Saturday, January 2, 2021

Cisco ASA 5506-X Security Plus License

I had to configure a pair of Cisco ASA 5506-X firewalls and apply a Security Plus license in order to support the Active/Standby Failover (High Availability) feature. You'll find the comparison between the Base license vs. Security Plus license feature on this link.

You'll be prompted a warning message for the lack of failover license support when you try to configure the standby (failover) IP address on an ASA interface.

ASA5506-X(config-if)# interface BVI1

ASA5506-X(config-if)# nameif inside

ASA5506-X(config-if)# security-level 100

ASA5506-X(config-if)# ip address 192.168.1.1 255.255.255.0 standby 192.168.1.2

WARNING: Cannot configure standby IP address because this unit lack failover license support.

 

 

ASA5506-X# show version

 

Cisco Adaptive Security Appliance Software Version 9.8(2)

Firepower Extensible Operating System Version 2.2(2.52)

Device Manager Version 7.8(2)

 

Compiled on Thu 02-Apr-20 10:19 PDT by builders

System image file is "disk0:/asa982-lfbff-k8.SPA"

Config file at boot was "startup-config"

 

ASA5506-X up 25 mins 29 secs

 

Hardware:   ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)

Internal ATA Compact Flash, 8000MB

BIOS Flash M25P64 @ 0xfed01000, 16384KB

 

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)

                             Number of accelerators: 1

 

 1: Ext: GigabitEthernet1/1  : address is bc5a.5681.d596, irq 255

 2: Ext: GigabitEthernet1/2  : address is bc5a.5681.d597, irq 255

 3: Ext: GigabitEthernet1/3  : address is bc5a.5681.d598, irq 255

 4: Ext: GigabitEthernet1/4  : address is bc5a.5681.d599, irq 255

 5: Ext: GigabitEthernet1/5  : address is bc5a.5681.d59a, irq 255

 6: Ext: GigabitEthernet1/6  : address is bc5a.5681.d59b, irq 255

 7: Ext: GigabitEthernet1/7  : address is bc5a.5681.d59c, irq 255

 8: Ext: GigabitEthernet1/8  : address is bc5a.5681.d59d, irq 255

 9: Int: Internal-Data1/1    : address is bc5a.5681.d595, irq 255

10: Int: Internal-Data1/2    : address is 0000.0001.0002, irq 0

11: Int: Internal-Control1/1 : address is 0000.0001.0001, irq 0

12: Int: Internal-Data1/3    : address is 0000.0001.0003, irq 0

13: Ext: Management1/1       : address is bc5a.5681.d595, irq 0

14: Int: Internal-Data1/4    : address is 0000.0100.0001, irq 0

 

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 5              perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Disabled       perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 2              perpetual

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 10             perpetual

Total VPN Peers                   : 12             perpetual

AnyConnect for Mobile             : Disabled       perpetual

AnyConnect for Cisco VPN Phone    : Disabled       perpetual

Advanced Endpoint Assessment      : Disabled       perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 2              perpetual

Botnet Traffic Filter             : Disabled       perpetual

Cluster                           : Disabled       perpetual

 

This platform has a Base license.

 

Serial Number: JAD24111234

Running Permanent Activation Key: 0xd71be575 0xb069db6f 0xb0523db4 0x949058c8 0x44221234

Configuration register is 0x1

Image type                : Release

Key Version               : A

Configuration last modified by enable_15 at 11:56:07.469 UTC Tue Nov 10 2020

 

 

You'll need to register and retrieve the license key in the Cisco Licensing portal. Next, apply the license key using the global config activation-key <KEY> command and issue a reload for the license to take effect.

 

ASA5506-X(config-if)# activation-key 3c2dfa64 2c9281c9 5491edd8 8b4c40a4 cb356789

Validating activation key. This may take a few minutes...

Failover is different.

   running permanent activation key: Restricted(R)

   new permanent activation key: Unrestricted(UR)

WARNING: The running activation key was not updated with the requested key.

Proceed with update flash activation key? [confirm] <ENTER>

The flash permanent activation key was updated with the requested key,

and will become active after the next reload.

