Friday, September 1, 2017

Cisco ASA FirePower Module Upgrade

Here's a good Cisco ASA FirePower module upgrade guide. The ASA image must be at least on the 9.2.2 code and there's an ASA image to FirePower version compatibility matrix that should be followed. Below is an SSD expansion module inserted on a Cisco 5525-X firewall. You can verify the status on the SSD drive on the ASA using the show inventory and show module commands.



ciscoasa# show version

Cisco Adaptive Security Appliance Software Version 9.4(3)12
Device Manager Version 7.6(1)

Compiled on Thu 20-Oct-16 17:58 PDT by builders
System image file is "disk0:/asa943-12-smp-k8.bin"
Config file at boot was "startup-config"

ciscoasa up 2 days 18 hours

Hardware:   ASA5525, 8192 MB RAM, CPU Lynnfield 2394 MHz, 1 CPU (4 cores)
            ASA: 4096 MB RAM, 1 CPU (1 core)
Internal ATA Compact Flash, 8192MB
BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
                             Boot microcode        : CNPx-MC-BOOT-2.00
                             SSL/IKE microcode     : CNPx-MC-SSL-SB-PLUS-0005
                             IPSec microcode       : CNPx-MC-IPSEC-MAIN-0026
                             Number of accelerators: 1
Baseboard Management Controller (revision 0x1) Firmware Version: 2.4


 0: Int: Internal-Data0/0    : address is fc5b.39aa.5164, irq 11
 1: Ext: GigabitEthernet0/0  : address is fc5b.39aa.5169, irq 5  
 2: Ext: GigabitEthernet0/1  : address is fc5b.39aa.5165, irq 5
 3: Ext: GigabitEthernet0/2  : address is fc5b.39aa.516a, irq 10
 4: Ext: GigabitEthernet0/3  : address is fc5b.39aa.5166, irq 10
 5: Ext: GigabitEthernet0/4  : address is fc5b.39aa.516b, irq 5
 6: Ext: GigabitEthernet0/5  : address is fc5b.39aa.5167, irq 5
 7: Ext: GigabitEthernet0/6  : address is fc5b.39aa.516c, irq 10
 8: Ext: GigabitEthernet0/7  : address is fc5b.39aa.5168, irq 10
 9: Int: Internal-Data0/1    : address is 0000.0001.0002, irq 0
10: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0
11: Int: Internal-Data0/2    : address is 0000.0001.0003, irq 0
12: Ext: Management0/0       : address is fc5b.39aa.5164, irq 0

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 200            perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Active/Active  perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Enabled        perpetual
Security Contexts                 : 2              perpetual
GTP/GPRS                          : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : Disabled       perpetual
Other VPN Peers                   : 750            perpetual         
Total VPN Peers                   : 750            perpetual
Shared License                    : Disabled       perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
Total UC Proxy Sessions           : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
IPS Module                        : Disabled       perpetual
Cluster                           : Enabled        perpetual
Cluster Members                   : 2              perpetual

This platform has an ASA5525 VPN Premium license.

Serial Number: FCH1834JABC
Running Permanent Activation Key: 0x363bee4d 0xcc858b80 0xe5d21db4 0xf1d49123 0xcb04c456
Configuration register is 0x1

Image type          : Release
Key version         : A

Configuration has not been modified since last system restart.


ciscoasa# show inventory
Name: "Chassis", DESCR: "ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC"
PID: ASA5525           , VID: V03     , SN: FTX18401234

Name: "Storage Device 1", DESCR: "Model Number: Micron_M550_MTFDDAK128MAY"
PID: N/A               , VID: N/A     , SN: MXA1835ABCD


ciscoasa# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525            FCH1834JABC
 ips Unknown                                      N/A                FCH1834JABC
cxsc Unknown                                      N/A                FCH1834JABC
 sfr Unknown                                      N/A                FCH1834JABC

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 fc5b.39aa.5164 to fc5b.39aa.5123  1.0          2.1(9)8      9.4(3)12
 ips fc5b.39aa.5162 to fc5b.39aa.5123  N/A          N/A         
cxsc fc5b.39aa.5162 to fc5b.39aa.5123  N/A          N/A         
 sfr fc5b.39aa.5162 to fc5b.39aa.5123  N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
 sfr Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 ips Unresponsive       Not Applicable       
cxsc Unresponsive       Not Applicable       
 sfr Unresponsive       Not Applicable       

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual


TFTP the FirePower image to the ASA flash.

ciscoasa# configure terminal
ciscoasa(config)# interface g0/1
ciscoasa(config-if)# ip add ress 192.168.1.1 255.255.255.0
ciscoasa(config-if)# no shut
ciscoasa(config-if)# show run interface f g0/1
!
interface GigabitEthernet0/1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0

ciscoasa(config-if)# ping 192.168.1.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
ciscoasa(config-if)#
ciscoasa(config-if)# end

ciscoasa# copy tftp://192.168.1.2/asasfr-5500x-boot-6.0.0-1005.img disk0:/ ?

  disk0:          Copy to disk0: file system
  disk1:          Copy to disk1: file system
  flash:          Copy to flash: file system
  running-config  Update (merge with) current system configuration
  startup-config  Copy to startup configuration
  system:         Copy to system: file system

ciscoasa# copy tftp://192.168.1.2/asasfr-5500x-boot-6.0.0-1005.img disk 0:

Address or name of remote host [192.168.1.2]?

Source filename [asasfr-5500x-boot-6.0.0-1005.img]?

Destination filename [asasfr-5500x-boot-6.0.0-1005.img]?

Accessing tftp://192.168.1.2/asasfr-5500x-boot-6.0.0-1005.img...!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

<OUTPUT TRUNCATED>

!!!!!!!!!!!!!!!!!!!!!!!!!
41848832 bytes copied in 31.880 secs (1349962 bytes/sec)

ciscoasa# dir

Directory of disk0:/

11     drwx  4096         19:16:16 Sep 29 2014  log
22     drwx  4096         19:16:44 Sep 29 2014  crypto_archive
23     drwx  4096         19:16:52 Sep 29 2014  coredumpinfo
120    -rwx  37656576     19:25:02 Sep 29 2014  asa913-smp-k8.bin
121    -rwx  22658960     19:27:04 Sep 29 2014  asdm-714.bin
122    -rwx  73285632     00:38:08 Jun 06 2017  asa943-12-smp-k8.bin
123    -rwx  69828608     19:28:22 Sep 29 2014  asacx-5500x-boot-9.2.1.1-48.img
124    -rwx  25819140     00:42:58 Jun 06 2017  asdm-761.bin
125    -rwx  12998641     19:51:42 Sep 29 2014  csd_3.5.2008-k9.pkg
126    drwx  4096         19:51:44 Sep 29 2014  sdesktop
127    -rwx  6487517      19:51:44 Sep 29 2014  anyconnect-macosx-i386-2.5.2014-k9.pkg
128    -rwx  6689498      19:51:44 Sep 29 2014  anyconnect-linux-2.5.2014-k9.pkg
129    -rwx  4678691      19:51:44 Sep 29 2014  anyconnect-win-2.5.2014-k9.pkg
130    -rwx  100          22:45:26 Jun 05 2017  upgrade_startup_errors_201706052245.log
137    -rwx  41848832     18:55:08 Jun 08 2017  asasfr-5500x-boot-6.0.0-1005.img

8238202880 bytes total (4712689664 bytes free)

ciscoasa# delete disk0:/asacx-5500x-boot-9.2.1.1-48.img      // REMOVE CX IMAGE IN FLASH

Delete filename [asacx-5500x-boot-9.2.1.1-48.img]?

