cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3466
Views
0
Helpful
10
Replies

ASA 5540 , CSC module problem

saeed-zamani
Level 1
Level 1

Hi, i have a ASA5540-AIP20-K9 with ASA-SSM-CSC-20-K9 module, but this module is not coming up, in ASDM and for entering the license it doesn't accept old password that should be "cisco" as document says, i don't know how can i reset the module to factory default, i can not use the mentioned password recovery procedure because module is not up and maybe version is lower than 6.

10 Replies 10

edadios
Cisco Employee
Cisco Employee

You will need to re-image it, if you do not know the password.

http://www.cisco.com/en/US/docs/security/ips/5.1/configuration/guide/cli/cliImage.html#wpxref68481 .

If you are planning to go to 6.X anyway, just use a 6.x image code for the procedure.

The module's port, needs to be plugged in, to the lan, and provided an ip range, that can reach the tftp server.

Hi, i tried command "hw-module" to reset the module but it says that module is not in up state. it show module in below command but it is not up.

ciscoasa# sh module 1

Mod Card Type Model Serial No.

--- -------------------------------------------- ------------------ -----------

1 ASA 5500 Series Content Security Services Mo ASA-SSM-CSC-20 JAF10380613

Mod MAC Address Range Hw Version Fw Version Sw Version

--- --------------------------------- ------------ ------------ ---------------

1 000a.b89c.d466 to 000a.b89c.d466 1.0 1.0(11)2

Mod SSM Application Name Status SSM Application Version

--- ------------------------------ ---------------- --------------------------

Mod Status Data Plane Status Compatibility

--- ------------------ --------------------- -------------

1 Unresponsive Not Applicable

Hello,

i tried to re-image the module but nothing happened in the TFTP server. module status is still down... how can i re-image it when module is not coming up??

Thanks,

Saeed.

saeed

I am having same problem with my SSM-CSC10 module. I have followed every Cisco recommend methods for re-image but module doesn't seems to go into rommon mode to pull image from tftp. I have also enabled debug module-boot command and nothing apprears as results.

Can someone please guide us?? Or Is it a hardware fault??

Thanks

R

The port on the module should be connected to the lan, and assigned an ip that will be able to reach the tftp server.

I use 3cdaemon v2 tftp most times, and works for me.

Use an image file (.img) from here http://www.cisco.com/cgi-bin/tablebuild.pl/ips6-asa-aip .

Read the reame that comes with it for further instruction on re-image.

Hope this helkps you if not, open an SR with TAC.

are you sure that this image is for CSC module? module is not IPS, it is CSC and i found that image for this module is: csc6.1.1587.0.bin

please confirm this. also i tried to load module from TFTP but nothing comes on TFTP when it boots. module goes to "init" mode after ASA boots and after few minutes it go to "unresponsive" mode.

BR,

Saeed.

@Saeed

I have exactly same issues with my CSC card, as you can see from my last posts. I hope you didn't bought it from ebay. I know there are some fake ones.

I am struck as well. I have also notice, those cards are very tempermental. :)

saeed-zamani
Level 1
Level 1

HI, i found that flash card of CSC module is empty, i put that on my laptop and see nothing is on the CF. i have the following files, which one should i put on the flash?

csc6.2.1599.5.pkg , 4MB

csc6.2.1599.5.pkg.md5 , 54 byte

csc6.1-b1519.bin, 57MB

please help me.

Saeed.

Well, I copied these files and it doesn't make any difference to it.

Look here:

ASA-5510# sho module 1 det

Getting details from the Service Module, please wait...

Unable to read details from slot 1

ASA 5500 Series Content Security Services Module-10

Model: ASA-SSM-CSC-10

Hardware version: 1.0

Serial Number: JAF10*****

Firmware version: 1.0(11)2

Software version:

MAC Address Range: 0018.199e.**** to 0018.199e.****

Data plane Status: Not Applicable

Status: Unresponsive

ASA-5510# session 1

Opening command session with slot 1.

Card in slot 1 did not respond to session request.

ASA-5510#_

ASA-5510(config)# hw module 1 rec

ASA-5510(config)# hw module 1 recover con

Image URL [tftp://0.0.0.0/]: tftp://192.168.1.6/csc6.2.1599.0.bin

Port IP Address [0.0.0.0]: 192.168.1.250

VLAN ID [0]:

Gateway IP Address [0.0.0.0]:

ASA-5510(config)# deb

ASA-5510(config)# debug mo

ASA-5510(config)# debug module-boot

debug module-boot enabled at level 1

ASA-5510(config)# hw module 1 recover boot

The module in slot 1 will be recovered. This may

erase all configuration and all data on that device and

attempt to download a new image for it.

Recover module in slot 1? [confirm]

Recover issued for module in slot 1

ASA-5510(config)# debug module-boot

debug module-boot enabled at level 1

ASA-5510# sho module 1 det

Getting details from the Service Module, please wait...

Unable to read details from slot 1

ASA 5500 Series Content Security Services Module-10

Model: ASA-SSM-CSC-10

Hardware version: 1.0

Serial Number: JAF1******

Firmware version: 1.0(11)2

Software version:

MAC Address Range: 0018.199e.**** to 0018.199e.****

Data plane Status: Not Applicable

Status: Recover

ASA-5510#

You can see no debuging is appearing in console and it seems card is gone dead. CSC NIC port is solid green and not blinking. Power: Green & Status: Yellow lights.

I am on same subnet no issues with VLANs or conectivity on LAN.

Any idea?? or Is it dead module?

Thanks

R

Hello,

I have exactly the same problem after an upgrade to 6.2.1599.6. CSC-SSM module rebooted and never came up.

I did follow all of the recovery procedure. The binary file (version 6.2.1599.0) is loaded from the tftp server. After a couple of minutes, after launching the image, the module should restart and come up but it is staying endlessly in recover state. When I manually reboot it, it comes to unresponsive state.

Anyone got an idea?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: