Friday, November 9, 2018

Cisco ASA 5506W-X FirePOWER Module Upgrade

You can directly upgrade the ASA FirePOWER module to 6.2.3 if it's a new installation. Just make sure the ASA version is compatible with the FirePOWER module version. If the sensor is running in a production network, you need to follow the upgrade path: 5.4.1 > 6.0.0 > 6.0.1 > 6.1.0 > 6.2.3. It's advisable the Firepower Management Center (FMC) is upgraded first before sensors (ASA FirePOWER module or FTD).

Cisco made a distinction that the ASA module uses FirePOWER.The central management and Next-Generation Firewall (NGFW) are called Firepower Management Center (FMC) and Firepower Threat Defense (FTD), respectively. My ASA5506W-X had the default FirePOWER 5.4.1 image, so I uninstalled it and directly upgraded to the new 6.2.3 image.


ASA5506W-X# show version

Cisco Adaptive Security Appliance Software Version 9.8(2)38
Firepower Extensible Operating System Version 2.2(2.90)
Device Manager Version 7.9(2)152

Compiled on Tue 12-Jun-18 13:31 PDT by builders
System image file is "disk0:/asa982-38-lfbff-k8.SPA"
Config file at boot was "startup-config"

ASA5506W-X up 13 mins 52 secs

Hardware:   ASA5506W, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)
Internal ATA Compact Flash, 8000MB
BIOS Flash M25P64 @ 0xfed01000, 16384KB

Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)
                             Number of accelerators: 1

 1: Ext: GigabitEthernet1/1  : address is 0078.884b.bf63, irq 255
 2: Ext: GigabitEthernet1/2  : address is 0078.884b.bf64, irq 255
 3: Ext: GigabitEthernet1/3  : address is 0078.884b.bf65, irq 255
 4: Ext: GigabitEthernet1/4  : address is 0078.884b.bf66, irq 255
 5: Ext: GigabitEthernet1/5  : address is 0078.884b.bf67, irq 255
 6: Ext: GigabitEthernet1/6  : address is 0078.884b.bf68, irq 255
 7: Ext: GigabitEthernet1/7  : address is 0078.884b.bf69, irq 255
 8: Ext: GigabitEthernet1/8  : address is 0078.884b.bf6a, irq 255
 9: Ext: GigabitEthernet1/9  : address is 0078.884b.bf6b, irq 255
10: Int: Internal-Data1/1    : address is 0078.884b.bf62, irq 255
11: Int: Internal-Data1/2    : address is 0000.0001.0002, irq 0
12: Int: Internal-Control1/1 : address is 0000.0001.0001, irq 0
13: Int: Internal-Data1/3    : address is 0000.0001.0003, irq 0
14: Ext: Management1/1       : address is 0078.884b.bf62, irq 0
15: Int: Internal-Data1/4    : address is 0000.0100.0001, irq 0

Licensed features for this platform:
Maximum Physical Interfaces       : Unlimited      perpetual
Maximum VLANs                     : 5              perpetual
Inside Hosts                      : Unlimited      perpetual
Failover                          : Disabled       perpetual
Encryption-DES                    : Enabled        perpetual
Encryption-3DES-AES               : Enabled        perpetual
Carrier                           : Disabled       perpetual
AnyConnect Premium Peers          : 2              perpetual
AnyConnect Essentials             : Disabled       perpetual
Other VPN Peers                   : 10             perpetual
Total VPN Peers                   : 12             perpetual
AnyConnect for Mobile             : Disabled       perpetual
AnyConnect for Cisco VPN Phone    : Disabled       perpetual
Advanced Endpoint Assessment      : Disabled       perpetual
Shared License                    : Disabled       perpetual
Total TLS Proxy Sessions          : 2              perpetual
Botnet Traffic Filter             : Disabled       perpetual
Cluster                           : Disabled       perpetual

This platform has a Base license.

Serial Number: JAD20080123
Running Permanent Activation Key: 0xf319c753 0x9c0e6651 0xbc534174 0x87548123 0x04191456
Configuration register is 0x1
Image type                : Release
Key Version               : A
Configuration last modified by enable_15 at 06:09:18.709 UTC Sat Sep 1 2018

ASA5506W-X# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5506-X with FirePOWER services, WiFi, 8G ASA5506W           JAD20080123
 sfr FirePOWER Services Software Module           ASA5506W           JAD20080123
wlan WLAN AP                                      N/A                N/A       

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 0078.884b.bf62 to 0078.884b.bf6b  2.0          1.1.8        9.8(2)38
 sfr 0078.884b.bf61 to 0078.884b.bf61  N/A          N/A          5.4.1-211
wlan none                              N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 sfr ASA FirePOWER                  Up               5.4.1-211

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 sfr Up                 Up                   
wlan Up                 Up                   

ASA5506W-X# 
ASA5506W-X# show module ?  

Available module ID(s):
  0     Module ID
  all   show all module information for all slots
  sfr   Module ID
  wlan  Module ID
  |     Output modifiers
  <cr>
ASA5506W-X# show module sfr ?

  details  show detailed hardware module information
  log      show logs for this module
  recover  show recover configuration for this module
  |        Output modifiers
  <cr>
ASA5506W-X# show module sfr details
Getting details from the Service Module, please wait...

Card Type:          FirePOWER Services Software Module
Model:              ASA5506W
Hardware version:   N/A
Serial Number:      JAD20080123
Firmware version:   N/A
Software version:   5.4.1-211
MAC Address Range:  0078.884b.bf61 to 0078.884b.bf61
App. name:          ASA FirePOWER
App. Status:        Up
App. Status Desc:   Normal Operation
App. version:       5.4.1-211
Data Plane Status:  Up
Console session:    Ready
Status:             Up
DC addr:            No DC Configured                                           
Mgmt IP addr:       192.168.45.45                                              
Mgmt Network mask:  255.255.255.0                                              
Mgmt Gateway:       0.0.0.0                                                    
Mgmt web ports:     443                                                        
Mgmt TLS enabled:   true     


ASA5506W-X# copy tftp://192.168.1.10/asasfr-5500x-boot-6.2.3-4.img disk0:/asasfr-5500x-boot-6.2.3-4.img

Address or name of remote host [192.168.1.10]?

Source filename [asasfr-5500x-boot-6.2.3-4.img]?

Destination filename [asasfr-5500x-boot-6.2.3-4.img]?

Accessing tftp://192.168.1.10/asasfr-5500x-boot-6.2.3-4.img...!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Writing file disk0:/asasfr-5500x-boot-6.2.3-4.img...
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
INFO: No digital signature found
42956800 bytes copied in 44.780 secs (976290 bytes/sec)

ASA5506W-X# dir    // I DELETED OLDER ASA IMAGES TO FREE UP FLASH MEMORY SPACE

Directory of disk0:/

102    -rwx  25025404     16:06:04 Nov 08 2017  asdm-751.bin
103    -rwx  63           06:10:37 Sep 01 2018  .boot_string
11     drwx  4096         16:09:06 Nov 08 2017  log
20     drwx  4096         16:09:58 Nov 08 2017  crypto_archive
21     drwx  4096         16:10:00 Nov 08 2017  coredumpinfo
112    -rwx  42956800     06:19:49 Sep 01 2018  asasfr-5500x-boot-6.2.3-4.img
105    -rwx  3474         14:55:42 Mar 21 2018  oldconfig_2018Mar21_2241.cfg
107    -rwx  108648864    03:18:40 Aug 20 2018  asa982-38-lfbff-k8.SPA
108    -rwx  32738244     03:20:02 Aug 20 2018  asdm-792-152.bin

6 file(s) total size: 209372849 bytes
7934787584 bytes total (4502102016 bytes free/56% free)


ASA5506W-X# sw-module ?

  module  Act on a module
ASA5506W-X# sw-module module ?