Delete disk0:/asacx-5500x-boot-9.2.1.1-48.img? [confirm]

ciscoasa# dir

Directory of disk0:/

11     drwx  4096         19:16:16 Sep 29 2014  log
22     drwx  4096         19:16:44 Sep 29 2014  crypto_archive
23     drwx  4096         19:16:52 Sep 29 2014  coredumpinfo
120    -rwx  37656576     19:25:02 Sep 29 2014  asa913-smp-k8.bin
121    -rwx  22658960     19:27:04 Sep 29 2014  asdm-714.bin
122    -rwx  73285632     00:38:08 Jun 06 2017  asa943-12-smp-k8.bin
124    -rwx  25819140     00:42:58 Jun 06 2017  asdm-761.bin
125    -rwx  12998641     19:51:42 Sep 29 2014  csd_3.5.2008-k9.pkg
126    drwx  4096         19:51:44 Sep 29 2014  sdesktop
127    -rwx  6487517      19:51:44 Sep 29 2014  anyconnect-macosx-i386-2.5.2014-k9.pkg
128    -rwx  6689498      19:51:44 Sep 29 2014  anyconnect-linux-2.5.2014-k9.pkg
129    -rwx  4678691      19:51:44 Sep 29 2014  anyconnect-win-2.5.2014-k9.pkg
130    -rwx  100          22:45:26 Jun 05 2017  upgrade_startup_errors_201706052245.log
137    -rwx  41848832     18:55:08 Jun 08 2017  asasfr-5500x-boot-6.0.0-1005.img

8238202880 bytes total (4712689664 bytes free)

ciscoasa# sw-module ?

  module  Act on a module

ciscoasa# sw-module module ?

Available module ID(s):
  cxsc  Module ID
  ips   Module ID
  sfr   Module ID

ciscoasa# sw-module module sfr ?

  recover    Configure recovery of this module
  reload     Reload the module
  reset      Reset the module
  shutdown   Shut down the module
  uninstall  Uninstall the module

ciscoasa# sw-module module sfr recover ?

  boot       Initiate recovery of this module
  configure  Configure recovery parameters for this module
  stop       Stop recovery of this module

ciscoasa# sw-module module sfr recover configure ?

  image  Configure image file path on disk

ciscoasa# sw-module module sfr recover configure image ?

  disk0:  Image File Path
  disk1:  Image File Path
  flash:  Image File Path

ciscoasa# sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.0.0-1005.img
ERROR: Another service (cxsc) is running, only one service is allowed to run at any time     // CX MODULE WAS USED PREVIOUSLY

ciscoasa# sw-module module cxsc ?

  password-reset  Reset the CLI password on the module
  recover         Configure recovery of this module
  reload          Reload the module
  reset           Reset the module
  shutdown        Shut down the module
  uninstall       Uninstall the module

ciscoasa# sw-module module cxsc shutdown

Shutdown module cxsc? [confirm]
Shutdown issued for module cxsc.

ciscoasa# sw-module module cxsc uninstall

Module cxsc will be uninstalled. This will completely remove the disk image assocated with the sw-module including any configuration that existed within it.

Uninstall module cxsc? [confirm]
Uninstall issued for module cxsc.

ciscoasa#

ciscoasa# reload
System config has been modified. Save? [Y]es/[N]o:  y
Cryptochecksum: c2929293 66ae9c7b 3523edd9 e85ff237

2866 bytes copied in 0.680 secs
Proceed with reload? [confirm]

ciscoasa#     // ASA DIDN'T REBOOT

ciscoasa# reload ?

  at             Reload at a specific time/date
  cancel         Cancel a scheduled reload
  in             Reload after a time interval
  max-hold-time  Maximum hold time for orderly reload
  noconfirm      Reload without asking for confirmation
  quick          Quick reload without properly shutting down each subsystem
  reason         Reason for reload
  save-config    Save configuration before reload
  <cr>

ciscoasa# reload noconfirm ?

  at             Reload at a specific time/date
  in             Reload after a time interval
  max-hold-time  Maximum hold time for orderly reload
  quick          Quick reload without properly shutting down each subsystem
  reason         Reason for reload
  save-config    Save configuration before reload
  <cr>

ciscoasa# reload noconfirm quick ?

  at             Reload at a specific time/date
  in             Reload after a time interval
  max-hold-time  Maximum hold time for orderly reload
  reason         Reason for reload
  save-config    Save configuration before reload
  <cr>

ciscoasa# reload noconfirm quick

***
*** --- SHUTDOWN NOW ---
Process shutdown finished
Rebooting.....


<OUTPUT TRUNCATED>


ciscoasa# sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.0.0-1005.img

ciscoasa# debug module-boot ?

  <1-255>  Specify an optional debug level (default is 1)
  <cr>

ciscoasa# debug module-boot      // ISSUE THIS DEBUG TO MONITOR SFR UPGRADE
debug module-boot  enabled at level 1

ciscoasa# sw-module module sfr recover boot

Module sfr will be recovered. This may erase all configuration and all data
on that device and attempt to download/install a new image for it. This may take
several minutes.


Recover module sfr? [confirm]     // HIT ENTER
Recover issued for module sfr.

