E-61
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
OL-24002-01
Appendix E Troubleshooting
Troubleshooting the ASA 5500 AIP SSM
Slot-1 146> ADDRESS=10.89.150.227
Slot-1 147> SERVER=10.89.146.1
Slot-1 148> GATEWAY=10.89.149.254
Slot-1 149> PORT=GigabitEthernet0/0
Slot-1 150> VLAN=untagged
Slot-1 151> IMAGE=IPS-SSM-K9-sys-1.1-a-5.1-0.1.img
Slot-1 152> CONFIG=
Slot-1 153> LINKTIMEOUT=20
Slot-1 154> PKTTIMEOUT=4
Slot-1 155> RETRY=20
Slot-1 156> tftp [email protected] via 10.89.149.254
Slot-1 157> TFTP failure: Packet verify failed after 20 retries
Slot-1 158> Rebooting due to Autoboot error ...
Slot-1 159> Rebooting....
Slot-1 160> Cisco Systems ROMMON Version (1.0(10)0) #0: Fri Mar 25 23:02:10 PST 2005
Slot-1 161> Platform ASA-SSM-10
Slot-1 162> GigabitEthernet0/0
Slot-1 163> Link is UP
Slot-1 164> MAC Address: 000b.fcf8.0176
Slot-1 165> ROMMON Variable Settings:
Slot-1 166> ADDRESS=10.89.150.227
Slot-1 167> SERVER=10.89.146.1
Slot-1 168> GATEWAY=10.89.149.254
Slot-1 169> PORT=GigabitEthernet0/0
Slot-1 170> VLAN=untagged
Slot-1 171> IMAGE=IPS-SSM-K9-sys-1.1-a-5.1-0.1.img
Slot-1 172> CONFIG=
Slot-1 173> LINKTIMEOUT=20
Slot-1 174> PKTTIMEOUT=4
Slot-1 175> RETRY=20
Slot-1 176> tftp [email protected] via 10.89.149.254
Failover Scenarios
The following failover scenarios apply to the ASA in the event of configuration changes,
signature/signature engine updates, service packs, and SensorApp crashes on the ASA 5500 AIP SSM.
Single ASA in Fail-Open Mode
•
If the ASA is configured in fail-open mode for the ASA 5500 AIP SSM, and the
ASA 5500 AIP SSM experiences a configuration change or signature/signature engine update,
traffic is passed through the ASA without being inspected.
•
If the ASA is configured in fail-open mode for the ASA 5500 AIP SSM, and the
ASA 5500 AIP SSM experiences a SensorApp crash or a service pack upgrade, traffic is passed
through the ASA without being inspected.
Single ASA in Fail-Close Mode
•
If the ASA is configured in fail-close mode for the ASA 5500 AIP SSM, and the
ASA 5500 AIP SSM experiences a configuration change or a signature/signature engine update,
traffic is stopped from passing through the ASA.
•
If the ASA is configured in fail-close mode for the ASA 5500 AIP SSM, and the
ASA 5500 AIP SSM experiences a SensorApp crash or a service pack upgrade, traffic is stopped
from passing through the ASA.