Available module ID(s):
  sfr  Module ID
ASA5506W-X# sw-module module sfr ?

  recover    Configure recovery of this module
  reload     Reload the module
  reset      Reset the module
  shutdown   Shut down the module
  uninstall  Uninstall the module
ASA5506W-X# sw-module module sfr uninstall    // NO NEED TO GO THROUGH THE UPGRADE PROCEDURE (FOR NEW INSTALL/NON-PRODUCTION DEVICE)

Module sfr will be uninstalled. This will completely remove the disk image assocated with the sw-module including any configuration that existed within it.

Uninstall module sfr? [confirm] <ENTER>
Uninstall issued for module sfr.

ASA5506W-X# sw-module module sfr recover ?

  boot       Initiate recovery of this module
  configure  Configure recovery parameters for this module
  stop       Stop recovery of this module
ASA5506W-X# sw-module module sfr recover configure ?

  image  Configure image file path on disk
ASA5506W-X# sw-module module sfr recover configure image ?

  disk0:  Image File Path
  disk1:  Image File Path
  flash:  Image File Path
ASA5506W-X# sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.2.3-4.img


You can monitor the FirePOWER module upgrade process with the debug module-boot command. This process usually takes around 10 minutes.


ASA5506W-X# debug module-boot
debug module-boot  enabled at level 1

ASA5506W-X# sw-module module sfr recover boot   

Module sfr will be recovered. This may erase all configuration and all data
on that device and attempt to download/install a new image for it. This may take
several minutes.