ciscoasa# Mod-sfr 0> ***
Mod-sfr 1> *** EVENT: Creating the Disk Image...
Mod-sfr 2> *** TIME: 19:14:00 UTC Jun 8 2017
Mod-sfr 3> ***
Mod-sfr 4> ***
Mod-sfr 5> *** EVENT: The module is being recovered.
Mod-sfr 6> *** TIME: 19:14:00 UTC Jun 8 2017
Mod-sfr 7> ***
Mod-sfr 8> ***
Mod-sfr 9> *** EVENT: Disk Image created successfully.
Mod-sfr 10> *** TIME: 19:16:45 UTC Jun 8 2017
Mod-sfr 11> ***
Mod-sfr 12> ***
Mod-sfr 13> *** EVENT: Start Parameters: Image: /mnt/disk0/vm/vm_3.img, ISO: -cdrom /mnt/disk0/
Mod-sfr 14> asasfr-5500x-boot-6.0.0-1005.img, Num CPUs: 3, RAM: 3614MB, Mgmt MAC: FC:5B:39:AA:5
Mod-sfr 15> 1:62, CP MAC: 00:00:00:04:00:01, HDD: -drive file=/dev/md0,cache=none,if=virtio, De
Mod-sfr 16> ***
Mod-sfr 17> *** EVENT: Start Parameters Continued: RegEx Shared Mem: 32MB, Cmd Op: r, Shared Me
Mod-sfr 18> m Key: 8061, Shared Mem Size: 64, Log Pipe: /dev/ttyS0_vm3, Sock: /dev/ttyS1_vm3, M
Mod-sfr 19> em-Path: -mem-path /hugepages
Mod-sfr 20> *** TIME: 19:16:46 UTC Jun 8 2017
Mod-sfr 21> ***
Mod-sfr 22> Status: Mapping host 0x2aab8d200000 to VM with size 67108864
Mod-sfr 23> Warning: vlan 0 is not connected to host network
Mod-sfr 24> ISOLINUX 3.73 2009-01-25  Copyright (C) 1994-2008 H. Peter Anvin
Mod-sfr 25>                    Cisco SFR-BOOT-IMAGE and CX-BOOT-IMAGE for SFR - 6.0.0
Mod-sfr 26>     (WARNING: ALL DATA ON DISK 1 WILL BE LOST)
Mod-sfr 27> Loading bzImage..........................................................
Mod-sfr 28> Loading initramfs.gz...............................................................
Mod-sfr 29> ...................................................................................
Mod-sfr 30> ...................................................................................
Mod-sfr 31> ...................................................................................
Mod-sfr 32> ...................................................................................
Mod-sfr 33> ...................................................................................
Mod-sfr 34> ...................................................................................
Mod-sfr 35> ...................ready.
Mod-sfr 36> [    0.000000] BIOS EBDA/lowmem at: 0009fc00/0009fc00
Mod-sfr 37> [    0.000000] Initializing cgroup subsys cpuset
Mod-sfr 38> [    0.000000] Initializing cgroup subsys cpu
Mod-sfr 39> [    0.000000] Linux version 2.6.28.10.x86-target-64 (build@cel64build6.esn.sourcef
Mod-sfr 40> ire.com) (gcc version 4.3.3 (MontaVista Linux Sourcery G++ 4.3-292) ) #1 SMP PREEMP
Mod-sfr 41> T Sun Nov 8 16:49:06 EST 2015
Mod-sfr 42> [    0.000000] Command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IMAGE=bzIm
Mod-sfr 43> age
Mod-sfr 44> [    0.000000] KERNEL supported cpus:
Mod-sfr 45> [    0.000000]   Intel GenuineIntel
Mod-sfr 46> [    0.000000]   AMD AuthenticAMD
Mod-sfr 47> [    0.000000]   Centaur CentaurHauls
Mod-sfr 48> [    0.000000] PAT WC disabled due to known CPU erratum.
Mod-sfr 49> [    0.000000] BIOS-provided physical RAM map:
Mod-sfr 50> [    0.000000]  BIOS-e820: 0000000000000000 - 000000000009fc00 (usable)
Mod-sfr 51> [    0.000000]  BIOS-e820: 000000000009fc00 - 00000000000a0000 (reserved)
Mod-sfr 52> [    0.000000]  BIOS-e820: 00000000000f0000 - 0000000000100000 (reserved)
Mod-sfr 53> [    0.000000]  BIOS-e820: 0000000000100000 - 00000000dfffe000 (usable)
Mod-sfr 54> [    0.000000]  BIOS-e820: 00000000dfffe000 - 00000000e0000000 (reserved)
Mod-sfr 55> [    0.000000]  BIOS-e820: 00000000feffc000 - 00000000ff000000 (reserved)
Mod-sfr 56> [    0.000000]  BIOS-e820: 00000000fffc0000 - 0000000100000000 (reserved)
Mod-sfr 57> [    0.000000]  BIOS-e820: 0000000100000000 - 0000000101e00000 (usable)
Mod-sfr 58> [    0.000000] DMI 2.4 present.
Mod-sfr 59> [    0.000000] last_pfn = 0x101e00 max_arch_pfn = 0x3ffffffff
Mod-sfr 60> [    0.000000] last_pfn = 0xdfffe max_arch_pfn = 0x3ffffffff
Mod-sfr 61> [    0.000000] init_memory_mapping: 0000000000000000-00000000dfffe000
Mod-sfr 62> [    0.000000] last_map_addr: dfffe000 end: dfffe000
Mod-sfr 63> [    0.000000] init_memory_mapping: 0000000100000000-0000000101e00000
Mod-sfr 64> [    0.000000] last_map_addr: 101e00000 end: 101e00000
Mod-sfr 65> [    0.000000] RAMDISK: 7dbe1000 - 7ffff5d8
Mod-sfr 66> [    0.000000] ACPI: RSDP 000FD8D0, 0014 (r0 BOCHS )
Mod-sfr 67> [    0.000000] ACPI: RSDT DFFFE3E0, 0034 (r1 BOCHS  BXPCRSDT        1 BXPC        1
Mod-sfr 68> [    0.000000] ACPI: FACP DFFFFF80, 0074 (r1 BOCHS  BXPCFACP        1 BXPC        1
Mod-sfr 69> [    0.000000] ACPI: DSDT DFFFE420, 11A9 (r1   BXPC   BXDSDT        1 INTL 20100528
Mod-sfr 70> [    0.000000] ACPI: FACS DFFFFF40, 0040
Mod-sfr 71> [    0.000000] ACPI: SSDT DFFFF740, 07F7 (r1 BOCHS  BXPCSSDT        1 BXPC        1
Mod-sfr 72> [    0.000000] ACPI: APIC DFFFF610, 0088 (r1 BOCHS  BXPCAPIC        1 BXPC        1
Mod-sfr 73> [    0.000000] ACPI: HPET DFFFF5D0, 0038 (r1 BOCHS  BXPCHPET        1 BXPC        1
Mod-sfr 74> [    0.000000] No NUMA configuration found
Mod-sfr 75> [    0.000000] Faking a node at 0000000000000000-0000000101e00000
Mod-sfr 76> [    0.000000] Bootmem setup node 0 0000000000000000-0000000101e00000
Mod-sfr 77> [    0.000000]   NODE_DATA [0000000000001000 - 0000000000005fff]
Mod-sfr 78> [    0.000000]   bootmap [000000000000d000 -  000000000002d3bf] pages 21
Mod-sfr 79> [    0.000000] (7 early reservations) ==> bootmem [0000000000 - 0101e00000]
Mod-sfr 80> [    0.000000]   #0 [0000000000 - 0000001000]   BIOS data page ==> [0000000000 - 00
Mod-sfr 81> 00001000]
Mod-sfr 82> [    0.000000]   #1 [0000006000 - 0000008000]       TRAMPOLINE ==> [0000006000 - 00
Mod-sfr 83> 00008000]
Mod-sfr 84> [    0.000000]   #2 [0000200000 - 0000ae86dc]    TEXT DATA BSS ==> [0000200000 - 00
Mod-sfr 85> 00ae86dc]
Mod-sfr 86> [    0.000000]   #3 [007dbe1000 - 007ffff5d8]          RAMDISK ==> [007dbe1000 - 00
Mod-sfr 87> 7ffff5d8]
Mod-sfr 88> [    0.000000]   #4 [000009fc00 - 0000100000]    BIOS reserved ==> [000009fc00 - 00
Mod-sfr 89> 00100000]
Mod-sfr 90> [    0.000000]   #5 [0000008000 - 000000c000]          PGTABLE ==> [0000008000 - 00
Mod-sfr 91> 0000c000]
Mod-sfr 92> [    0.000000]   #6 [000000c000 - 000000d000]          PGTABLE ==> [000000c000 - 00
Mod-sfr 93> 0000d000]
Mod-sfr 94> [    0.000000] found SMP MP-table at [ffff8800000fdab0] 000fdab0
Mod-sfr 95> [    0.000000] Zone PFN ranges:
Mod-sfr 96> [    0.000000]   DMA      0x00000000 -> 0x00001000
Mod-sfr 97> [    0.000000]   DMA32    0x00001000 -> 0x00100000
Mod-sfr 98> [    0.000000]   Normal   0x00100000 -> 0x00101e00
Mod-sfr 99> [    0.000000] Movable zone start PFN for each node
Mod-sfr 100> [    0.000000] early_node_map[3] active PFN ranges
Mod-sfr 101> [    0.000000]     0: 0x00000000 -> 0x0000009f
Mod-sfr 102> [    0.000000]     0: 0x00000100 -> 0x000dfffe
Mod-sfr 103> [    0.000000]     0: 0x00100000 -> 0x00101e00
Mod-sfr 104> [    0.000000] ACPI: PM-Timer IO Port: 0xb008
Mod-sfr 105> [    0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
Mod-sfr 106> [    0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)
Mod-sfr 107> [    0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)
Mod-sfr 108> [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
Mod-sfr 109> [    0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
Mod-sfr 110> [    0.000000] IOAPIC[0]: apic_id 0, version 0, address 0xfec00000, GSI 0-23
Mod-sfr 111> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
Mod-sfr 112> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
Mod-sfr 113> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Mod-sfr 114> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
Mod-sfr 115> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
Mod-sfr 116> [    0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000
Mod-sfr 117> [    0.000000] Using ACPI (MADT) for SMP configuration information
Mod-sfr 118> [    0.000000] SMP: Allowing 3 CPUs, 0 hotplug CPUs
Mod-sfr 119> [    0.000000] Allocating PCI resources starting at e2000000 (gap: e0000000:1effc0
Mod-sfr 120> 00)
Mod-sfr 121> [    0.000000] PERCPU: Allocating 53248 bytes of per cpu data
Mod-sfr 122> [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages
Mod-sfr 123> : 908258
Mod-sfr 124> [    0.000000] Policy zone: Normal
Mod-sfr 125> [    0.000000] Kernel command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IM
Mod-sfr 126> AGE=bzImage
Mod-sfr 127> [    0.000000] Initializing CPU#0
Mod-sfr 128> [    0.000000] PID hash table entries: 4096 (order: 12, 32768 bytes)
Mod-sfr 129> [    0.000000] Fast TSC calibration using PIT
Mod-sfr 130> [    0.000000] Detected 2394.091 MHz processor.
Mod-sfr 131> [    0.000999] Console: colour VGA+ 80x25
Mod-sfr 132> [    0.000999] console [ttyS0] enabled
Mod-sfr 133> [    0.000999] allocated 38010880 bytes of page_cgroup
Mod-sfr 134> [    0.000999] please try cgroup_disable=memory option if you don't want
Mod-sfr 135> [    0.000999] Checking aperture...
Mod-sfr 136> [    0.000999] No AGP bridge found
Mod-sfr 137> [    0.000999] PCI-DMA: Using software bounce buffering for IO (SWIOTLB)
Mod-sfr 138> [    0.000999] Placing software IO TLB between 0x20000000 - 0x24000000
Mod-sfr 139> [    0.000999] Memory: 3497472k/4225024k available (4733k kernel code, 524684k abs
Mod-sfr 140> ent, 202868k reserved, 2572k data, 544k init)
Mod-sfr 141> [    0.000999] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
Mod-sfr 142> [    0.001007] Calibrating delay loop (skipped), value calculated using timer freq
Mod-sfr 143> uency.. 4788.18 BogoMIPS (lpj=2394091)
Mod-sfr 144> [    0.002322] Security Framework initialized
Mod-sfr 145> [    0.003559] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
Mod-sfr 146> [    0.006005] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
Mod-sfr 147> [    0.007103] Mount-cache hash table entries: 256
Mod-sfr 148> [    0.007911] Initializing cgroup subsys ns
Mod-sfr 149> [    0.008003] Initializing cgroup subsys cpuacct
Mod-sfr 150> [    0.008455] Initializing cgroup subsys memory
Mod-sfr 151> [    0.009038] CPU: L1 I cache: 32K, L1 D cache: 32K
Mod-sfr 152> [    0.009555] CPU: L2 cache: 4096K
Mod-sfr 153> [    0.010006] CPU 0/0x0 -> Node 0
Mod-sfr 154> [    0.010356] ACPI: Core revision 20080926
Mod-sfr 155> [    0.011857] Setting APIC routing to flat
Mod-sfr 156> [    0.013363] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
Mod-sfr 157> [    0.024274] CPU0: Intel QEMU Virtual CPU version 1.5.0 stepping 03
Mod-sfr 158> [    0.025996] Booting processor 1 APIC 0x1 ip 0x6000
Mod-sfr 159> [    0.000999] Initializing CPU#1
Mod-sfr 160> [    0.000999] Calibrating delay using timer specific routine.. 4787.92 BogoMIPS (
Mod-sfr 161> lpj=2393964)
Mod-sfr 162> [    0.000999] CPU: L1 I cache: 32K, L1 D cache: 32K
Mod-sfr 163> [    0.000999] CPU: L2 cache: 4096K
Mod-sfr 164> [    0.000999] CPU 1/0x1 -> Node 0
Mod-sfr 165> [    0.096063] CPU1: Intel QEMU Virtual CPU version 1.5.0 stepping 03
Mod-sfr 166> [    0.099191] checking TSC synchronization [CPU#0 -> CPU#1]: passed.
Mod-sfr 167> [    0.100053] Booting processor 2 APIC 0x2 ip 0x6000
Mod-sfr 168> [    0.000999] Initializing CPU#2
Mod-sfr 169> [    0.000999] Calibrating delay using timer specific routine.. 4787.88 BogoMIPS (
Mod-sfr 170> lpj=2393944)
Mod-sfr 171> [    0.000999] CPU: L1 I cache: 32K, L1 D cache: 32K
Mod-sfr 172> [    0.000999] CPU: L2 cache: 4096K
Mod-sfr 173> [    0.000999] CPU 2/0x2 -> Node 0
Mod-sfr 174> [    0.172134] CPU2: Intel QEMU Virtual CPU version 1.5.0 stepping 03
Mod-sfr 175> [    0.175141] checking TSC synchronization [CPU#0 -> CPU#2]: passed.
Mod-sfr 176> [    0.175987] Brought up 3 CPUs
Mod-sfr 177> [    0.176333] Total of 3 processors activated (14363.99 BogoMIPS).
Mod-sfr 178> [    0.177189] net_namespace: 1280 bytes
Mod-sfr 179> [    0.178086] NET: Registered protocol family 16
Mod-sfr 180> [    0.179001] ACPI: bus type pci registered
Mod-sfr 181> [    0.180024] PCI: Using configuration type 1 for base access
Mod-sfr 182> [    0.196360] ACPI: Interpreter enabled
Mod-sfr 183> [    0.196778] ACPI: (supports S0 S5)
Mod-sfr 184> [    0.197069] ACPI: Using IOAPIC for interrupt routing
Mod-sfr 185> [    0.201261] ACPI: No dock devices found.
Mod-sfr 186> [    0.201982] ACPI: PCI Root Bridge [PCI0] (0000:00)
Mod-sfr 187> [    0.204305] pci 0000:00:01.3: quirk: region b000-b03f claimed by PIIX4 ACPI
Mod-sfr 188> [    0.204978] pci 0000:00:01.3: quirk: region b100-b10f claimed by PIIX4 SMB
Mod-sfr 189> [    0.227222] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
Mod-sfr 190> [    0.228260] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
Mod-sfr 191> [    0.229126] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
