Saturday, June 3, 2023

Cisco Firepower 1120 ASA Image and FXOS

You won't find the location of the ASA image in a Firepower 1120. You can only view it using the FXOS CLI. The Firepower eXtensible Operating System (FXOS) is the supervisor and on top of it, you can either run the Firepower Threat Defense (FTD) or the classic ASA software. FXOS provides command-based interface for configuring features, monitoring chassis status, and accessing advanced troubleshooting features.

You can use the show version command to view the current ASA version and image file location. In this case the image file is not found in disk0 (flash).


ciscoasa/admin# changeto system

ciscoasa# show version

 

Cisco Adaptive Security Appliance Software Version 9.13(1)2 <system>

SSP Operating System Version 2.7(1.107)

Device Manager Version 7.13(1)

 

Compiled on Tue 22-Oct-19 19:47 PDT by builders

System image file is "disk0:/installables/switch/fxos-k8-fp1k-lfbff.2.7.1.107.SPA"

Config file at boot was "startup-config"

 

ciscoasa up 1 day 6 hours

 

<OUTPUT TRUNCATED>

 

ciscoasa# dir /all disk0:

 

Directory of disk0:/

 

805306668  drwx  4096         05:35:01 May 18 2023  log

241    drwx  4096         02:19:58 May 18 2023  .private

538857109  -rw-  34033084     06:01:55 Nov 24 2020  asdm.bin

537176350  -rw-  0            06:03:35 Nov 24 2020  coredumpfsysimage.bin

2      drwx  4096         06:10:38 Apr 13 2023  coredumpfsys

210    drwx  21           06:04:27 Nov 24 2020  smart-log

268442472  drw-  25           06:05:05 Nov 24 2020  coredumpinfo

537178212  -rwx  10738        01:34:16 May 18 2023  old_running.cfg

537178213  -rwx  9187         07:25:39 May 18 2023  admin.cfg

2      drwx  4096         06:10:38 Apr 13 2023  cores

204    drwx  6            06:03:35 Nov 24 2020  fxos

538857097  -rw-  1834         06:03:34 Nov 24 2020  cspCfg.xml

805306629  drw-  18           06:45:19 May 18 2023  snmp

 

6 file(s) total size: 34058827 bytes

16106127360 bytes total (15795257344 bytes free/98% free)

 

 

Type the connect fxos command to execute FXOS CLI commands. Use the scope firmware then show image commands to view the ASA image file which is a CSP APP (application image).

 

ciscoasa# connect fxos

Configuring session.

Connecting to FXOS.

...

Connected to FXOS. Escape character sequence is 'CTRL-^X'.

 

NOTICE: You have connected to the FXOS CLI with read-only privileges.

For admin level privileges connect using 'connect fxos admin'.

Config commands and commit-buffer are not supported in appliance mode.

 

 

Cisco Firepower Extensible Operating System (FX-OS) Software

TAC support: http://www.cisco.com/tac

Copyright (c) 2009-2019, Cisco Systems, Inc. All rights reserved.

 

The copyrights to certain works contained in this software are

owned by other third parties and used and distributed under

license.

 

Certain components of this software are licensed under the "GNU General Public

License, version 3" provided with ABSOLUTELY NO WARRANTY under the terms of

"GNU General Public License, Version 3", available here:

http://www.gnu.org/licenses/gpl.html. See User Manual (''Licensing'') for

details.

 

Certain components of this software are licensed under the "GNU General Public

License, version 2" provided with ABSOLUTELY NO WARRANTY under the terms of

"GNU General Public License, version 2", available here:

http://www.gnu.org/licenses/old-licenses/gpl-2.0.html. See User Manual

(''Licensing'') for details.

 

Certain components of this software are licensed under the "GNU LESSER GENERAL

PUBLIC LICENSE, version 3" provided with ABSOLUTELY NO WARRANTY under the terms

of "GNU LESSER GENERAL PUBLIC LICENSE" Version 3", available here:

http://www.gnu.org/licenses/lgpl.html. See User Manual (''Licensing'') for

details.

 

Certain components of this software are licensed under the "GNU Lesser General

Public License, version 2.1" provided with ABSOLUTELY NO WARRANTY under the

terms of "GNU Lesser General Public License, version 2", available here:

http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html. See User Manual

(''Licensing'') for details.

 

Certain components of this software are licensed under the "GNU Library General

Public License, version 2" provided with ABSOLUTELY NO WARRANTY under the terms

of "GNU Library General Public License, version 2", available here:

http://www.gnu.org/licenses/old-licenses/lgpl-2.0.html. See User Manual

(''Licensing'') for details.

 

firepower-1120# scope firmware

firepower-1120 /firmware # show image

Name                                          Type                 Version

--------------------------------------------- -------------------- -------

cisco-asa.9.13.1.2.csp                        CSP APP              9.13.1.2

fxos-k8-fp1k-firmware.1008.0203.SPA           Switch Firmware      1008.0203

fxos-k8-fp1k-lfbff.2.7.1.107.SPA              System Image         2.7(1.107)

fxos-k9-manager.2.7.1.107.SPA                 Manager Image        2.7(1.107)

fxos-k9-mgmtext.2.7.1.84.SPA                  Management Extension 2.7(1.84)

 

To go back to ASA mode or CLI prompt, type the connect asa command.

 

firepower-1120 /firmware #  connect asa

Connection with FXOS terminated.

Type help or '?' for a list of available commands.

ciscoasa/admin# show version

 

Cisco Adaptive Security Appliance Software Version 9.13(1)2 <context>

SSP Operating System Version 2.7(1.107)

Device Manager Version 7.13(1)

 

Compiled on Tue 22-Oct-19 19:47 PDT by builders

 

ciscoasa up 1 day 6 hours

 

Hardware:   FPR-1120, 13799 MB RAM, CPU Atom C3000 series 2000 MHz, 1 CPU (12 cores)

 

Encryption hardware device : Cisco FP Crypto on-board accelerator (revision 0x11)

                             Driver version        : 4.1.0

                             Number of accelerators: 6

 

 1: Int: Internal-Data0/0    : address is 00a0.c900.0002, irq 10

 3: Int: Not licensed        : irq 0

 4: Ext: Management1/1       : address is a281.7300.0004, irq 0

 5: Int: Internal-Data1/1    : address is a281.7300.0002, irq 0

 

License mode: Smart Licensing

 

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited     

Maximum VLANs                     : 512           

Inside Hosts                      : Unlimited     

Failover                          : Active/Active 

Encryption-DES                    : Enabled       

Encryption-3DES-AES               : Enabled       

Security Contexts                 : 2             

Carrier                           : Disabled      

AnyConnect Premium Peers          : 150           

AnyConnect Essentials             : Disabled      

Other VPN Peers                   : 150           

Total VPN Peers                   : 150           

AnyConnect for Mobile             : Enabled       

AnyConnect for Cisco VPN Phone    : Enabled       

Advanced Endpoint Assessment      : Enabled       

Shared License                    : Disabled      

Total TLS Proxy Sessions          : 320           

Cluster                           : Disabled      

 

Serial Number: JAD24421234

Configuration register is 0x1

Configuration last modified by enable_15 at 07:47:12.437 UTC Thu May 18 2023