Recover module sfr? [confirm] <ENTER>
Recover issued for module sfr.
ASA5506W-X# Mod-sfr 647> ***
Mod-sfr 648> *** EVENT: Creating the Disk Image...
Mod-sfr 649> *** TIME: 06:27:57 UTC Sep 1 2018
Mod-sfr 650> ***
Mod-sfr 651> ***
Mod-sfr 652> *** EVENT: The module is being recovered.
Mod-sfr 653> *** TIME: 06:27:57 UTC Sep 1 2018
Mod-sfr 654> ***
Mod-sfr 655> ***
Mod-sfr 656> *** EVENT: Disk Image created successfully.
Mod-sfr 657> *** TIME: 06:32:35 UTC Sep 1 2018
Mod-sfr 658> ***
Mod-sfr 659> ***
Mod-sfr 660> *** EVENT: Start Parameters: Image: /mnt/disk0/vm/vm_1.img, ISO: -cdrom /mnt/disk0
Mod-sfr 661> /asasfr-5500x-boot-6.2.3-4.img, Num CPUs: 3, RAM: 2251MB, Mgmt MAC: 00:78:88:4B:BF
Mod-sfr 662> :61, CP MAC: 00:00:00:02:00:01, HDD: -drive file=/dev/sda,cache=none,if=virtio, De
Mod-sfr 663> v D
Mod-sfr 664> ***
Mod-sfr 665> *** EVENT: Start Parameters Continued: RegEx Shared Mem: 0MB, Cmd Op: r, Shared Me
Mod-sfr 666> m Key: 8061, Shared Mem Size: 16, Log Pipe: /dev/ttyS0_vm1, Sock: /dev/ttyS1_vm1,
Mod-sfr 667> Mem-Path: -mem-path /hugepages
Mod-sfr 668> *** TIME: 06:32:35 UTC Sep 1 2018
Mod-sfr 669> ***
Mod-sfr 670> Status: Mapping host 0x2aab38000000 to VM with size 16777216
Mod-sfr 671> Warning: vlan 0 is not connected to host network
Mod-sfr 672> ISOLINUX 3.73 2009-01-25  Copyright (C) 1994-2008 H. Peter Anvin
Mod-sfr 673>                    Cisco SFR-BOOT-IMAGE and CX-BOOT-IMAGE for SFR - 6.2.3
Mod-sfr 674>     (WARNING: ALL DATA ON DISK 1 WILL BE LOST)
Mod-sfr 675> Loading bzImage.............................................................
Mod-sfr 676> Loading initramfs.gz..............................................................
Mod-sfr 677> ..................................................................................
Mod-sfr 678> ..................................................................................
Mod-sfr 679> ..................................................................................
Mod-sfr 680> ..................................................................................
Mod-sfr 681> ..................................................................................
Mod-sfr 682> ..................................................................................
Mod-sfr 683> ........................................ready.
Mod-sfr 684> [    0.000000] Initializing cgroup subsys cpuset
Mod-sfr 685> [    0.000000] Initializing cgroup subsys cpu
Mod-sfr 686> [    0.000000] Initializing cgroup subsys cpuacct
Mod-sfr 687> [    0.000000] Linux version 3.10.107sf.cisco-1 (build@1fd5cd658885) (gcc version
Mod-sfr 688> 4.7.1 (GCC) ) #1 SMP PREEMPT Fri Nov 10 17:06:45 UTC 2017
Mod-sfr 689> [    0.000000] Command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IMAGE=bzI
Mod-sfr 690> mage
Mod-sfr 691> [    0.000000] e820: BIOS-provided physical RAM map:
Mod-sfr 692> [    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
Mod-sfr 693> [    0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
Mod-sfr 694> [    0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
Mod-sfr 695> [    0.000000] BIOS-e820: [mem 0x0000000000100000-0x000000008cafdfff] usable
Mod-sfr 696> [    0.000000] BIOS-e820: [mem 0x000000008cafe000-0x000000008cafffff] reserved
Mod-sfr 697> [    0.000000] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved
Mod-sfr 698> [    0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved
Mod-sfr 699> [    0.000000] NX (Execute Disable) protection: active
Mod-sfr 700> [    0.000000] SMBIOS 2.4 present.
Mod-sfr 701> [    0.000000] Hypervisor detected: KVM
Mod-sfr 702> [    0.000000] No AGP bridge found
Mod-sfr 703> [    0.000000] e820: last_pfn = 0x8cafe max_arch_pfn = 0x400000000
Mod-sfr 704> [    0.000000] PAT not supported by CPU.
Mod-sfr 705> [    0.000000] found SMP MP-table at [mem 0x000fdac0-0x000fdacf] mapped at [ffff88
Mod-sfr 706> 00000fdac0]
Mod-sfr 707> [    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
Mod-sfr 708> [    0.000000] init_memory_mapping: [mem 0x8c800000-0x8c9fffff]
Mod-sfr 709> [    0.000000] init_memory_mapping: [mem 0x8c000000-0x8c7fffff]
Mod-sfr 710> [    0.000000] init_memory_mapping: [mem 0x80000000-0x8bffffff]
Mod-sfr 711> [    0.000000] init_memory_mapping: [mem 0x00100000-0x7fffffff]
Mod-sfr 712> [    0.000000] init_memory_mapping: [mem 0x8ca00000-0x8cafdfff]
Mod-sfr 713> [    0.000000] RAMDISK: [mem 0x7db0b000-0x7fffffff]
Mod-sfr 714> [    0.000000] ACPI: RSDP 0x00000000000FD900 00014 (v00 BOCHS )
Mod-sfr 715> [    0.000000] ACPI: RSDT 0x000000008CAFE3E0 00034 (v01 BOCHS  BXPCRSDT 00000001 B
Mod-sfr 716> XPC 00000001)
Mod-sfr 717> [    0.000000] ACPI: FACP 0x000000008CAFFF80 00074 (v01 BOCHS  BXPCFACP 00000001 B
Mod-sfr 718> XPC 00000001)
Mod-sfr 719> [    0.000000] ACPI: DSDT 0x000000008CAFE420 011A9 (v01 BXPC   BXDSDT   00000001 I
Mod-sfr 720> NTL 20100528)
Mod-sfr 721> [    0.000000] ACPI: FACS 0x000000008CAFFF40 00040
Mod-sfr 722> [    0.000000] ACPI: SSDT 0x000000008CAFF740 007F7 (v01 BOCHS  BXPCSSDT 00000001 B
Mod-sfr 723> XPC 00000001)
Mod-sfr 724> [    0.000000] ACPI: APIC 0x000000008CAFF610 00088 (v01 BOCHS  BXPCAPIC 00000001 B
Mod-sfr 725> XPC 00000001)
Mod-sfr 726> [    0.000000] ACPI: HPET 0x000000008CAFF5D0 00038 (v01 BOCHS  BXPCHPET 00000001 B
Mod-sfr 727> XPC 00000001)
Mod-sfr 728> [    0.000000] No NUMA configuration found
Mod-sfr 729> [    0.000000] Faking a node at [mem 0x0000000000000000-0x000000008cafdfff]
Mod-sfr 730> [    0.000000] Initmem setup node 0 [mem 0x00000000-0x8cafdfff]
Mod-sfr 731> [    0.000000]   NODE_DATA [mem 0x8cafa000-0x8cafdfff]
Mod-sfr 732> [    0.000000] kvm-clock: Using msrs 4b564d01 and 4b564d00
Mod-sfr 733> [    0.000000] kvm-clock: cpu 0, msr 0:8caf9001, boot clock
Mod-sfr 734> [    0.000000] Zone ranges:
Mod-sfr 735> [    0.000000]   DMA      [mem 0x00001000-0x00ffffff]
Mod-sfr 736> [    0.000000]   DMA32    [mem 0x01000000-0xffffffff]
Mod-sfr 737> [    0.000000]   Normal   empty
Mod-sfr 738> [    0.000000] Movable zone start for each node
Mod-sfr 739> [    0.000000] Early memory node ranges
Mod-sfr 740> [    0.000000]   node   0: [mem 0x00001000-0x0009efff]
Mod-sfr 741> [    0.000000]   node   0: [mem 0x00100000-0x8cafdfff]
Mod-sfr 742> [    0.000000] ACPI: PM-Timer IO Port: 0xb008
Mod-sfr 743> [    0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
Mod-sfr 744> [    0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)
Mod-sfr 745> [    0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)
Mod-sfr 746> [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
Mod-sfr 747> [    0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
Mod-sfr 748> [    0.000000] IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23
Mod-sfr 749> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
Mod-sfr 750> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
Mod-sfr 751> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Mod-sfr 752> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
Mod-sfr 753> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
Mod-sfr 754> [    0.000000] Using ACPI (MADT) for SMP configuration information
Mod-sfr 755> [    0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000
Mod-sfr 756> [    0.000000] smpboot: Allowing 3 CPUs, 0 hotplug CPUs
Mod-sfr 757> [    0.000000] e820: [mem 0x8cb00000-0xfeffbfff] available for PCI devices
Mod-sfr 758> [    0.000000] Booting paravirtualized kernel on KVM
Mod-sfr 759> [    0.000000] setup_percpu: NR_CPUS:64 nr_cpumask_bits:64 nr_cpu_ids:3 nr_node_id
Mod-sfr 760> s:1
Mod-sfr 761> [    0.000000] PERCPU: Embedded 24 pages/cpu @ffff88008c600000 s68672 r8192 d21440
Mod-sfr 762>  u524288
Mod-sfr 763> [    0.000000] kvm-clock: cpu 0, msr 0:8caf9001, primary cpu clock
Mod-sfr 764> [    0.000000] KVM setup async PF for cpu 0
Mod-sfr 765> [    0.000000] kvm-stealtime: cpu 0, msr 8c60ba40
Mod-sfr 766> [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages
Mod-sfr 767> : 568256
Mod-sfr 768> [    0.000000] Policy zone: DMA32
Mod-sfr 769> [    0.000000] Kernel command line: initrd=initramfs.gz console=ttyS0,9600 BOOT_IM
Mod-sfr 770> AGE=bzImage
Mod-sfr 771> [    0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
Mod-sfr 772> [    0.000000] Checking aperture...
Mod-sfr 773> [    0.000000] No AGP bridge found
Mod-sfr 774> [    0.000000] Memory: 2224736k/2305016k available (4805k kernel code, 392k absent
Mod-sfr 775> , 79888k reserved, 2414k data, 896k init)