Mod-sfr 192> [    0.229920] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
Mod-sfr 193> [    0.230220] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
Mod-sfr 194> [    0.232102] SCSI subsystem initialized
Mod-sfr 195> [    0.233002] usbcore: registered new interface driver usbfs
Mod-sfr 196> [    0.233992] usbcore: registered new interface driver hub
Mod-sfr 197> [    0.234565] usbcore: registered new device driver usb
Mod-sfr 198> [    0.234988] PCI: Using ACPI for IRQ routing
Mod-sfr 199> [    0.243993] cfg80211: Using static regulatory domain info
Mod-sfr 200> [    0.244568] cfg80211: Regulatory domain: US
Mod-sfr 201> [    0.244964]     (start_freq - end_freq @ bandwidth), (max_antenna_gain, max_eirp)
Mod-sfr 202> [    0.245759]     (2402000 KHz - 2472000 KHz @ 40000 KHz), (600 mBi, 2700 mBm)
Mod-sfr 203> [    0.245964]     (5170000 KHz - 5190000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)
Mod-sfr 204> [    0.246964]     (5190000 KHz - 5210000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)
Mod-sfr 205> [    0.247963]     (5210000 KHz - 5230000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)
Mod-sfr 206> [    0.248963]     (5230000 KHz - 5330000 KHz @ 40000 KHz), (600 mBi, 2300 mBm)
Mod-sfr 207> [    0.249712]     (5735000 KHz - 5835000 KHz @ 40000 KHz), (600 mBi, 3000 mBm)
Mod-sfr 208> [    0.249963] cfg80211: Calling CRDA for country: US
Mod-sfr 209> [    0.250980] NetLabel: Initializing
Mod-sfr 210> [    0.251349] NetLabel:  domain hash size = 128
Mod-sfr 211> [    0.251963] NetLabel:  protocols = UNLABELED CIPSOv4
Mod-sfr 212> [    0.252522] NetLabel:  unlabeled traffic allowed by default
Mod-sfr 213> [    0.253282] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
Mod-sfr 214> [    0.254087] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
Mod-sfr 215> [    0.259966] pnp: PnP ACPI init
Mod-sfr 216> [    0.260327] ACPI: bus type pnp registered
Mod-sfr 217> [    0.262259] pnp: PnP ACPI: found 9 devices
Mod-sfr 218> [    0.262722] ACPI: ACPI bus type pnp unregistered
Mod-sfr 219> [    0.269188] bus: 00 index 0 io port: [0x00-0xffff]
Mod-sfr 220> [    0.269728] bus: 00 index 1 mmio: [0x000000-0xffffffffffffffff]
Mod-sfr 221> [    0.270473] NET: Registered protocol family 2
Mod-sfr 222> [    0.281104] IP route cache hash table entries: 131072 (order: 8, 1048576 bytes)
Mod-sfr 223> [    0.283331] TCP established hash table entries: 524288 (order: 11, 8388608 byte
Mod-sfr 224> s)
Mod-sfr 225> [    0.287512] TCP bind hash table entries: 65536 (order: 8, 1048576 bytes)
Mod-sfr 226> [    0.288597] TCP: Hash tables configured (established 524288 bind 65536)
Mod-sfr 227> [    0.289346] TCP reno registered
Mod-sfr 228> [    0.293058] NET: Registered protocol family 1
Mod-sfr 229> [    0.293631] checking if image is initramfs...<7>Switched to high resolution mod
Mod-sfr 230> e on CPU 2
Mod-sfr 231> [    1.431669]  it is
Mod-sfr 232> [    2.690158] Freeing initrd memory: 36985k freed
Mod-sfr 233> [    2.699392] Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter
Mod-sfr 234>  Oruba
Mod-sfr 235> [    2.705522] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mod-sfr 236> [    2.706641] VFS: Disk quotas dquot_6.5.1
Mod-sfr 237> [    2.707121] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mod-sfr 238> [    2.708565] msgmni has been set to 6903
Mod-sfr 239> [    2.709759] alg: No test for stdrng (krng)
Mod-sfr 240> [    2.710356] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 252
Mod-sfr 241> [    2.711186] io scheduler noop registered
Mod-sfr 242> [    2.711647] io scheduler anticipatory registered
Mod-sfr 243> [    2.712165] io scheduler deadline registered
Mod-sfr 244> [    2.712699] io scheduler cfq registered (default)
Mod-sfr 245> [    2.713237] LTT : ltt-relay init
Mod-sfr 246> [    2.713623] ltt-control init
Mod-sfr 247> [    2.744365] LTT : ltt-kprobes init
Mod-sfr 248> [    2.744770] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
Mod-sfr 249> [    2.745452] pci 0000:00:01.0: PIIX3: Enabling Passive Release
Mod-sfr 250> [    2.746105] pci 0000:00:01.0: Activating ISA DMA hang workarounds
Mod-sfr 251> [    2.747955] pci_hotplug: PCI Hot Plug PCI Core version: 0.5
Mod-sfr 252> [    2.749332] processor ACPI_CPU:00: registered as cooling_device0
Mod-sfr 253> [    2.750207] processor ACPI_CPU:01: registered as cooling_device1
Mod-sfr 254> [    2.751089] processor ACPI_CPU:02: registered as cooling_device2
Mod-sfr 255> [    2.758534] Non-volatile memory driver v1.2
Mod-sfr 256> [    2.759013] Linux agpgart interface v0.103
Mod-sfr 257> [    2.759666] [drm] Initialized drm 1.1.0 20060810
Mod-sfr 258> [    2.760227] Serial: 8250/16550 driver4 ports, IRQ sharing enabled
Mod-sfr 259> ÿ[    3.005451] serial8250: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
Mod-sfr 260> [    3.250469] serial8250: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
Mod-sfr 261> [    3.251915] 00:06: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
Mod-sfr 262> [    3.252926] 00:07: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
Mod-sfr 263> [    3.253885] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M
Mod-sfr 264> [    3.265962] FDC 0 is a S82078B
Mod-sfr 265> [    3.269857] brd: module loaded
Mod-sfr 266> [    3.271570] loop: module loaded
Mod-sfr 267> [    3.272017] Intel(R) Gigabit Ethernet Network Driver - version 1.2.45-k2
Mod-sfr 268> [    3.272792] Copyright (c) 2008 Intel Corporation.
Mod-sfr 269> [    3.273412] pcnet32.c:v1.35 21.Apr.2008 tsbogend@alpha.franken.de
Mod-sfr 270> [    3.274169] e100: Intel(R) PRO/100 Network Driver, 3.5.23-k6-NAPI
Mod-sfr 271> [    3.274869] e100: Copyright(c) 1999-2006 Intel Corporation
Mod-sfr 272> [    3.275646] sky2 driver version 1.22
Mod-sfr 273> [    3.276449] console [netcon0] enabled
Mod-sfr 274> [    3.276867] netconsole: network logging started
Mod-sfr 275> [    3.277570] input: Macintosh mouse button emulation as /devices/virtual/input/i
Mod-sfr 276> nput0
Mod-sfr 277> [    3.278888] Loading iSCSI transport class v2.0-870.
Mod-sfr 278> [    3.280358] Driver 'sd' needs updating - please use bus_type methods
Mod-sfr 279> [    3.281150] Driver 'sr' needs updating - please use bus_type methods
Mod-sfr 280> [    3.283124] scsi0 : ata_piix
Mod-sfr 281> [    3.283758] scsi1 : ata_piix
Mod-sfr 282> [    3.284258] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14
Mod-sfr 283> [    3.285036] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15
Mod-sfr 284> [    3.436610] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100
Mod-sfr 285> [    3.437290] ata1.00: 6291456 sectors, multi 16: LBA48
Mod-sfr 286> [    3.438308] ata1.00: configured for MWDMA2
Mod-sfr 287> [    3.590609] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100
Mod-sfr 288> [    3.591713] ata2.00: configured for MWDMA2
Mod-sfr 289> [    3.592487] scsi 0:0:0:0: Direct-Access     ATA      QEMU HARDDISK    1.5. PQ:
Mod-sfr 290> 0 ANSI: 5
Mod-sfr 291> [    3.593641] sd 0:0:0:0: [sda] 6291456 512-byte hardware sectors: (3.22 GB/3.00
Mod-sfr 292> GiB)
Mod-sfr 293> [    3.594518] sd 0:0:0:0: [sda] Write Protect is off
Mod-sfr 294> [    3.595091] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'
Mod-sfr 295> t support DPO or FUA
Mod-sfr 296> [    3.596189] sd 0:0:0:0: [sda] 6291456 512-byte hardware sectors: (3.22 GB/3.00
Mod-sfr 297> GiB)
Mod-sfr 298> [    3.597076] sd 0:0:0:0: [sda] Write Protect is off
Mod-sfr 299> [    3.597651] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'
Mod-sfr 300> t support DPO or FUA
Mod-sfr 301> [    3.598672]  sda: unknown partition table
Mod-sfr 302> [    3.599808] sd 0:0:0:0: [sda] Attached SCSI disk
Mod-sfr 303> [    3.600485] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mod-sfr 304> [    3.601437] scsi 1:0:0:0: CD-ROM            QEMU     QEMU DVD-ROM     1.5. PQ:
Mod-sfr 305> 0 ANSI: 5
Mod-sfr 306> [    3.602882] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
Mod-sfr 307> [    3.603521] Uniform CD-ROM driver Revision: 3.20
Mod-sfr 308> [    3.604314] sr 1:0:0:0: Attached scsi generic sg1 type 5
Mod-sfr 309> [    3.605189] Fusion MPT base driver 3.04.07
Mod-sfr 310> [    3.605652] Copyright (c) 1999-2008 LSI Corporation
Mod-sfr 311> [    3.606223] Fusion MPT SPI Host driver 3.04.07
Mod-sfr 312> [    3.606809] Fusion MPT FC Host driver 3.04.07
Mod-sfr 313> [    3.607417] Fusion MPT SAS Host driver 3.04.07
Mod-sfr 314> [    3.608251] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mod-sfr 315> [    3.609066] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mod-sfr 316> [    3.609838] uhci_hcd: USB Universal Host Controller Interface driver
Mod-sfr 317> [    3.610751] usbcore: registered new interface driver usblp
Mod-sfr 318> [    3.611382] Initializing USB Mass Storage driver...
Mod-sfr 319> [    3.612003] usbcore: registered new interface driver usb-storage
Mod-sfr 320> [    3.612690] USB Mass Storage support registered.
Mod-sfr 321> [    3.613299] usbcore: registered new interface driver libusual
Mod-sfr 322> [    3.614099] PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64 irq 1,1
Mod-sfr 323> [    3.615569] serio: i8042 KBD port at 0x60,0x64 irq 1
Mod-sfr 324> [    3.616190] serio: i8042 AUX port at 0x60,0x64 irq 12
Mod-sfr 325> [    3.620420] mice: PS/2 mouse device common for all mice
Mod-sfr 326> [    3.623849] rtc_cmos 00:01: RTC can wake from S4
Mod-sfr 327> [    3.624457] input: AT Translated Set 2 keyboard as /devices/platform/i8042/seri
Mod-sfr 328> o0/input/input1
Mod-sfr 329> [    3.624493] rtc_cmos 00:01: rtc core: registered rtc_cmos as rtc0
Mod-sfr 330> [    3.624620] rtc0: alarms up to one day, 114 bytes nvram, hpet irqs
Mod-sfr 331> [    3.624673] i2c /dev entries driver
Mod-sfr 332> [    3.624822] md: raid1 personality registered for level 1
Mod-sfr 333> [    3.627997] device-mapper: ioctl: 4.14.0-ioctl (2008-04-23) initialised: dm-dev
Mod-sfr 334> el@redhat.com
Mod-sfr 335> [    3.628956] cpuidle: using governor ladder
Mod-sfr 336> [    3.629443] cpuidle: using governor menu
Mod-sfr 337> [    3.629895] No iBFT detected.
Mod-sfr 338> [    3.631462] usbcore: registered new interface driver hiddev
Mod-sfr 339> [    3.632137] usbcore: registered new interface driver usbhid
Mod-sfr 340> [    3.632816] usbhid: v2.6:USB HID core driver
Mod-sfr 341> [    3.633493] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
Mod-sfr 342> [    3.634151] virtio-pci 0000:00:05.0: PCI INT A -> Link[LNKA] -> GSI 10 (level,
Mod-sfr 343> high) -> IRQ 10
Mod-sfr 344> [    3.635827] ACPI: PCI Interrupt Link [LNKB] enabled at IRQ 11
Mod-sfr 345> [    3.636526] virtio-pci 0000:00:06.0: PCI INT A -> Link[LNKB] -> GSI 11 (level,
Mod-sfr 346> high) -> IRQ 11
Mod-sfr 347> [    3.638209] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
Mod-sfr 348> [    3.638880] virtio-pci 0000:00:08.0: PCI INT A -> Link[LNKD] -> GSI 11 (level,
Mod-sfr 349> high) -> IRQ 11
Mod-sfr 350> [    3.640959]  vda: vda1
Mod-sfr 351> [    3.643004] Advanced Linux Sound Architecture Driver Version 1.0.18rc3.
Mod-sfr 352> [    3.645040] ALSA device list:
Mod-sfr 353> [    3.645432]   No soundcards found.
Mod-sfr 354> [    3.645893] Netfilter messages via NETLINK v0.30.
Mod-sfr 355> [    3.646468] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
Mod-sfr 356> [    3.647272] ctnetlink v0.93: registering with nfnetlink.
Mod-sfr 357> [    3.648139] IPv4 over IPv4 tunneling driver
Mod-sfr 358> [    3.649176] ip_tables: (C) 2000-2006 Netfilter Core Team
Mod-sfr 359> [    3.649853] TCP cubic registered
Mod-sfr 360> [    3.650335] Initializing XFRM netlink socket
Mod-sfr 361> [    3.650966] NET: Registered protocol family 10
Mod-sfr 362> [    3.651925] lo: Disabled Privacy Extensions
Mod-sfr 363> [    3.653057] tunl0: Disabled Privacy Extensions
Mod-sfr 364> [    3.653913] ip6_tables: (C) 2000-2006 Netfilter Core Team
Mod-sfr 365> [    3.654586] IPv6 over IPv4 tunneling driver
Mod-sfr 366> [    3.655429] sit0: Disabled Privacy Extensions
Mod-sfr 367> [    3.656210] NET: Registered protocol family 17
Mod-sfr 368> [    3.657056] RPC: Registered udp transport module.
Mod-sfr 369> [    3.657609] RPC: Registered tcp transport module.
Mod-sfr 370> [    3.658405] registered taskstats version 1
Mod-sfr 371> [    3.851301] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/s
Mod-sfr 372> erio1/input/input2
Mod-sfr 373> [    5.161037] Sending DHCP and RARP requests ...<7>eth1: no IPv6 routers present
Mod-sfr 374> [   18.661352] ... timed out!
Mod-sfr 375> [   80.598727] IP-Config: Reopening network devices...
Mod-sfr 376> [   82.101038] Sending DHCP and RARP requests ...<7>eth0: no IPv6 routers present