ASA5506-X(config-if)# end

ASA5506-X# reload

Proceed with reload? [confirm]

ASA5506-X#

 

 

***

*** --- START GRACEFUL SHUTDOWN ---

Shutting down isakmp

Shutting down webvpn

Shutting down sw-module

Shutting down License Controller

Shutting down File system

 

 

 

***

*** --- SHUTDOWN NOW ---

Process shutdown finished

Rebooting... (status 0x9)

 

 

<OUTPUT TRUNCATED>

 

 

Notice the ASA 5506-X now has the Security Plus license as well as the Maximum VLANs is now 30, Failover has been enabled for Active/Standby and VPN peers was increased to 50 (for AnyConnect VPN). The support for AnyConnect requires a separate AnyConnect Plus or Apex license.

 

ASA5506-X# show version

 

Cisco Adaptive Security Appliance Software Version 9.8(2)

Firepower Extensible Operating System Version 2.2(2.52)

Device Manager Version 7.8(2)

 

Compiled on Thu 02-Apr-20 10:19 PDT by builders

System image file is "disk0:/asa982-lfbff-k8.SPA"

Config file at boot was "startup-config"

 

ASA5506-X up 13 mins 34 secs

 

Hardware:   ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)

Internal ATA Compact Flash, 8000MB

BIOS Flash M25P64 @ 0xfed01000, 16384KB

 

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)

                             Number of accelerators: 1

 

 1: Ext: GigabitEthernet1/1  : address is bc5a.5681.d596, irq 255

 2: Ext: GigabitEthernet1/2  : address is bc5a.5681.d597, irq 255

 3: Ext: GigabitEthernet1/3  : address is bc5a.5681.d598, irq 255

 4: Ext: GigabitEthernet1/4  : address is bc5a.5681.d599, irq 255

 5: Ext: GigabitEthernet1/5  : address is bc5a.5681.d59a, irq 255

 6: Ext: GigabitEthernet1/6  : address is bc5a.5681.d59b, irq 255

 7: Ext: GigabitEthernet1/7  : address is bc5a.5681.d59c, irq 255

 8: Ext: GigabitEthernet1/8  : address is bc5a.5681.d59d, irq 255

 9: Int: Internal-Data1/1    : address is bc5a.5681.d595, irq 255

10: Int: Internal-Data1/2    : address is 0000.0001.0002, irq 0

11: Int: Internal-Control1/1 : address is 0000.0001.0001, irq 0

12: Int: Internal-Data1/3    : address is 0000.0001.0003, irq 0

13: Ext: Management1/1       : address is bc5a.5681.d595, irq 0

14: Int: Internal-Data1/4    : address is 0000.0100.0001, irq 0

 

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 30             perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Standby perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 4              perpetual

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 50             perpetual

Total VPN Peers                   : 50             perpetual

AnyConnect for Mobile             : Disabled       perpetual

AnyConnect for Cisco VPN Phone    : Disabled       perpetual

Advanced Endpoint Assessment      : Disabled       perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 160            perpetual

Botnet Traffic Filter             : Disabled       perpetual

Cluster                           : Disabled       perpetual

 

This platform has an ASA 5506 Security Plus license.

 

Serial Number: JAD24111234

Running Permanent Activation Key: 0x3c2dfa64 0x2c9281c9 0x5491edd8 0x8b4c40a4 0xcb356789

Configuration register is 0x1

Image type                : Release

Key Version               : A

Configuration has not been modified since last system restart.


Sunday, December 6, 2020

Configure Cisco AnyConnect in ASA Multiple Context Mode

I tried the popular Beef Wellington (English meat pie) at Bread Street Kitchen Marina Bay Sands, which is owned by celebrity chef Gordon Ramsay. The dining experience was nice and had free bread while waiting for my order. The serving was generous and the meat was very tender (ordered medium rare). I strolled around Garden's By the Bay afterwards and noticed most of the attractions such as the Floral Fantasy, Flower Dome and Supertree Skyway would need pre-purchased online tickets (no more walk-ins) due to COVID-19 crowd control and physical distancing.

 




You'll need to apply first the AnyConnect Apex license SKU/part: L-AC-APX-LIC= under the System context, which is a term based of 1-, 3- or 5-year subscription. The Apex license would take effect immediately and doesn't require a reboot. Also note the Total VPN peers supported on the specific platform (in this case 2500 max VPN sessions).

 

You can't use the default AnyConnect Premium Peers as it will display an error requiring for an Apex license.