Mod-sfr 776> [    0.000000] Preemptible hierarchical RCU implementation.
Mod-sfr 777> [    0.000000]     RCU restricting CPUs from NR_CPUS=64 to nr_cpu_ids=3.
Mod-sfr 778> [    0.000000] NR_IRQS:4352 nr_irqs:704 16
Mod-sfr 779> [    0.000000] Console: colour VGA+ 80x25
Mod-sfr 780> [    0.000000] console [ttyS0] enabled
Mod-sfr 781> [    0.000000] allocated 9437184 bytes of page_cgroup
Mod-sfr 782> [    0.000000] please try 'cgroup_disable=memory' option if you don't want memory
Mod-sfr 783> cgroups
Mod-sfr 784> [    0.000000] tsc: Detected 1249.999 MHz processor
Mod-sfr 785> [    0.003000] Calibrating delay loop (skipped) preset value.. 2499.99 BogoMIPS (l
Mod-sfr 786> pj=1249999)
Mod-sfr 787> [    0.004018] pid_max: default: 32768 minimum: 301
Mod-sfr 788> [    0.005144] Security Framework initialized
Mod-sfr 789> [    0.008835] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
Mod-sfr 790> [    0.015037] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
Mod-sfr 791> [    0.018314] Mount-cache hash table entries: 256
Mod-sfr 792> [    0.020467] Initializing cgroup subsys memory
Mod-sfr 793> [    0.022247] Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0
Mod-sfr 794> [    0.022247] Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0
Mod-sfr 795> [    0.022247] tlb_flushall_shift: 6
Mod-sfr 796> [    0.024026] Freeing SMP alternatives: 12k freed
Mod-sfr 797> [    0.028570] ACPI: Core revision 20130328
Mod-sfr 798> [    0.034223] ACPI: All ACPI Tables successfully acquired
Mod-sfr 799> [    0.041604] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
Mod-sfr 800> [    0.042009] smpboot: CPU0: Intel QEMU Virtual CPU version 1.5.0 (fam: 06, model
Mod-sfr 801> : 02, stepping: 03)
Mod-sfr 802> [    0.047000] Performance Events: unsupported p6 CPU model 2 no PMU driver, softw
Mod-sfr 803> are events only.
Mod-sfr 804> [    0.056294] smpboot: Booting Node   0, Processors  #1[    0.003000] kvm-clock:
Mod-sfr 805> cpu 1, msr 0:8caf9041, secondary cpu clock
Mod-sfr 806> [    0.073092] KVM setup async PF for cpu 1
Mod-sfr 807>  #2 OK
Mod-sfr 808> [    0.073092] kvm-stealtime: cpu 1, msr 8c68ba40
Mod-sfr 809> [    0.003000] kvm-clock: cpu 2, msr 0:8caf9081, secondary cpu clock
Mod-sfr 810> [    0.092193] Brought up 3 CPUs
Mod-sfr 811> [    0.092096] KVM setup async PF for cpu 2
Mod-sfr 812> [    0.092096] kvm-stealtime: cpu 2, msr 8c70ba40
Mod-sfr 813> [    0.093011] smpboot: Total of 3 processors activated (7499.99 BogoMIPS)
Mod-sfr 814> [    0.096860] devtmpfs: initialized
Mod-sfr 815> [    0.100215] NET: Registered protocol family 16
Mod-sfr 816> [    0.104760] ACPI: bus type PCI registered
Mod-sfr 817> [    0.107325] PCI: Using configuration type 1 for base access
Mod-sfr 818> [    0.159786] bio: create slab <bio-0> at 0
Mod-sfr 819> [    0.163597] ACPI: Added _OSI(Module Device)
Mod-sfr 820> [    0.165013] ACPI: Added _OSI(Processor Device)
Mod-sfr 821> [    0.166014] ACPI: Added _OSI(3.0 _SCP Extensions)
Mod-sfr 822> [    0.167000] ACPI: Added _OSI(Processor Aggregator Device)
Mod-sfr 823> [    0.174691] ACPI: Interpreter enabled
Mod-sfr 824> [    0.177025] ACPI: (supports S0 S5)
Mod-sfr 825> [    0.178000] ACPI: Using IOAPIC for interrupt routing
Mod-sfr 826> [    0.181426] PCI: Using host bridge windows from ACPI; if necessary, use "pci=no
Mod-sfr 827> crs" and report a bug
Mod-sfr 828> [    0.186310] ACPI: No dock devices found.
Mod-sfr 829> [    0.212805] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff])
Mod-sfr 830> [    0.216025] acpi PNP0A03:00: ACPI _OSC support notification failed, disabling P
Mod-sfr 831> CIe ASPM
Mod-sfr 832> [    0.217000] acpi PNP0A03:00: Unable to request _OSC control (_OSC support mask:
Mod-sfr 833>  0x08)
Mod-sfr 834> [    0.217000] acpi PNP0A03:00: fail to add MMCONFIG information, can't access ext
Mod-sfr 835> ended PCI configuration space under this bridge.
Mod-sfr 836> [    0.229254] PCI host bridge to bus 0000:00
Mod-sfr 837> [    0.231016] pci_bus 0000:00: root bus resource [bus 00-ff]
Mod-sfr 838> [    0.232000] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7]
Mod-sfr 839> [    0.232000] pci_bus 0000:00: root bus resource [io  0x0d00-0xffff]
Mod-sfr 840> [    0.232000] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff]
Mod-sfr 841> [    0.242014] pci_bus 0000:00: root bus resource [mem 0xc0000000-0xfebfffff]
Mod-sfr 842> [    0.263856] pci 0000:00:01.3: quirk: [io  0xb000-0xb03f] claimed by PIIX4 ACPI
Mod-sfr 843> [    0.268051] pci 0000:00:01.3: quirk: [io  0xb100-0xb10f] claimed by PIIX4 SMB
Mod-sfr 844> [    0.428839] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
Mod-sfr 845> [    0.431316] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
Mod-sfr 846> [    0.435000] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
Mod-sfr 847> [    0.435000] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
Mod-sfr 848> [    0.441069] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
Mod-sfr 849> [    0.445139] ACPI: Enabled 16 GPEs in block 00 to 0F
Mod-sfr 850> [    0.449505] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,l
Mod-sfr 851> ocks=none
Mod-sfr 852> [    0.453013] vgaarb: loaded
Mod-sfr 853> [    0.454000] vgaarb: bridge control possible 0000:00:02.0
Mod-sfr 854> [    0.458110] SCSI subsystem initialized
Mod-sfr 855> [    0.459012] ACPI: bus type ATA registered
Mod-sfr 856> [    0.463290] ACPI: bus type USB registered
Mod-sfr 857> [    0.465641] usbcore: registered new interface driver usbfs
Mod-sfr 858> [    0.468070] usbcore: registered new interface driver hub
Mod-sfr 859> [    0.471213] usbcore: registered new device driver usb
Mod-sfr 860> [    0.474316] pps_core: LinuxPPS API ver. 1 registered
Mod-sfr 861> [    0.476015] pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giomett
Mod-sfr 862> i <giometti@linux.it>
Mod-sfr 863> [    0.481063] PTP clock support registered
Mod-sfr 864> [    0.483429] PCI: Using ACPI for IRQ routing
Mod-sfr 865> [    0.486912] NetLabel: Initializing
Mod-sfr 866> [    0.488048] NetLabel:  domain hash size = 128
Mod-sfr 867> [    0.490008] NetLabel:  protocols = UNLABELED CIPSOv4
Mod-sfr 868> [    0.491000] NetLabel:  unlabeled traffic allowed by default
Mod-sfr 869> [    0.491000] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
Mod-sfr 870> [    0.491000] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
Mod-sfr 871> [    0.501520] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
Mod-sfr 872> [    0.509592] amd_nb: Cannot enumerate AMD northbridges
Mod-sfr 873> [    0.512010] Switching to clocksource kvm-clock
Mod-sfr 874> [    0.514602] pnp: PnP ACPI init
Mod-sfr 875> [    0.516017] ACPI: bus type PNP registered
Mod-sfr 876> [    0.521946] pnp: PnP ACPI: found 8 devices
Mod-sfr 877> [    0.523892] ACPI: bus type PNP unregistered
Mod-sfr 878> [    0.564829] NET: Registered protocol family 2
Mod-sfr 879> [    0.568197] TCP established hash table entries: 32768 (order: 7, 524288 bytes)
Mod-sfr 880> [    0.572008] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
Mod-sfr 881> [    0.575412] TCP: Hash tables configured (established 32768 bind 32768)
Mod-sfr 882> [    0.578589] TCP: reno registered
Mod-sfr 883> [    0.580203] UDP hash table entries: 2048 (order: 4, 65536 bytes)
Mod-sfr 884> [    0.583104] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
Mod-sfr 885> [    0.586458] NET: Registered protocol family 1
Mod-sfr 886> [    0.589200] RPC: Registered named UNIX socket transport module.
Mod-sfr 887> [    0.591989] RPC: Registered udp transport module.
Mod-sfr 888> [    0.594227] RPC: Registered tcp transport module.
Mod-sfr 889> [    0.596443] RPC: Registered tcp NFSv4.1 backchannel transport module.
Mod-sfr 890> [    0.599503] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
Mod-sfr 891> [    0.602301] pci 0000:00:01.0: PIIX3: Enabling Passive Release
Mod-sfr 892> [    0.605098] pci 0000:00:01.0: Activating ISA DMA hang workarounds
Mod-sfr 893> [    0.608476] Trying to unpack rootfs image as initramfs...
Mod-sfr 894> [    2.857834] Freeing initrd memory: 37844k freed
Mod-sfr 895> [    2.884144] microcode: CPU0 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 896> [    2.886886] microcode: CPU1 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 897> [    2.889575] microcode: CPU2 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 898> [    2.892591] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co