ciscoasa# sw-module module sfr recover boot debug module-boot  Mod-sfr 377> [   96.707352] ... timed out!
Mod-sfr 378> [  161.449733] IP-Config: Auto-configuration of network failed.
Mod-sfr 379> [  161.450403] Freeing unused kernel memory: 544k freed
Mod-sfr 380> INIT: version 2.86 booting
Mod-sfr 381> Please wait: booting...
Mod-sfr 382> mount: sysfs already mounted or /sys busy
Mod-sfr 383> mount: according to mtab, sysfs is already mounted on /sys
Mod-sfr 384> Starting udev [  161.504797] udevd version 124 started
Mod-sfr 385> [  161.618022] udev: renamed network interface eth0 to cplane
Mod-sfr 386> [  161.620822] udev: renamed network interface eth1 to eth0
Mod-sfr 387> [  162.148045] end_request: I/O error, dev fd0, sector 0
Mod-sfr 388> [  162.168044] end_request: I/O error, dev fd0, sector 0
Mod-sfr 389> and populating dev cache
Mod-sfr 390> Root filesystem already rw, not remounting
Mod-sfr 391> Configuring network interfaces... done.
Mod-sfr 392> net.ipv4.conf.default.rp_filter = 1
Mod-sfr 393> net.ipv4.conf.all.rp_filter = 1
Mod-sfr 394> Configuring kvm-ivshmem
Mod-sfr 395> Configuring busybox-syslog
Mod-sfr 396>  System startup links for /etc/init.d/sysklogd already exist.
Mod-sfr 397> Configuring openssh-sshd
Mod-sfr 398>  Adding system startup for /etc/init.d/sshd.
Mod-sfr 399> Configuring sudo
Mod-sfr 400> Configuring ntpdate
Mod-sfr 401> adding crontab
Mod-sfr 402> Configuring update-modules
Mod-sfr 403> INIT: Entering runlevel: 5
Mod-sfr 404> Starting OpenBSD Secure Shell server: sshd
Mod-sfr 405>   generating ssh RSA key...
Mod-sfr 406>   generating ssh DSA key...
Mod-sfr 407> done.
Mod-sfr 408> Starting Advanced Configuration and Power Interface daemon: acpid.
Mod-sfr 409> acpid: starting up with proc fs
Mod-sfr 410> acpid: opendir(/etc/acpi/events): No such file or directory
Mod-sfr 411> starting Busybox inetd: inetd... done.
Mod-sfr 412> Starting ntpd: done
Mod-sfr 413> Starting syslogd/klogd: done
Mod-sfr 414> Cisco FirePOWER Services Boot Image 6.0.0   // TOOK 5-10 MINS TO FINISH

