Nov 8th, 2008


My ASA 5520 is on:

ASA bin 8.0(3)

ASDM 6.0(3)

My flash output is:

# sh flash:

--#-- --length-- -----date/time------ path

2 8192 Feb 07 2008 09:48:00 log

6 8192 Dec 22 2007 15:57:20 crypto_archive

70 14635008 Feb 07 2008 09:39:18 asa803-k8.bin

71 6851212 Feb 07 2008 09:43:24 asdm-603.bin

72 8192 Oct 25 2008 13:09:07 tmp

122 2154944 Nov 03 2008 13:41:34 anyconnect-win-2.2.0140-k9.pkg

I did have asa507-k8.bin in there which I just deleted.

Would it be ok to upgrade my ASDM as SSL VPN needs a later version:

ASA Boot image

8.0(3).1 or later

Adaptive Security Device Manager (ASDM)

6.1(3).1 or later

I'm not sure what that tmp file is

Do I simply need to upload the newer ASDM to flash? It scares me a little, will I need to reboot too.

husycisco Sat, 11/08/2008 - 09:38

Hello Andy,

Just simply upload the asdm image, then issue the following command

asdm image flash:/asdmimagename.bin

You dont need a restart.


whiteford Sat, 11/08/2008 - 09:59

How does it know that the new version should be used as the old asdm will be kept in the flash, just in case I get issues with the latest version?

A Cisco guy told me to keep the ASA firmware and ASDM to the same version like mine currently is, but I don't think he was right as the download of the latest ASDM will work with 8.0(3).

Just wondered what you thought?

husycisco Sat, 11/08/2008 - 10:18


"boot system flash:/imagename.bin" command does set the image to be used and "asdm image flash:asdmimagename.bin" sets the ASDM image that must be used. If none is issued, firewall sets the first comaptible images for system and ASDM.

You can keep the old images of both ASDM and IOS in flash if you have enough space in flash. But as far as I know, ASDM 5.x does not work with IOS 8.x . So if you get issues with new ASDM, you also have to downgrade the IOS.


whiteford Sat, 11/08/2008 - 10:33

Thanks, I deleted the 5.x ASDM, so if I upgrade I will just have ASA 8.0(3) ASDm 6.0(3) and the latest ASDM 6.1(1) I think. A just keep the ASDM 6.0(3) as fallback.

Did my latest comment about keeping both the same not matter?

husycisco Sat, 11/08/2008 - 11:36

Ah sorry, I now got that your question was about 6.0(3) and 6.1(1) not 5.0

That cisco guy is somewhat correct. Here is the issue. As you know, ASDM is a GUI that actually sends IOS commands to device. If ASDM has a higher version than IOS, it may send commands to device when you want to enable a new feature, which are not recognized by IOS. There is a little information icon that appears next to disk image in ASDM window, I have seen rare instances when that popped up and when I clicked on it, it said "Some of the commands ASDM sent are not recognized by device"

Please have a look at following link

As you can see, there are some minor enhancements/corrections in ASDM 6.1 for IOS 8.0. But "new features" work with IOS 8.1.

If you still have concerns, feel free to keep both images, you can switch between images whenever you want with the asdm image command.

whiteford Sat, 11/08/2008 - 13:01

Thanks for finding the time to answer my questions.

I undersatand what you are saying, that error message that could pop up in the ASDM due to having a different version of ASDM, could it cause issues with the firewall or just wont make the config change?

My next challenge would be on updating the ASDM on the faulover ASA I have. I have a active/standby setup (sorry I didn't mention this), but the only way can get on the standby ASA is when I turn off the primary or just pull the failover cable, the standby then becomes the active ASA, thus enablng me to update the ASDM. Is this a normal approach to updating a standby ASA?


husycisco Sun, 11/09/2008 - 13:02

It wont make the config change. Have seen rare occasions that IOS cant recognize a part of a set of commands and desired service cant function properly. I mean if a group of commands which are ready to be sent to firewall by ASDM, contains a single line that cant be recognized, every other commands will be issued despite that single command. And only that single command wont be issued.

If you have console access or ssh access to device, you can still perform IOS copy and boot image set commands (firewall is operational with standby IP address), you dont need a state change. Besides, once you upgrade the IOS of one unit, failover will be broken since failover requires same IOS versions