Mod-sfr 899> .uk>, Peter Oruba
Mod-sfr 900> [    2.899780] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mod-sfr 901> [    2.903801] VFS: Disk quotas dquot_6.5.2
Mod-sfr 902> [    2.905838] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mod-sfr 903> [    2.910607] NFS: Registering the id_resolver key type
Mod-sfr 904> [    2.913229] Key type id_resolver registered
Mod-sfr 905> [    2.915226] Key type id_legacy registered
Mod-sfr 906> [    2.917664] msgmni has been set to 4419
Mod-sfr 907> [    2.922242] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251
Mod-sfr 908> [    2.925710] io scheduler noop registered
Mod-sfr 909> [    2.927629] io scheduler deadline registered
Mod-sfr 910> [    2.929808] io scheduler cfq registered (default)
Mod-sfr 911> [    2.935443] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input
Mod-sfr 912> [    2.939102] ACPI: Power Button [PWRF]
Mod-sfr 913> [    2.950485] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
Mod-sfr 914> [    2.956951] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
Mod-sfr 915> [    2.964063] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 11
Mod-sfr 916> [    2.973189] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
Mod-sfr 917> [    3.004230] 00:05: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
Mod-sfr 918> [    3.035402] 00:06: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
Mod-sfr 919> [    3.042476] Non-volatile memory driver v1.3
Mod-sfr 920> [    3.044549] Linux agpgart interface v0.103
Mod-sfr 921> [    3.048095] [drm] Initialized drm 1.1.0 20060810
Mod-sfr 922> [    3.051791] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M
Mod-sfr 923> [    3.064832] brd: module loaded
Mod-sfr 924> [    3.068810] FDC 0 is a S82078B
Mod-sfr 925> [    3.074996] loop: module loaded
Mod-sfr 926> [    3.083322]  vda: vda1 vda2 vda3 < vda5 vda6 vda7 >
Mod-sfr 927> [    3.092446] Loading iSCSI transport class v2.0-870.
Mod-sfr 928> [    3.104364] scsi0 : ata_piix
Mod-sfr 929> [    3.106603] scsi1 : ata_piix
Mod-sfr 930> [    3.108456] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14
Mod-sfr 931> [    3.111602] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15
Mod-sfr 932> [    3.115162] e100: Intel(R) PRO/100 Network Driver, 3.5.24-k2-NAPI
Mod-sfr 933> [    3.118259] e100: Copyright(c) 1999-2006 Intel Corporation
Mod-sfr 934> [    3.121079] igb: Intel(R) Gigabit Ethernet Network Driver - version 5.0.3-k
Mod-sfr 935> [    3.124277] igb: Copyright (c) 2007-2013 Intel Corporation.
Mod-sfr 936> [    3.127138] Fusion MPT base driver 3.04.20
Mod-sfr 937> [    3.129064] Copyright (c) 1999-2008 LSI Corporation
Mod-sfr 938> [    3.131360] Fusion MPT SPI Host driver 3.04.20
Mod-sfr 939> [    3.133687] Fusion MPT FC Host driver 3.04.20
Mod-sfr 940> [    3.135971] Fusion MPT SAS Host driver 3.04.20
Mod-sfr 941> [    3.138904] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mod-sfr 942> [    3.141943] ehci-pci: EHCI PCI platform driver
Mod-sfr 943> [    3.144293] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mod-sfr 944> [    3.147370] uhci_hcd: USB Universal Host Controller Interface driver
Mod-sfr 945> [    3.150811] usbcore: registered new interface driver usblp
Mod-sfr 946> [    3.153607] usbcore: registered new interface driver usb-storage
Mod-sfr 947> [    3.156830] i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64
Mod-sfr 948> irq 1,12
Mod-sfr 949> [    3.162919] serio: i8042 KBD port at 0x60,0x64 irq 1
Mod-sfr 950> [    3.165396] serio: i8042 AUX port at 0x60,0x64 irq 12
Mod-sfr 951> [    3.168546] mousedev: PS/2 mouse device common for all mice
Mod-sfr 952> [    3.173387] rtc_cmos 00:00: RTC can wake from S4
Mod-sfr 953> [    3.175578] input: AT Translated Set 2 keyboard as /devices/platform/i8042/seri
Mod-sfr 954> o0/input/input1
Mod-sfr 955> [    3.177849] rtc_cmos 00:00: rtc core: registered rtc_cmos as rtc0
Mod-sfr 956> [    3.178498] rtc_cmos 00:00: alarms up to one day, 114 bytes nvram, hpet irqs
Mod-sfr 957> [    3.178939] i2c /dev entries driver
Mod-sfr 958> [    3.179625] md: raid1 personality registered for level 1
Mod-sfr 959> [    3.190816] device-mapper: ioctl: 4.24.0-ioctl (2013-01-15) initialised: dm-dev
Mod-sfr 960> el@redhat.com
Mod-sfr 961> [    3.195262] cpuidle: using governor ladder
Mod-sfr 962> [    3.198377] hidraw: raw HID events driver (C) Jiri Kosina
Mod-sfr 963> [    3.211611] usbcore: registered new interface driver usbhid
Mod-sfr 964> [    3.214253] usbhid: USB HID core driver
Mod-sfr 965> [    3.216313] ipip: IPv4 over IPv4 tunneling driver
Mod-sfr 966> [    3.219922] TCP: cubic registered
Mod-sfr 967> [    3.221697] Initializing XFRM netlink socket
Mod-sfr 968> [    3.224141] NET: Registered protocol family 10
Mod-sfr 969> [    3.227215] NET: Registered protocol family 17
Mod-sfr 970> [    3.229475] Key type dns_resolver registered
Mod-sfr 971> [    3.232677] registered taskstats version 1
Mod-sfr 972> [    3.235910] console [netcon0] enabled
Mod-sfr 973> [    3.237703] netconsole: network logging started
Mod-sfr 974> [    3.269427] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100
Mod-sfr 975> [    3.272237] ata1.00: 6291456 sectors, multi 16: LBA48
Mod-sfr 976> [    3.275931] ata1.00: configured for MWDMA2
Mod-sfr 977> [    3.277977] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100
Mod-sfr 978> [    3.278231] scsi 0:0:0:0: Direct-Access     ATA      QEMU HARDDISK    1.5. PQ:
Mod-sfr 979> 0 ANSI: 5
Mod-sfr 980> [    3.285821] ata2.00: configured for MWDMA2
Mod-sfr 981> [    3.289356] sd 0:0:0:0: [sda] 6291456 512-byte logical blocks: (3.22 GB/3.00 Gi
Mod-sfr 982> B)
Mod-sfr 983> [    3.293265] sd 0:0:0:0: [sda] Write Protect is off
Mod-sfr 984> [    3.293381] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mod-sfr 985> [    3.298158] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'
Mod-sfr 986> t support DPO or FUA
Mod-sfr 987> [    3.302758] scsi 1:0:0:0: CD-ROM            QEMU     QEMU DVD-ROM     1.5. PQ:
Mod-sfr 988> 0 ANSI: 5
Mod-sfr 989> [    3.308911]  sda: unknown partition table
Mod-sfr 990> [    3.308917] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
Mod-sfr 991> [    3.308923] cdrom: Uniform CD-ROM driver Revision: 3.20
Mod-sfr 992> [    3.317082] sd 0:0:0:0: [sda] Attached SCSI disk
Mod-sfr 993> [    3.317460] sr 1:0:0:0: Attached scsi generic sg1 type 5
Mod-sfr 994> [    3.322428] Freeing unused kernel memory: 896k freed
Mod-sfr 995> INIT: version 2.86 booting
Mod-sfr 996> Please wait: booting...
Mod-sfr 997> mount: sysfs already mounted or /sys busy
Mod-sfr 998> mount: according to mtab, sysfs is already mounted on /sys
Mod-sfr 999> Starting udev [    3.617005] udevd (765): /proc/765/oom_adj is deprecated, please
Mod-sfr 0> use /proc/765/oom_score_adj instead.
Mod-sfr 1> [    3.621417] udevd version 124 started
Mod-sfr 2> [    3.815985] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/ser
Mod-sfr 3> io1/input/input2
Mod-sfr 4> [    3.881597] tsc: Refined TSC clocksource calibration: 1250.001 MHz
Mod-sfr 5> [    4.592126] end_request: I/O error, dev fd0, sector 0
Mod-sfr 6> [    4.677125] end_request: I/O error, dev fd0, sector 0
Mod-sfr 7> and populating dev cache
Mod-sfr 8> Root filesystem already rw, not remounting
Mod-sfr 9> Configuring network interfaces... done.
Mod-sfr 10> net.ipv4.conf.default.rp_filter = 1
Mod-sfr 11> net.ipv4.conf.all.rp_filter = 1
Mod-sfr 12> Configuring kvm-ivshmem
Mod-sfr 13> Configuring busybox-syslog
Mod-sfr 14>  System startup links for /etc/init.d/sysklogd already exist.
Mod-sfr 15> Configuring openssh-sshd
Mod-sfr 16>  Adding system startup for /etc/init.d/sshd.
Mod-sfr 17> Configuring sudo
Mod-sfr 18> Configuring ntpdate
Mod-sfr 19> adding crontab
Mod-sfr 20> Configuring update-modules
Mod-sfr 21> INIT: Entering runlevel: 5
Mod-sfr 22> Starting OpenBSD Secure Shell server: sshd
Mod-sfr 23>   generating ssh RSA key...
Mod-sfr 24>   generating ssh DSA key...
Mod-sfr 25> done.
Mod-sfr 26> Starting Advanced Configuration and Power Interface daemon: acpid.
Mod-sfr 27> acpid: starting up with proc fs
Mod-sfr 28> acpid: opendir(/etc/acpi/events): No such file or directory
Mod-sfr 29> starting Busybox inetd: inetd... done.
Mod-sfr 30> Starting ntpd: done
Mod-sfr 31> Starting syslogd/klogd: done
Mod-sfr 32>
Cisco FirePOWER Services Boot Image 6.2.3    