 

ciscoasa/pri/act(config)# class AnyConnect

ciscoasa/pri/act(config-class)# limit-resource VPN AnyConnect 4

WARNING: Multi-mode remote access VPN support requires an AnyConnect Apex license

 

ciscoasa/pri/act/admin# changeto system

ciscoasa/pri/act# show version

 

<OUTPUT TRUNCATED>

 

 

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 300            perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Active  perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Security Contexts                 : 10             perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 2              perpetual   // ANYCONNECT APEX LICENSE

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 2500           perpetual  

Total VPN Peers                   : 2500           perpetual   // TOTAL VPN SESSION SUPPORTED ON THE PLATFORM

AnyConnect for Mobile             : Disabled       perpetual

AnyConnect for Cisco VPN Phone    : Disabled       perpetual

Advanced Endpoint Assessment      : Disabled       perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 2              perpetual

Botnet Traffic Filter             : Disabled       perpetual

IPS Module                        : Disabled       perpetual

Cluster                           : Enabled        perpetual

Cluster Members                   : 2              perpetual

 

This platform has an ASA5545 VPN Premium license.

 

 

Failover cluster licensed features for this platform:   // ACTIVE-STANDBY FAILOVER PAIR

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 300            perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Active  perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Security Contexts                 : 12             perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 4              perpetual   // 2x FROM ACTIVE FW + 2x FROM STANDBY FW

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 2500           perpetual

Total VPN Peers                   : 2500           perpetual

AnyConnect for Mobile             : Disabled       perpetual

AnyConnect for Cisco VPN Phone    : Disabled       perpetual

Advanced Endpoint Assessment      : Disabled       perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 4              perpetual

Botnet Traffic Filter             : Disabled       perpetual

IPS Module                        : Disabled       perpetual

Cluster                           : Enabled        perpetual

 

This platform has an ASA5545 VPN Premium license.

 

<OUTPUT TRUNCATED>

 

 

ciscoasa/pri/act# configure terminal

ciscoasa/pri/act(config)# activation-key 1c05d652 e83add97 3573e568 dcfc1234 07335678

Validating activation key. This may take a few minutes...

Both Running and Flash permanent activation key was updated with the requested key.

ciscoasa/pri/act(config)#

ciscoasa/pri/act(config)# show version

 

<OUTPUT TRUNCATED>

 

 

Licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 300            perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Active  perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Security Contexts                 : 10             perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 2500           perpetual

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 2500           perpetual

Total VPN Peers                   : 2500           perpetual

AnyConnect for Mobile             : Enabled        perpetual

AnyConnect for Cisco VPN Phone    : Enabled        perpetual

Advanced Endpoint Assessment      : Enabled        perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 2              perpetual

Botnet Traffic Filter             : Disabled       perpetual

IPS Module                        : Disabled       perpetual

Cluster                           : Enabled        perpetual

Cluster Members                   : 2              perpetual

 

This platform has an ASA5545 VPN Premium license.

 

 

Failover cluster licensed features for this platform:

Maximum Physical Interfaces       : Unlimited      perpetual

Maximum VLANs                     : 300            perpetual

Inside Hosts                      : Unlimited      perpetual

Failover                          : Active/Active  perpetual

Encryption-DES                    : Enabled        perpetual

Encryption-3DES-AES               : Enabled        perpetual

Security Contexts                 : 12             perpetual

Carrier                           : Disabled       perpetual

AnyConnect Premium Peers          : 2500           perpetual

AnyConnect Essentials             : Disabled       perpetual

Other VPN Peers                   : 2500           perpetual

Total VPN Peers                   : 2500           perpetual

AnyConnect for Mobile             : Enabled        perpetual

AnyConnect for Cisco VPN Phone    : Enabled        perpetual

Advanced Endpoint Assessment      : Enabled        perpetual

Shared License                    : Disabled       perpetual

Total TLS Proxy Sessions          : 4              perpetual

Botnet Traffic Filter             : Disabled       perpetual

IPS Module                        : Disabled       perpetual

Cluster                           : Enabled        perpetual

 

This platform has an ASA5545 VPN Premium license.

 

<OUTPUT TRUNCATED>

 

 

Create a VPN Resource Class and allocate the number of AnyConnect license under System context. You can divide the AnyConnect resource to other Resource Class but make sure their total equals to the maximum VPN count the platform supports. Since this is the only context using AnyConnect, I gave it the full 2500 count with a burst of up to 1500.

