-2GB=| ====CompactFlash Upgrade Kits==== The following table lists the CompactFlash upgrade kits available for the ASA 5510 through ASA 5550, for use as internal or external flash memory. ^Model^Size^Part Number^ |ASA 5510 through ASA 5550|256 MB|ASA5500-CF-256MB=| |ASA 5510 through ASA 5550|512 MB|ASA5500-CF-512MB=| =====ASA Version Notes===== From [[https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|Cisco Secure Firewall ASA Compatibility]]: * ASA 9.18(x) was the final version for the Firepower 4110, 4120, 4140, 4150, and Security Modules SM-24, SM-36, and SM-44 for the Firepower 9300. * ASA 9.16(x) was the final version for the ASA 5506-X, 5506H-X, 5506W-X, 5508-X, and 5516-X. * ASA 9.14(x) was the final version for the ASA 5525-X, 5545-X, and 5555-X. * ASA 9.12(x) was the final version for the ASA 5512-X, 5515-X, 5585-X, and ASASM. * ASA 9.2(x) was the final version for the ASA 5505. Later ASDM versions continue to support the ASA 5505. * ASA 9.1(x) was the final verison for the ASA 5510, 5520, 5540, 5550, and 5580. * ASDM versions are backwards compatible with all previous ASA versions, unless otherwise stated. For example, ASDM 7.12(1) can manage an ASA 5515-X on ASA 9.10(1). * New ASA versions require the coordinating ASDM version or a later version; you cannot use an old version of ASDM with a new version of ASA. For example, you cannot use ASDM 7.10 with ASA 9.12. For ASA interims, you can continue to use the current ASDM version, unless otherwise stated. For example, you can use ASA 9.12(1.15) with ASDM 7.12(1). * ASA 9.8(4.45) and 9.12(4.50) and later require ASDM 7.18(1.152) or later. The ASA now validates whether the ASDM image is a Cisco digitally signed image. If you try to run an older ASDM image than 7.18(1.152) with an ASA version with this fix, ASDM will be blocked and the message “%ERROR: Signature not valid for file disk0:/” will be displayed at the ASA CLI. Older versions of the [[https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|Cisco Secure Firewall ASA Compatibility]] page: * [[https://web.archive.org/web/20210508144409/https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2021-05-08]] still mentions ASA 9.4 to 8.4. * [[https://web.archive.org/web/20190401061212/https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2019-04-01]] still mentions ASA 8.3 to 7.2. * [[https://web.archive.org/web/20171114225430/https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2017-11-14]] still mentions ASA 55[1-2,4-5,8]0s, and one of the last versions to do so. * [[https://web.archive.org/web/20160618182749/http://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2016-06-18]] * [[https://web.archive.org/web/20140303140307/http://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html|archive.org - 2014-03-03]] still mentions ASA versions for ASA 55[1-2,4-5,8]0s, and PIX ASDM compatibility. Cisco ASA release notes: * [[https://www.cisco.com/web/software/280775065/109852/ASA-904-Interim-Release-Notes.html|9.0(4) Interim Release Notes]] * [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/release/notes/asarn91.html|Release Notes for the Cisco ASA Series, 9.1(x)]] * [[https://www.cisco.com/web/software/280775065/131523/ASA-917-Interim-Release-Notes.html|9.1(7) Interim Release Notes]] * [[https://www.cisco.com/web/software/280775065/123352/ASA-916-Interim-Release-Notes.html|9.1(6) Interim Release Notes]] * [[https://www.cisco.com/web/software/280775065/112517/ASA-915-Interim-Release-Notes.html|9.1(5) Interim Release Notes]] * [[https://www.cisco.com/web/software/280775065/107119/ASA-913-Interim-Release-Notes.html|9.1(3) Interim Release Notes]] * [[https://www.cisco.com/web/software/280775065/105669/ASA-912-Interim-Release-Notes.html|9.1(2) Interim Release Notes]] * [[https://www.cisco.com/web/software/280775065/101125/ASA-911-Interim-Release-Notes.html|9.1(1) Interim Release Notes]] ====Traffic shaping not supported on multi-core ASA up to 9.2==== [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/conns_qos.html|CLI Book 2: Cisco ASA Series Firewall CLI Configuration Guide, 9.1]] lists: Model Guidelines * Traffic shaping is only supported on the ASA 5505, 5510, 5520, 5540, and 5550. Multi-core models (such as the ASA 5500-X) do not support shaping. * (ASA 5580) You cannot create a standard priority queue for a Ten Gigabit Ethernet interface. Note : For the ASA 5585-X, standard priority queuing is supported on a Ten Gigabit Interface. * (ASA 5512-X through ASA 5555-X) Priority queuing is not supported on the Management 0/0 interface. * (ASASM) Only policing is supported. These limitations are also listed for ASA 9.2 on [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/firewall/asa-firewall-cli/conns-qos.html|CLI Book 2: Cisco ASA Series Firewall CLI Configuration