Just unshut Management 1/1 interface and leave the default settings. Don't assign the interface with an IP address.

ASA5506W-X# show run interface management1/1
!
interface Management1/1
 management-only
 shutdown
 no nameif
 no security-level
 no ip address
ASA5506W-X#          
ASA5506W-X# configure terminal
ASA5506W-X(config)# interface Management1/1
ASA5506W-X(config-if)# no shutdown
ASA5506W-X(config-if)# end


You can access the CLI of the FirePower module using the session sfr console. Use the default login: admin / Admin123. Temporarily configure the FirePower module with an IP address to be the same with the inside interface. You'll reconfigure again the FirePower module after the package installation (1 GB+ file).

ASA5506W-X# session ?

Available module ID(s):
  sfr   Module ID
  wlan  Module ID
ASA5506W-X# session sfr ?

  console  Login to console port on another module.
  do       Execute a command on another module.
  ip       Configure Module logging port ip addresses
  <cr>
ASA5506W-X# session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.
Cisco FirePOWER Services Boot Image 6.2.3

asasfr login: admin
Password: <Admin123>


            Cisco FirePOWER Services Boot 6.2.3 (4)
                  Type ? for list of commands
asasfr-boot>setup


                 Welcome to Cisco FirePOWER Services Setup
                          [hit Ctrl-C to abort]
                        Default values are inside []

Enter a hostname [asasfr]:     // JUST HIT ENTER TO ACCEPT DEFAULT
asasfr
Do you want to configure IPv4 address on management interface?(y/n) [Y]:
Y
Do you want to enable DHCP for IPv4 address assignment on management interface?(y/n) [N]:
N
Enter an IPv4 address [192.168.8.8]: 192.168.1.2
Enter the netmask [255.255.255.0]:
255.255.255.0
Enter the gateway [192.168.8.1]: 192.168.1.1
Need a valid IPv4 address, please enter again.
Enter the gateway [192.168.8.1]: 192.168.1.1
Do you want to configure static IPv6 address on management interface?(y/n) [N]:
N
Stateless autoconfiguration will be enabled for IPv6 addresses.
Enter the primary DNS server IP address: 8.8.8.8
Do you want to configure Secondary DNS Server? (y/n) [n]:
n
Do you want to configure Local Domain Name? (y/n) [n]:
n
Do you want to configure Search domains? (y/n) [n]:
n
Do you want to enable the NTP service? [Y]: n
Please review the final configuration:
Hostname:               asasfr
Management Interface Configuration

IPv4 Configuration:     static
        IP Address:     192.168.1.2
        Netmask:        255.255.255.0
        Gateway:        192.168.1.1

IPv6 Configuration:     Stateless autoconfiguration

DNS Configuration:
        DNS Server:
                        8.8.8.8

NTP configuration:      Disabled

CAUTION:
You have selected IPv6 stateless autoconfiguration, which assigns a global address
based on network prefix and a device identifier. Although this address is unlikely
to change, if it does change, the system will stop functioning correctly.
We suggest you use static addressing instead.