 

ciscoasa/pri/act(config)# class AnyConnect 

ciscoasa/pri/act(config-class)# limit-resource VPN ?

 

class mode commands/options:

  AnyConnect  AnyConnect Premium license limit. These are guaranteed for a

              context and shouldn't exceed the system capacity when combined

              across all contexts.

  Burst       Burst limit over the configured limit. This burst limit is not

              guaranteed. The context may take this resource if it is available

              on the device at run time.

  Other       Other VPN sessions which include Site-to-Site, IKEv1 RA and L2tp

              Sessions. These are guaranteed for a context and shouldn't exceed

              the system capacity when combined across all contexts.

  ikev1       Configure IKEv1 specific resources.

 

ciscoasa/pri/act(config-class)# limit-resource VPN AnyConnect ?

 

class mode commands/options:

  WORD  Value of resource limit (in <value> or <value>%)

 

ciscoasa/pri/act(config-class)# limit-resource VPN AnyConnect 2500

ciscoasa/pri/act(config-class)# limit-resource VPN Burst AnyConnect 1500

 

 

Create a new directory (I named it shared). Configure the new context to use/point on this new storage and add the AnyConnect Resource Class under the System context.

 

ciscoasa/pri/act(config)# mkdir shared

 

Create directory filename [shared]?

 

Created dir disk0:/shared

ciscoasa/pri/act(config)# context RA-VPN

Creating context 'RA-VPN'... Done. (1)

ciscoasapri/act(config-ctx)# member AnyConnect

ciscoasa/pri/act(config-ctx)#  description FOR ANYCONNECT RA VPN

ciscoasa/pri/act(config-ctx)#  allocate-interface GigabitEthernet0/0

ciscoasa/pri/act(config-ctx)#  allocate-interface GigabitEthernet0/1.50

ciscoasa/pri/act(config-ctx)#  config-url disk0:/RA-VPN.cfg

 

WARNING: Could not fetch the URL disk0:/RA-VPN.cfg

INFO: Creating context with default config

ciscoasa/pri/act(config-ctx)# storage-url shared disk0:/shared shared

 

 

Transfer the AnyConnect image from the main flash/disk0 space to the new shared directory.

 

ciscoasa/pri/act(config)# copy disk0:/anyconnect-win-4.8.03052-webdeploy-k9.pkg disk0:/shared

 

Source filename [anyconnect-win-4.8.03052-webdeploy-k9.pkg]?

 

Destination filename [/shared/anyconnect-win-4.8.03052-webdeploy-k9.pkg]?

 

Copy in progress...CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

 

<OUTPUT TRUNCATED>

 

 

ciscoasa/pri/act(config)# dir shared/

 

Directory of disk0:/shared/

 

107    -rwx  72771616     01:56:18 Oct 27 2020  anyconnect-win-4.8.03052-webdeploy-k9.pkg

 

 

Configure AnyConnect (webvpn) and the rest of the config in the new Context.

 

ciscoasa/pri/act(config)# changeto context RA-VPN

ciscoasa/pri/act/RA-VPN(config)# webvpn

ciscoasa/pri/act/RA-VPN(config-webvpn)# enable outside

ciscoasa/pri/act/RA-VPN(config-webvpn)# anyconnect enable

ciscoasa/pri/act/RA-VPN(config-webvpn)# anyconnect image shared:/anyconnect-win-4.8.03052-webdeploy-k9.pkg 1


Sunday, October 4, 2020

Cisco ASA Firewall 'no-proxy-arp' Command

I was troubleshooting a Context-based (Multiple Mode) Cisco ASA Firewall and noticed the upstream Internet edge router had duplicate ARP entries or MAC address coming from the ASA Context "outside" interfaces. This caused the traffic on some downstream devices to be intermittent or unstable. I initially thought it was a software bug since I recently upgraded the ASA version but most of the time, an issue or an outage might be caused by a recent configuration change.

I discovered one of the newly created ASA Context had an Identity NAT from "all source" to "all destination" was misconfigured by one of the admin (scary command!). I suspected it was configured as such since both the "inside" and "outside" interfaces were configured with a public IP address and thought of the old 8.2 NAT (NAT exemption). So I put the NAT keyword no-proxy-arp at the end, cleared the ARP table and issue was resolved.