ciscoasa# no debug module-boot      // DISABLE DEBUG
debug module-boot  disabled.

ciscoasa# debug module-boot   // YOU CAN RETAIN THE DEBUG TO OBSERVE .pkg INSTALL


The FirePower (sfr) module will remain in Recover status. You'll need to console to the module, install the package file to complete the upgrade.

ciscoasa# show module sfr

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
 sfr Unknown                                      N/A                FCH2124J0P7

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
 sfr 4001.7ab9.6dd2 to 4001.7ab9.6dd2  N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
 sfr Recover            Not Applicable        


ciscoasa# session sfr console

Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

asasfr login: admin

Password: Admin123

        Cisco FirePOWER Services Boot 6.0.0 (1005)

          Type ? for list of commands

asasfr-boot>system ?
    reload           => Reload the system
    install          => Install the system software
    shutdown         => Shut down the system. Manual restart will be required

asasfr-boot>system install ftp://ftp:ftp123@192.168.1.2/asasfr-sys-6.0.0-1005.pkg
Verifying.        
113

Upgrade aborted.  


You'll need to configure the FirePower module IP address via the setup command in order to FTP (or HTTP) the package (.pkg) file. Connect a straight cable between the FTP PC (192.168.1.2/24) and ASA MGMT port. You just need to unshut (no shutdown) the MGMT interface and may leave the IP address blank. Just configure the FirePower module with basic IP address settings for FTP connectivity. Hit 'Enter' on other configuration since the final FirePower settings will be done after the package (.pkg) has been installed.

You can configure the IP address for the ASA MGMT interface and FirePower module (eth0) to be on the same subnet since the management function are independent of each other.

ciscoasa# show run interface Management0/0
!
interface Management0/0
 management-only
 shutdown
 no nameif
 no security-level
 no ip address

ciscoasa# configure terminal
ciscoasa(config)# interface Management0/0
ciscoasa(config-if)# no shutdown
ciscoasa(config-if)# show run int Management0/0      
!
interface Management0/0
 management-only
 no nameif
 security-level 100
 no ip address
ciscoasa(config-if)# session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

asasfr-boot>setup     

         Welcome to Cisco FirePOWER Services Setup

              [hit Ctrl-C to abort]

            Default values are inside []      

Enter a hostname [asasfr]:

Do you want to configure IPv4 address on management interface?(y/n) [Y]:

Do you want to enable DHCP for IPv4 address assignment on management interface?(y/n) [N]:

Enter an IPv4 address [192.168.8.8]:192.168.1.1

Enter the netmask [255.255.255.0]:

Enter the gateway [192.168.8.1]:192.168.1.1

Do you want to configure static IPv6 address on management interface?(y/n) [N]:

Stateless autoconfiguration will be enabled for IPv6 addresses.