Apply the changes?(y,n) [Y]:
Y
Configuration saved successfully!
Applying...
Restarting network services...
Done.
Press ENTER to continue...

asasfr-boot>ping 192.168.1.1       // INSIDE INTERFACE DEFAULT GATEWAY
PING 192.168.1.1 (192.168.1.1): 56 data bytes
64 bytes from 192.168.1.1: seq=0 ttl=255 time=1.544 ms
64 bytes from 192.168.1.1: seq=1 ttl=255 time=0.882 ms
64 bytes from 192.168.1.1: seq=2 ttl=255 time=1.012 ms
64 bytes from 192.168.1.1: seq=3 ttl=255 time=0.864 ms

--- 192.168.1.1 ping statistics ---
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 0.864/1.075/1.544 ms

asasfr-boot>ping 192.168.1.10    // TFTP/FTP SERVER
PING 192.168.1.10 (192.168.1.10): 56 data bytes
64 bytes from 192.168.1.10: seq=0 ttl=128 time=3.331 ms
64 bytes from 192.168.1.10: seq=1 ttl=128 time=1.383 ms
64 bytes from 192.168.1.10: seq=2 ttl=128 time=1.251 ms
64 bytes from 192.168.1.10: seq=3 ttl=128 time=1.145 ms

--- 192.168.1.10 ping statistics ---

4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 1.145/1.777/3.331 ms


You'll need to FTP the .pkg file since it's a very large file (1 GB+). This is a lengthy process and usually takes around 30 mins to an hour. My upgrade completed around 1.5 hours so you'll have to be VERY patient.

asasfr-boot>system install ftp://ftp:ftp123@192.168.1.10/asasfr-sys-6.2.3-83.pkg
Mod-sfr 33> asasfr login: [  805.681772]  vda: vda1
Mod-sfr 34> [  809.699738] Adding 4194756k swap on /dev/vda1.  Priority:-1 extents:1 across:419
Mod-sfr 35> 4756k
Verifying    
Downloading.... 
Extracting....


Escape Sequence detected   // YOU CAN USE ESCAPE SEQUENCE: CTRL+SHIFT+6+x
Console session with module sfr terminated.

ASA5506W-X# show module

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5506-X with FirePOWER services, WiFi, 8G ASA5506W           JAD20080123
 sfr Unknown                                      N/A                JAD20080123
wlan WLAN AP                                      N/A                N/A       

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 0078.884b.bf62 to 0078.884b.bf6b  2.0          1.1.8        9.8(2)38
 sfr 0078.884b.bf61 to 0078.884b.bf61  N/A          N/A         
wlan none                              N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 sfr Recover            Not Applicable       
wlan Up                 Up           

ASA5506W-X# show module sfr details
Getting details from the Service Module, please wait...
Unable to read details from module sfr

Card Type:          Unknown
Model:              N/A
Hardware version:   N/A
Serial Number:      JAD20080123
Firmware version:   N/A
Software version:  
MAC Address Range:  0078.884b.bf61 to 0078.884b.bf61
Data Plane Status:  Not Applicable
Console session:    Ready
Status:             Recover


