Pages

Sunday, September 22, 2013

Forcing a Cisco ASA Reboot

I manage a good number of  Cisco ASA 5505 firewalls. I am currently working on one for a remote employee for a company who's network I manage. The firewall, at the time, was running 9.1(1)4. I discovered an issue with that code where the VPN process will occasionally cause the firewall to crash and become unresponsive for about 10-15 minutes. In an effort to update this firewall, which happens to be in Pennsylvania (I'm in Iowa), I uploaded the new firewall and attempted to reload the device. I type reload, hit enter twice to confirm, and nothing happens! I tried it several times with different flags, including reload quick and reload noconfirm. Nothing worked! I got so desperate I even opened ASDM and attempted to reload there, thinking it might have different hooks into the underlying OS. That failed as well. Desperate to get this firewall rebooted to fix the VPN bug (and this newly discovered reload bug, likely caused by the VPN bug), I came across the crashinfo command. To preface this, if you aren't familiar with ASAs, if they crash they dump a bunch of information to a text file on the flash drive called crash.txt. It contains a bunch of debug information, including the current memory contents and the process(es) that crashed. The crashinfo command allows you to view or save the crash info and also allows you to simulate a crash, either by doing a test or a forced crash as you can see from the output below.

asa(config)# crashinfo ?
configure mode commands/options:

console  Control output of crashinfo to the console
save     Save

exec mode commands/options:
force       Forcibly crash the system and reboot
test        Test crashinfo generation - will not crash the system

asa(config)# crashinfo force ?exec mode commands/options:
page-fault    Crash by causing a page fault exception
watchdog      Crash by causing a watchdog timeout

So to force a reload on the firewall, I was able to issue:
crashinfo force watchdog

and the firewall immediately rebooted and came up on the new firmware. I wouldn't recommend doing this unless you absolutely have to, but it did bail me out in this situation.

17 comments:

  1. Good job! Fruitful article. I like this very much. It is very useful for my research. It shows your interest in this topic very well. I hope you will post some more information about the software. Please keep sharing!!
    AWS Training in Chennai
    AWS Course in Chennai
    Selenium Training in Chennai
    Software Testing Training in Chennai
    Java Training in Chennai
    AWS Training in Anna Nagar
    AWS Training in T Nagar

    ReplyDelete
  2. This command helped me out. Thank you!

    ReplyDelete
  3. As a networking engineer you may prefer to work at a computer store or also work independently. You need to form contact with clients and companies because many small companies cannot afford to employ the entire team of networking engineer so they look for home-based networking engineer who could sort out their technical faults. CCNA course in Pune

    ReplyDelete
  4. Happy Independence Day Quotes Freedom doesn’t come back while not a price. as a result of going freelance came at the expense of uncounted lives, it ought to be maintained, loved, respected, and cherished. https://wishesquotz.com/independence-day-quotes/

    ReplyDelete
  5. Thank you for taking the time and sharing this information with us. Elevate your online presence with our handpicked dofollow classified submission sites! Discover a world of opportunity with free classified submission sites designed to boost your reach.
    visit Classified submission sites

    ReplyDelete
  6. I am glad to discover this post Very valuable for me. Unleash your linguistic potential with our personalized approach, designed to address common pain points such as tackling grammar gaffes, boosting confidence, and conquering conversation hurdles.
    For more info visit english online tuition

    ReplyDelete