Professional Documents
Culture Documents
Troubleshooting Management Interface With Classic ASA CLI
Troubleshooting Management Interface With Classic ASA CLI
interface on FTD
Standard
I had to convert a Cisco ASA 5506 to FTD the other day and baffled because no matter what I
did the management interface was admin down / down. This is a problem in FTD since you can’t
simply type a no shut and you can’t join it to a FMC without the management interface.
It looked like this from the CLI, if you haven’t seen system support diagnostic-cli before, it
gives you the classic ASA CLI back for operational commands.
firepower>
firepower> en
Password:
firepower#
firepower# sh int ip br
Interface IP-Address OK? Method Status Protocol
Virtual0 127.1.0.1 YES unset up up
GigabitEthernet1/1 unassigned YES unset administratively down down
GigabitEthernet1/2 unassigned YES unset administratively down down
GigabitEthernet1/3 unassigned YES unset administratively down down
GigabitEthernet1/4 unassigned YES unset administratively down down
GigabitEthernet1/5 unassigned YES unset administratively down down
GigabitEthernet1/6 unassigned YES unset administratively down down
GigabitEthernet1/7 unassigned YES unset administratively down down
GigabitEthernet1/8 unassigned YES unset administratively down down
Internal-Control1/1 127.0.1.1 YES unset up up
Internal-Data1/1 unassigned YES unset down up
Internal-Data1/2 unassigned YES unset down down
Internal-Data1/3 unassigned YES unset up up
Internal-Data1/4 169.254.1.1 YES unset up up
Management1/1 unassigned YES unset administratively down up
How did I fix it? Voodoo? Smash a PIX in front of it so the misbehaving ASA knows my power?
Actually the issue is the config-register has been modified on this box and FTD doesn’t like it.
We can fix it by booting into rommon, then we need to use confreg to make sure it is set to
0x00000001, apparently at some point “ignore system configuration” was enabled in my case.
> reboot
This command will reboot the system. Continue?
Please enter 'YES' or 'NO': yes
acpid.
Stopping system message bus: dbus.
Deconfiguring network interfaces... ifdown: interface br1 not configured
done.
Sending all processes the TERM signal...
Sending all processes the KILL signal...
Deactivating swap...
Unmounting local filesystems...
Rebooting...
Rom image verified correctly
You must reset or power cycle for new config to take effect
rommon 2 > reset
Resetting .......
Once the FTD came back up the management interface was happy.