The behavior in a Cisco ASA NAT is that it can respond to ARP requests for IP addresses other than the ASA's interface IP address. If you add the keyword no-proxy-arp to specific NAT commands (best practice), the ASA will not respond to ARP requests for the global IP subnet identified in those NAT statements.


INTERNET_ROUTER#show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 80.25.22.150 118 a20f.0c00.0004 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.151 118 a20f.0c00.0005 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.152 225 a20f.0c00.00f8 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.153 162 a20f.0c00.00f8 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.154 118 a20f.0c00.0020 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.155 118 a20f.0c00.0021 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.156 248 a20f.0c00.00f8 ARPA TenGigabitEthernet0/0/0
Internet 80.25.22.157 231 a20f.0c00.00f8 ARPA TenGigabitEthernet0/0/0 


ciscoasa/pri/act/CUSTA# show arp
 outside 80.25.22.130 a03d.6f2e.7000 6
 outside 80.25.22.129 0000.0c9f.f004 6
 outside 80.25.22.235 001b.1700.0110 32
 outside 80.25.22.151 a20f.0c00.0005 158
 outside 80.25.22.147 a20f.0c00.0017 158
 outside 80.25.22.135 a20f.0c00.000b 158
 outside 80.25.22.149 a20f.0c00.001b 158
 outside 80.25.22.159 a20f.0c00.0025 158
 outside 80.25.22.155 a20f.0c00.0021 158
 outside 80.25.22.139 a20f.0c00.0029 158
 outside 80.25.22.169 a20f.0c00.002d 158
 inside 80.25.21.67 5087.89b8.db00 13196
 inside 80.25.21.66 a20f.0c00.00fb 13706


ciscoasa/pri/act/CUSTA# show run nat
nat (inside,outside) source static all all destination static all all
ciscoasa/pri/act/CUSTA#
ciscoasa/pri/act/CUSTA# configure terminal
ciscoasa/pri/act/CUSTA(config)# nat (inside,outside) source static all all destination static all all ?                    
configure mode commands/options:
  description     Specify NAT rule description
  inactive        Disable a NAT rule
  net-to-net      Net to net mapping of IPv4 to IPv6
  no-proxy-arp    Disable proxy ARP on egress interface
  route-lookup    Perform route lookup for this rule
  service         NAT service parameters
  unidirectional  Enable per-session NAT
  <cr>


ciscoasa/pri/act/CUSTA(config)# nat (inside,outside) source static all all destination static all all no-proxy-arp
ciscoasa/pri/act/CUSTA(config)# show run nat
nat (inside,outside) source static all all destination static all all no-proxy-arp

ciscoasa/pri/act/CUSTA(config)#
ciscoasa/pri/act/CUSTA(config)# clear arp
ciscoasa/pri/act/CUSTA(config)#
ciscoasa/pri/act/CUSTA(config)# show arp
ciscoasa/pri/act/CUSTA(config)# <BLANK>

 

Saturday, September 5, 2020

Enabling coredump on a Cisco ASA Firewall

Here's a nice link in configuring a coredump in a Cisco ASA Firewall. This feature takes a snapshot of the ASA memory when a system crash occur, which can give useful information to Cisco TAC engineer in their troubleshooting.

 

LAB-ASA5515x# show coredump filesystem  

 

'disk0:' has no coredump filesystem

LAB-ASA5515x# conf t

LAB-ASA5515x(config)# coredump ?    

 

configure mode commands/options:

  enable  Enable coredump generation to filesystem

LAB-ASA5515x(config)# coredump enable

 

WARNING: Enabling coredump on an ASA5515 platform will delay the reload of

the system by up to 30 minutes in the event of software forced reload.

The exact time depends on the size of the coredump generated.

 

Proceed with coredump filesystem allocation of 1000 MB

on 'disk0:' (Note this may take a while) ? [confirm]

filesys_image created ok: disk0:coredumpfsysimage.bin

 

Making coredump file system image!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

 

<OUTPUT TRUNCATED>


!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Coredump file system image created & mounted successfully

 

/dev/loop0 on /mnt/disk0/coredumpfsys type vfat (rw,relatime,fmask=0022,dmask=0022,codepage=437,iocharset=iso8859-1,shortname=mixed,errors=remount-ro)

 

 

LAB-ASA5515x(config)# dir

 

Directory of disk0:/

 

95     -rwx  111550464    06:02:40 Oct 15 2019  asa984-10-smp-k8.bin

96     -rwx  33696792     06:04:16 Oct 15 2019  asdm-7122.bin

11     drwx  4096         06:08:18 Oct 15 2019  log

22     drwx  4096         06:08:58 Oct 15 2019  crypto_archive

25     drwx  4096         06:09:04 Oct 15 2019  coredumpinfo

98     -rwx  4799         05:14:28 Oct 26 2019  oldconfig_2019Oct26_0514.cfg

23     drwx  4096         05:25:12 Nov 24 2019  snmp

104    -rwx  72771616     04:22:02 May 20 2020  anyconnect-win-4.8.03052-webdeploy-k9.pkg

105    -rwx  111624192    04:22:42 May 20 2020  asa984-20-smp-k8.bin

110    -rwx  1048576000   03:28:09 Jul 29 2020  coredumpfsysimage.bin

1      drwx  16384        03:27:39 Jul 29 2020  coredumpfsys

 

6 file(s) total size: 1378223863 bytes

7994437632 bytes total (6615339008 bytes free/82% free)

 

 

LAB-ASA5515x(config)# no coredump enable

LAB-ASA5515x(config)# dir

 

Directory of disk0:/

 

95     -rwx  111550464    06:02:40 Oct 15 2019  asa984-10-smp-k8.bin

96     -rwx  33696792     06:04:16 Oct 15 2019  asdm-7122.bin

11     drwx  4096         06:08:18 Oct 15 2019  log

22     drwx  4096         06:08:58 Oct 15 2019  crypto_archive

25     drwx  4096         06:09:04 Oct 15 2019  coredumpinfo

98     -rwx  4799         05:14:28 Oct 26 2019  oldconfig_2019Oct26_0514.cfg

23     drwx  4096         05:25:12 Nov 24 2019  snmp

104    -rwx  72771616     04:22:02 May 20 2020  anyconnect-win-4.8.03052-webdeploy-k9.pkg

105    -rwx  111624192    04:22:42 May 20 2020  asa984-20-smp-k8.bin

110    -rwx  1048576000   03:28:09 Jul 29 2020  coredumpfsysimage.bin

1      drwx  16384        03:27:39 Jul 29 2020  coredumpfsys

 

6 file(s) total size: 1378223863 bytes

7994437632 bytes total (6615339008 bytes free/82% free)

 

LAB-ASA5515x(config)# delete disk0:/coredumpfsysimage.bin

 

Delete filename [coredumpfsysimage.bin]?

 

Delete disk0:/coredumpfsysimage.bin? [confirm]

 

LAB-ASA5515x(config)# delete disk0:/coredumpfsys        

 

Delete filename [coredumpfsys]?

 

Delete disk0:/coredumpfsys? [confirm]

 

 

%Error deleting disk0:/coredumpfsys (Device or resource busy)

LAB-ASA5515x(config)# delete ?

 

exec mode commands/options:

  /noconfirm  Do not prompt for confirmation

  /recursive  Recursive delete

  /replicate  Execute delete operation on standby unit as well

  disk0:      File to be deleted

  disk1:      File to be deleted

  flash:      File to be deleted

LAB-ASA5515x(config)# delete /recursive ?

 

exec mode commands/options:

  /noconfirm  Do not prompt for confirmation

  /replicate  Execute delete operation on standby unit as well

  disk0:      File to be deleted

  disk1:      File to be deleted

  flash:      File to be deleted

LAB-ASA5515x(config)# delete /recursive disk0:/coredumpfsys

 

Delete filename [coredumpfsys]?

 

Examine files in directory disk0:/coredumpfsys? [confirm]

 

Delete disk0:/coredumpfsys? [confirm]

 

%Error Removing dir disk0:/coredumpfsys (Device or resource busy)

 

 

LAB-ASA5515x(config)# rmdir coredumpfsys

 

Remove directory filename [coredumpfsys]?

 

Delete disk0:/coredumpfsys? [confirm]

 

%Error Removing dir disk0:/coredumpfsys (Device or resource busy)