Guide, 9.2]]. But have disappeared for ASA 9.4 on [[https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/firewall/asa-94-firewall-config/conns-qos.html|CLI Book 2: Cisco ASA Series Firewall CLI Configuration Guide, 9.4]]. =====Traffic Shaping/Policing===== [[https://www.routerfreak.com/traffic-policing-vs-traffic-shaping/|Router Freak! - Traffic Policing vs. Traffic Shaping]] \\ [[https://www.cisco.com/c/en/us/support/docs/quality-of-service-qos/qos-policing/19645-policevsshape.html|Cisco - Compare Traffic Policy and Traffic Shape to Limit Bandwidth]] =====Management===== [[https://github.com/DiogoAndre/napalm-asa-asdm|GitHub - DiogoAndre/napalm-asa-asdm]] This is a [[https://github.com/napalm-automation/napalm|NAPALM]] community driver for the Cisco ASA platform, using the ASDM HTTPS interface as means to communicate with the device. \\ [[https://github.com/napalm-automation-community/napalm-asa|GitHub - napalm-automation-community/napalm-asa]] This is a [[https://github.com/napalm-automation/napalm|NAPALM]] community driver for the Cisco ASA platform, using the ASA REST interface. The REST API is only available from software version 9.3.2 and up, and on the 5500-X series, ASAv, ASA on Firepower and ISA 3000 platforms. [[https://github.com/rhwendt/asdm|GitHub - rhwendt/asdm]] This is a cli asdm launcher. It will automatically add the ASA to the java exceptions list. =====ASDM===== ====ASDM 7.18+ on OpenBSD==== // Tested on OpenBSD/AMD64 7.2, with ASA 9.12(4)58 and ASDM 7.19(1)95. // \\ // When used this way ASDM 7.19(1)95 keeps asking to set an enable password on start, even when it is already set, and to apply changes on close, even when there are no changes. // Based on [[https://williamlieurance.com/cisco-asdm-718-719-linux/|William Lieurance's Tech Blog - Running Cisco ASDM 7.18 or 7.19 on Linux]]. \\ Starting with ASDM 7.18 there is no asdm.jnlp Java WebStart file anymore. To run ASDM you would have to install the ASDM Launcher, when Cisco only provides installers for macOS (dm-launcher.dmg) or Windows (dm-launcher.msi). You can download de necessary jar files from the ASA (replace with the IP of the ASA): export ipaddr= wget --no-check-certificate https://${ipaddr}/admin/public/jploader.jar wget --no-check-certificate https://${ipaddr}/admin/public/dm-launcher.jar wget --no-check-certificate https://${ipaddr}/admin/public/lzma.jar wget --no-check-certificate https://${ipaddr}/admin/public/retroweaver-rt-2.0.jar But you'd still need the cert.pem certificate file, and I haven't yet found the correct URL to download this from the ASA, so you should get it from either dm-launcher.dmg or dm-launcher.msi. In this case I'll be using 7zip to extract all needed files from dm-launcher.msi. // The following assumes everything should end up in the current directory.// * Install 7zip:pkg_add -i p7zip * Open a web browser, and download the dm-launcher.msi from https://IP-ADDRESS/admin/dm-launcher.msi, log in with your enable password when asked to login. * Change IP-ADDRESS to the IP address of your ASA. * Extract Data1.cab from the msi with 7zip:7z x dm-launcher.msi Data1.cab * Extract all .jar, and all .pem files from the MSI:7z x Data1.cab *.jar *.pem * Create an asdm.sh with content: #!/bin/sh export JAVA_HOME=/usr/local/jdk-1.8.0/ $JAVA_HOME/bin/java -Xms64m -Xmx512m -Djava.util.Arrays.useLegacyMergeSort=true -Dhttp.agent=ASDM -cp asdm_launcher.jar:jploader.jar:lzma.jar:retroweaver_rt_2.0.jar com.cisco.launcher.Launcher cert.pem * Mark asdm.sh as executable:chmod +x asdm.sh * Make sure JDK 1.8 is installed: * Install the jdk package: pkg_add -i jdk * When asked which version, choose the jdk-1.8.0 version. * Start the ASDM:./asdm.sh Proof that it works: \\ {{:cisco:firewall:cisco_asdm_7.19.1-95_on_openbsd72.png|}} =====Run another OS on ASA===== [[https://medium.com/@DomPolizzi/install-opnsense-and-linux-on-cisco-asa-59995dd6d60f|Medium - Install OPNSense and Linux on Cisco ASA]] \\ [[https://dompolizzi.github.io/project/asa-modding|Dominic Polizzi - Install OPNSense and Linux on Cisco ASA]] \\ [[https://www.reddit.com/r/OPNsenseFirewall/comments/t27hxs/install_opnsense_on_a_cisco_asa/|Reddit - Install OPNSense on a Cisco ASA]] \\ [[https://forums.servethehome.com/index.php?threads/pfsense-or-opnsense-on-a-cisco-asa-5512-x.30478/|ServeTheHome Forums - Pfsense(or Opnsense) on a Cisco ASA-5512-X]] \\ [[https://www.reddit.com/r/homelab/comments/5xlm7n/cisco_ironport_c170_findings/|Reddit - Cisco Ironport C170 findings...]] \\ [[https://forum.openwrt.org/t/openwrt-on-old-cisco-asa-5525-x-appliance/127704|OpenWrt Forum - OpenWrt on old Cisco ASA 5525-x appliance]] \\ [[https://www.reddit.com/r/OPNsenseFirewall/comments/q1woy7/opnsense_running_on_a_cisco_asa5512x/|Reddit - OPNSense running on a Cisco ASA5512-X]] \\