Enter the primary DNS server IP address [8.8.8.8]:

Do you want to configure Secondary DNS Server? (y/n) [n]:

Do you want to configure Local Domain Name? (y/n) [n]:

Do you want to configure Search domains? (y/n) [n]:

Do you want to enable the NTP service? [Y]:

Please review the final configuration:

Hostname:        asasfr

Management Interface Configuration

IPv4 Configuration:    static
    IP Address:    192.168.1.1
    Netmask:    255.255.255.0
    Gateway:    192.168.1.1

IPv6 Configuration:    Stateless autoconfiguration

DNS Configuration:

    DNS Server:

            8.8.8.8

NTP configuration:     Disabled

CAUTION

You have selected IPv6 stateless autoconfiguration, which assigns a global address

based on network prefix and a device identifier. Although this address is unlikely

to change, if it does change, the system will stop functioning correctly.

We suggest you use static addressing instead.

Apply the changes?(y,n) [Y]:

Configuration saved successfully!

Applying...

Done.

Press ENTER to continue...

asasfr-boot> system install ftp://ftp:ftp123@192.168.1.2/asasfr-sys-6.0.0-1005.pkg

Verifying...         
Downloading...

Extracting...

<OUTPUT TRUNCATED>


Package Detail
    Description:            Cisco ASA-SFR 6.0.0-1005 System Install
    Requires reboot:        Yes

Do you want to continue with upgrade? [y]:
Warning: Please do not interrupt the process or turn off the system.

Doing so might leave system in unusable state.

Upgrading...   

Starting upgrade process ....  

Populating new system image.


<OUTPUT TRUNCATED>


Reboot is required to complete the upgrade. Press 'Enter' to reboot the system.    // HIT 'ENTER'

Broadcast message from root (ttyS1) (Thu Jun  8 23:08:50 2017):

The system is going down for reboot NOW!

Console session with module sfr terminated.   


ciscoasa# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525            FCH1834J123
 ips Unknown                                      N/A                FCH1834J123
cxsc Unknown                                      N/A                FCH1834J123
 sfr Unknown                                      N/A                FCH1834J123

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 fc5b.39aa.5164 to fc5b.39aa.5abc  1.0          2.1(9)8      9.4(3)12
 ips fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
cxsc fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
 sfr fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
cxsc Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 ips Unresponsive       Not Applicable       
cxsc Unresponsive       Not Applicable       
 sfr Recover            Not Applicable       

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual    


The FirePower package installation took around 15-20 mins for the FirePower upgrade to finish. You can observe the 'HD' LED light at the back of the chassis if it's already steady green. Use the show module command to verify the SFR status and should see it as UP.

ciscoasa# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525            FCH1834J123
 ips Unknown                                      N/A                FCH1834J123
cxsc Unknown                                      N/A                FCH1834J123
 sfr FirePOWER Services Software Module           ASA5525            FCH1834J123

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 fc5b.39aa.5164 to fc5b.39aa.5abc  1.0          2.1(9)8      9.4(3)12
 ips fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
cxsc fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
 sfr fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A          6.0.0-1005

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
cxsc Unknown                        No Image Present Not Applicable
 sfr ASA FirePOWER                  Up               6.0.0-1005

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 ips Unresponsive       Not Applicable       
cxsc Unresponsive       Not Applicable       
 sfr Up                 Up                   

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual    


ciscoasa# show module sfr

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
 sfr FirePOWER Services Software Module           ASA5525            FCH1834J6E8

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
 sfr fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A          6.0.0-1005

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 sfr ASA FirePOWER                  Up               6.0.0-1005

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
 sfr Up                 Up                   


ciscoasa# show module sfr ?

  details  show detailed hardware module information
  log      show logs for this module
  recover  show recover configuration for this module
  |        Output modifiers
  <cr>

ciscoasa# show module sfr details
Getting details from the Service Module, please wait...

Card Type:          FirePOWER Services Software Module
Model:              ASA5525
Hardware version:   N/A
Serial Number:      FCH1834J123
Firmware version:   N/A
Software version:   6.0.0-1005
MAC Address Range:  fc5b.39aa.5162 to fc5b.39aa.5abc
App. name:          ASA FirePOWER
App. Status:        Up
App. Status Desc:   Normal Operation
App. version:       6.0.0-1005
Data Plane Status:  Up
Console session:    Ready
Status:             Up
DC addr:            No DC Configured                                           
Mgmt IP addr:       192.168.45.45                                              
Mgmt Network mask:  255.255.255.0                                              
Mgmt Gateway:       0.0.0.0                                                    
Mgmt web ports:     443                                                        
Mgmt TLS enabled:   true                                                       


The package (.pkg) file is not visible in the show flash or dir output but it would be permanent even if you reboot the ASA. If you reboot the ASA the SFR module will show as INIT and then becomes UP after a couple of minutes.

ciscoasa# dir

Directory of disk0:/

11     drwx  4096         19:16:16 Sep 29 2014  log
22     drwx  4096         19:16:44 Sep 29 2014  crypto_archive
23     drwx  4096         19:16:52 Sep 29 2014  coredumpinfo
123    -rwx  37656576     19:25:02 Sep 29 2014  asa913-smp-k8.bin
124    -rwx  22658960     19:27:04 Sep 29 2014  asdm-714.bin
125    -rwx  73285632     00:38:08 Jun 06 2017  asa943-12-smp-k8.bin
126    -rwx  25819140     00:42:58 Jun 06 2017  asdm-761.bin
127    -rwx  12998641     19:51:42 Sep 29 2014  csd_3.5.2008-k9.pkg
128    drwx  4096         19:51:44 Sep 29 2014  sdesktop
129    -rwx  6487517      19:51:44 Sep 29 2014  anyconnect-macosx-i386-2.5.2014-k9.pkg
130    -rwx  6689498      19:51:44 Sep 29 2014  anyconnect-linux-2.5.2014-k9.pkg
131    -rwx  4678691      19:51:44 Sep 29 2014  anyconnect-win-2.5.2014-k9.pkg
132    -rwx  100          22:45:26 Jun 05 2017  upgrade_startup_errors_201706052245.log
133    -rwx  41848832     18:55:08 Jun 08 2017  asasfr-5500x-boot-6.0.0-1005.img

8238202880 bytes total (4782514176 bytes free)

ciscoasa# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525            FCH1834J123
 ips Unknown                                      N/A                FCH1834J123
cxsc Unknown                                      N/A                FCH1834J123
 sfr Unknown                                      N/A                FCH1834J123

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 fc5b.39aa.5164 to fc5b.39aa.5abc 1.0          2.1(9)8      9.4(3)12
 ips fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
cxsc fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         
 sfr fc5b.39aa.5162 to fc5b.39aa.5abc  N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 ips Unknown                        No Image Present Not Applicable
cxsc Unknown                        No Image Present Not Applicable

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 ips Unresponsive       Not Applicable       
cxsc Unresponsive       Not Applicable       
 sfr Init               Not Applicable           //  SFR WILL SHOW AS UP AFTER FEW MINS

Mod  License Name   License Status  Time Remaining
---- -------------- --------------- ---------------
 ips IPS Module     Disabled        perpetual


ciscoasa# session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

Cisco ASA5525 v6.0.0 (build 1005)

firepower login: admin

Password: Admin123

Last login: Fri Jun  9 00:04:17 UTC 2017 on ttyS1

Copyright 2004-2015, Cisco and/or its affiliates. All rights reserved.

Cisco is a registered trademark of Cisco Systems, Inc.

All other trademarks are property of their respective owners.

Cisco Fire Linux OS v6.0.0 (build 258)

Cisco ASA5525 v6.0.0 (build 1005)

Last login: Thu Jun  8 23:21:29 UTC 2017

Last login: Fri Jun  9 00:04:17 UTC 2017 on ttyS1

You must accept the EULA to continue.

Press <ENTER> to display the EULA:    // HIT 'ENTER'

END USER LICENSE AGREEMENT

IMPORTANT: PLEASE READ THIS END USER LICENSE AGREEMENT CAREFULLY.  IT IS VERY IMPORTANT THAT YOU CHECK THAT YOU ARE PURCHASING CISCO SOFTWARE OR EQUIPMENT FROM AN APPROVED SOURCE AND THAT YOU, OR THE ENTITY YOU REPRESENT (COLLECTIVELY, THE "CUSTOMER") HAVE BEEN REGISTERED AS THE END USER FOR THE PURPOSES OF THIS CISCO END USER LICENSE AGREEMENT.  IF YOU ARE NOT REGISTERED AS THE END USER YOU HAVE NO LICENSE TO USE THE SOFTWARE AND THE LIMITED WARRANTY IN THIS END USER LICENSE AGREEMENT DOES NOT APPLY.  ASSUMING YOU HAVE PURCHASED FROM AN APPROVED SOURCE, DOWNLOADING, INSTALLING OR USING CISCO OR CISCO-SUPPLIED SOFTWARE CONSTITUTES ACCEPTANCE OF THIS AGREEMENT.


<OUTPUT TRUNCATED>


Product warranty terms and other information applicable to Cisco products are

available at the following URL: http://www.cisco.com/go/warranty.

Please enter 'YES' or press <ENTER> to AGREE to the EULA:   // HIT 'ENTER'

System initialization in progress.  Please stand by. 

You must change the password for 'admin' to continue.

Enter new password: cisco123     // NOT A GOOD PASSWORD IN PRODUCTION NETWORK

Confirm new password: cisco123

You must configure the network to continue.

You must configure at least one of IPv4 or IPv6.

Do you want to configure IPv4? (y/n) [y]:

Do you want to configure IPv6? (y/n) [n]:

Configure IPv4 via DHCP or manually? (dhcp/manual) [manual]:

Enter an IPv4 address for the management interface [192.168.45.45]: 172.27.25.253

Enter an IPv4 netmask for the management interface [255.255.255.0]:

Enter the IPv4 default gateway for the management interface []: 172.27.25.1

Enter a fully qualified hostname for this system [firepower]: lab-firepower

Enter a comma-separated list of DNS servers or 'none' []: 8.8.8.8

Enter a comma-separated list of search domains or 'none' [example.net]: none

If your networking information has changed, you will need to reconnect.


For HTTP Proxy configuration, run 'configure network http-proxy'


Creating default Identity Policy.

Creating default SSL Policy.


Update policy deployment information

    - add device configuration

    - add network discovery

    - add system policy

    - add access control policy

    - applying access control policy


You can register the sensor to a Firepower Management Center and use the
Firepower Management Center to manage it. Note that registering the sensor
to a Firepower Management Center disables on-sensor Firepower Services
management capabilities.

When registering the sensor to a Firepower Management Center, a unique
alphanumeric registration key is always required.  In most cases, to register
a sensor to a Firepower Management Center, you must provide the hostname or
the IP address along with the registration key.

'configure manager add [hostname | ip address ] [registration key ]'

However, if the sensor and the Firepower Management Center are separated by a
NAT device, you must enter a unique NAT ID, along with the unique registration key.

'configure manager add DONTRESOLVE [registration key ] [ NAT ID ]'

Later, using the web interface on the Firepower Management Center, you must
use the same registration key and, if necessary, the same NAT ID when you add
this sensor to the Firepower Management Center.

>

configure  Change to Configuration mode
end        Return to the default mode
exit       Exit this CLI session
expert     Invoke a shell
help       Display an overview of the CLI syntax
history    Display the current session's command line history
logout     Logout of the current CLI session
show       Change to Show Mode
system     Change to System Mode

> show

access-control-config  Show Current Access-Control Configuration
audit-log              Show audit log
cpu                    Show CPU utilization
database               Change to Show Database Mode
device-settings        Show device settings
disk                   Show disk usage
disk-manager           Display current status of local disk(s)
dns                    Show DNS configuration
hostname               Show hostname
hosts                  Show hosts
ifconfig               Show currently configured interfaces
interfaces             Show interface configuration
kdump                  Display status of kernel crash dump feature
log-events-to-ramdisk  Display Logging of Events to hard disk
log-ips-connection     Display Logging of Connection Events setting
managers               Show managing Defense Centers
memory                 Show available memory
model                  Show model
netstat                Show network connections
network                Show configuration of management interface
network-static-routes  Show static routes for management interfaces
ntp                    Show NTP configuration
perfstats              Show perfstats
process-tree           Show processes in tree format
processes              Show processes
route                  Show configured routes
serial-number          Show serial number
ssl-policy-config      Show Current SSL Policy Configuration
summary                Show summary
time                   Show time
traffic-statistics     Show traffic statistics
user                   Show specified users
users                  Show all users
version                Show versions

> show version
-----------------[ lab-firepower ]------------------
Model                     : ASA5525 (72) Version 6.0.0 (Build 1005)
UUID                      : 8a8a8310-4c9f-11e7-a92a-8909aa1a5123
Rules update version      : 2015-10-01-001-vrt
VDB version               : 252
----------------------------------------------------

> show summary
-----------------[ lab-firepower ]------------------
Model                     : ASA5525 (72) Version 6.0.0 (Build 1005)
UUID                      : 8a8a8310-4c9f-11e7-a92a-8909aa1a5123
Rules update version      : 2015-10-01-001-vrt
VDB version               : 252
----------------------------------------------------

Access control policy not yet applied.

> show ifconfig
cplane    Link encap:Ethernet  HWaddr 00:00:00:04:01:23 
          inet addr:127.0.4.1  Bcast:127.0.255.255  Mask:255.255.0.0
          inet6 addr: fe80::200:ff:fe04:1/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:501 errors:0 dropped:0 overruns:0 frame:0
          TX packets:92 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:31930 (31.1 Kb)  TX bytes:8178 (7.9 Kb)

eth0      Link encap:Ethernet  HWaddr FC:5B:39:AA:51:23
          inet addr:172.27.25.253  Bcast:172.27.25.255  Mask:255.255.255.0
          inet6 addr: fe80::fe5b:39ff:feaa:5162/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:204 errors:0 dropped:0 overruns:0 frame:0
          TX packets:68 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:17518 (17.1 Kb)  TX bytes:3288 (3.2 Kb)

lo        Link encap:Local Loopback 
          inet addr:127.0.0.1  Mask:255.255.255.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:874 errors:0 dropped:0 overruns:0 frame:0
          TX packets:874 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:6119854 (5.8 Mb)  TX bytes:6119854 (5.8 Mb)

tun1      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 
          inet addr:169.254.0.1  P-t-P:169.254.0.1  Mask:255.255.0.0
          inet6 addr: fdcc::bd:0:ffff:a9fe:1/64 Scope:Global
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:500
          RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b) 

> show interfaces
---------------------[ inside ]---------------------
Physical Interface        : GigabitEthernet0/1
Type                      : ASA
Security Zone             : None
Status                    : Enabled
Load Balancing Mode       : N/A
---------------------[ cplane ]---------------------
IPv4 Address              : 127.0.4.1
----------------------[ eth0 ]----------------------

Physical Interface        : eth0
Type                      : Management
Status                    : Enabled
MDI/MDIX                  : Auto
MTU                       : 1500
MAC Address               : FC:5B:39:AA:51:23
IPv4 Address              : 172.27.25.253
----------------------[ tun1 ]----------------------
IPv6 Address              : fdcc::bd:0:ffff:a9fe:1/64
---------------------[ tunl0 ]----------------------

----------------------------------------------------

> expert    // GO TO LINUX SHELL

admin@lab-firepower:~$ sudo ping 172.2.8.3   // FIRESIGHT MANAGEMENT CENTER (FMC) IP
PING 172.2.8.3 (172.2.8.3) 56(84) bytes of data.
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
64 bytes from 172.2.8.3:icmp_req=1 ttl=56 time=347 ms
^C
--- 172.2.8.3 ping statistics ---

10 packets transmitted, 10 received, 0% packet loss, time 9006ms
rtt min/avg/max/mdev = 346.345/347.605/349.714/1.312 ms

No comments:

Post a Comment