ASA5506W-X# Mod-sfr 36> [ 2312.788211]  sda: unknown partition table
Mod-sfr 37> [ 2315.793574]  sda: sda1 sda2
Mod-sfr 38> [ 2336.098409] kjournald starting.  Commit interval 5 seconds
Mod-sfr 39> [ 2336.101196] EXT3-fs (sda2): using internal journal
Mod-sfr 40> [ 2336.103513] EXT3-fs (sda2): mounted filesystem with writeback data mode
Mod-sfr 41> [ 2388.711247] hrtimer: interrupt took 2679518 ns
Mod-sfr 42> [ 2462.181077] kjournald starting.  Commit interval 5 seconds
Mod-sfr 43> [ 2462.181408] EXT3-fs (vda5): using internal journal
Mod-sfr 44> [ 2462.181413] EXT3-fs (vda5): mounted filesystem with ordered data mode
Mod-sfr 45> [ 2462.286675] kjournald starting.  Commit interval 5 seconds
Mod-sfr 46> [ 2462.289676] EXT3-fs (sda1): using internal journal
Mod-sfr 47> [ 2462.292071] EXT3-fs (sda1): mounted filesystem with ordered data mode
Mod-sfr 48> [ 2462.393570] kjournald starting.  Commit interval 5 seconds
Mod-sfr 49> [ 2462.394082] EXT3-fs (vda7): using internal journal
Mod-sfr 50> [ 2462.394087] EXT3-fs (vda7): mounted filesystem with ordered data mode
Mod-sfr 51> [ 2590.976119] end_request: I/O error, dev fd0, sector 0
Mod-sfr 52> [ 2595.343117] end_request: I/O error, dev fd0, sector 0
Mod-sfr 53> [ 2648.466117] end_request: I/O error, dev fd0, sector 0
Mod-sfr 54> INIT: Switching to runlevel: 6
Mod-sfr 55> INIT: Sending processeStopping OpenBSD Secure Shell server: sshdstopped /usr/sbin/s
Mod-sfr 56> shd (pid 2126)
Mod-sfr 57> .
Mod-sfr 58> Stopping Advanced Configuration and Power Interface daemon: no /usr/sbin/acpid foun
Mod-sfr 59> d; none killed
Mod-sfr 60> stopping Busybox inetd: inetd... stopped inetd (pid 2134)
Mod-sfr 61> done.
Mod-sfr 62> Stopping ntpd: start-stop-daemon: warning: killing process 0: No such process
Mod-sfr 63> done
Mod-sfr 64> Stopping syslogd/klogd: done
Mod-sfr 65> Deconfiguring network interfaces... done.
Mod-sfr 66> Sending all processes the TERM signal...
Mod-sfr 67> Sending all processes the KILL signal...
Mod-sfr 68> Unmounting remote filesystems...
Mod-sfr 69> Deactivating swap...
Mod-sfr 70> Unmounting local filesystems...
Mod-sfr 71> umount2: Device or resource busy
Mod-sfr 72> umount: none busy - remounted read-only
Mod-sfr 73> Rebooting... [ 2685.046404] Unregister pv shared memory for cpu 1
Mod-sfr 74> [ 2685.046409] Unregister pv shared memory for cpu 2
Mod-sfr 75> [ 2685.050836] Unregister pv shared memory for cpu 0
Mod-sfr 76> [ 2685.053491] sd 0:0:0:0: [sda] Synchronizing SCSI cache
Mod-sfr 77> [ 2685.058912] Restarting system.
Mod-sfr 78> [ 2685.060405] reboot: machine restart
Mod-sfr 79> ***
Mod-sfr 80> *** EVENT: The module is being automatically restarted.
Mod-sfr 81> *** TIME: 07:17:32 UTC Sep 1 2018
Mod-sfr 82> ***
Mod-sfr 83> ***
Mod-sfr 84> *** EVENT: Start Parameters: Image: /mnt/disk0/vm/vm_1.img, ISO: , Num CPUs: 3, RAM
Mod-sfr 85> : 2251MB, Mgmt MAC: 00:78:88:4B:BF:61, CP MAC: 00:00:00:02:00:01, HDD: -drive file=
Mod-sfr 86> /dev/sda,cache=none,if=virtio, Dev Driver: virtio
Mod-sfr 87> *** TIME: 07:17:32 UTC Sep 1 2018
Mod-sfr 88> ***
Mod-sfr 89> *** EVENT: Start Parameters Continued: RegEx Shared Mem: 0MB, Cmd Op: , Shared Mem
Mod-sfr 90> Key: 8061, Shared Mem Size: 16, Log Pipe: /dev/ttyS0_vm1, Sock: /dev/ttyS1_vm1, Mem
Mod-sfr 91> -Path: -mem-path /hugepages
Mod-sfr 92> *** TIME: 07:17:32 UTC Sep 1 2018
Mod-sfr 93> ***
Mod-sfr 94> Status: Mapping host 0x2aab38000000 to VM with size 16777216
Mod-sfr 95> Warning: vlan 0 is not connected to host network
Mod-sfr 96> LILO 24.2 boot:
Mod-sfr 97> Loading 6.2.3......................................................................
Mod-sfr 98> ...
Mod-sfr 99> BIOS data check successful
Mod-sfr 100> [    0.000000] Initializing cgroup subsys cpuset
Mod-sfr 101> [    0.000000] Initializing cgroup subsys cpu
Mod-sfr 102> [    0.000000] Initializing cgroup subsys cpuacct
Mod-sfr 103> [    0.000000] Linux version 3.10.107sf.cisco-1 (build@4ecc4298f325) (gcc version
Mod-sfr 104> 4.7.1 (GCC) ) #1 SMP PREEMPT Thu Mar 8 18:29:04 UTC 2018
Mod-sfr 105> [    0.000000] Command line: auto BOOT_IMAGE=6.2.3 ro root=fd05 console=ttyS0,9600
Mod-sfr 106> [    0.000000] e820: BIOS-provided physical RAM map:
Mod-sfr 107> [    0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
Mod-sfr 108> [    0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
Mod-sfr 109> [    0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
Mod-sfr 110> [    0.000000] BIOS-e820: [mem 0x0000000000100000-0x000000008cafdfff] usable
Mod-sfr 111> [    0.000000] BIOS-e820: [mem 0x000000008cafe000-0x000000008cafffff] reserved
Mod-sfr 112> [    0.000000] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved
Mod-sfr 113> [    0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved
Mod-sfr 114> [    0.000000] NX (Execute Disable) protection: active
Mod-sfr 115> [    0.000000] SMBIOS 2.4 present.
Mod-sfr 116> [    0.000000] Hypervisor detected: KVM
Mod-sfr 117> [    0.000000] No AGP bridge found
Mod-sfr 118> [    0.000000] e820: last_pfn = 0x8cafe max_arch_pfn = 0x400000000
Mod-sfr 119> [    0.000000] PAT not supported by CPU.
Mod-sfr 120> [    0.000000] found SMP MP-table at [mem 0x000fdac0-0x000fdacf] mapped at [ffff88
Mod-sfr 121> 00000fdac0]
Mod-sfr 122> [    0.000000] init_memory_mapping: [mem 0x00000000-0x000fffff]
Mod-sfr 123> [    0.000000] init_memory_mapping: [mem 0x8c800000-0x8c9fffff]
Mod-sfr 124> [    0.000000] init_memory_mapping: [mem 0x8c000000-0x8c7fffff]
Mod-sfr 125> [    0.000000] init_memory_mapping: [mem 0x80000000-0x8bffffff]
Mod-sfr 126> [    0.000000] init_memory_mapping: [mem 0x00100000-0x7fffffff]
Mod-sfr 127> [    0.000000] init_memory_mapping: [mem 0x8ca00000-0x8cafdfff]
Mod-sfr 128> [    0.000000] ACPI: RSDP 0x00000000000FD900 00014 (v00 BOCHS )
Mod-sfr 129> [    0.000000] ACPI: RSDT 0x000000008CAFE3E0 00034 (v01 BOCHS  BXPCRSDT 00000001 B
Mod-sfr 130> XPC 00000001)
Mod-sfr 131> [    0.000000] ACPI: FACP 0x000000008CAFFF80 00074 (v01 BOCHS  BXPCFACP 00000001 B
Mod-sfr 132> XPC 00000001)
Mod-sfr 133> [    0.000000] ACPI: DSDT 0x000000008CAFE420 011A9 (v01 BXPC   BXDSDT   00000001 I
Mod-sfr 134> NTL 20100528)
Mod-sfr 135> [    0.000000] ACPI: FACS 0x000000008CAFFF40 00040
Mod-sfr 136> [    0.000000] ACPI: SSDT 0x000000008CAFF740 007F7 (v01 BOCHS  BXPCSSDT 00000001 B
Mod-sfr 137> XPC 00000001)
Mod-sfr 138> [    0.000000] ACPI: APIC 0x000000008CAFF610 00088 (v01 BOCHS  BXPCAPIC 00000001 B
Mod-sfr 139> XPC 00000001)
Mod-sfr 140> [    0.000000] ACPI: HPET 0x000000008CAFF5D0 00038 (v01 BOCHS  BXPCHPET 00000001 B
Mod-sfr 141> XPC 00000001)
Mod-sfr 142> [    0.000000] No NUMA configuration found
Mod-sfr 143> [    0.000000] Faking a node at [mem 0x0000000000000000-0x000000008cafdfff]
Mod-sfr 144> [    0.000000] Initmem setup node 0 [mem 0x00000000-0x8cafdfff]
Mod-sfr 145> [    0.000000]   NODE_DATA [mem 0x8cafa000-0x8cafdfff]
Mod-sfr 146> [    0.000000] kvm-clock: Using msrs 4b564d01 and 4b564d00
Mod-sfr 147> [    0.000000] kvm-clock: cpu 0, msr 0:8caf9001, boot clock
Mod-sfr 148> [    0.000000] Zone ranges:
Mod-sfr 149> [    0.000000]   DMA      [mem 0x00001000-0x00ffffff]
Mod-sfr 150> [    0.000000]   DMA32    [mem 0x01000000-0xffffffff]
Mod-sfr 151> [    0.000000]   Normal   empty
Mod-sfr 152> [    0.000000] Movable zone start for each node
Mod-sfr 153> [    0.000000] Early memory node ranges
Mod-sfr 154> [    0.000000]   node   0: [mem 0x00001000-0x0009efff]
Mod-sfr 155> [    0.000000]   node   0: [mem 0x00100000-0x8cafdfff]
Mod-sfr 156> [    0.000000] ACPI: PM-Timer IO Port: 0xb008
Mod-sfr 157> [    0.000000] ACPI: LAPIC (acpi_id[0x00] lapic_id[0x00] enabled)
Mod-sfr 158> [    0.000000] ACPI: LAPIC (acpi_id[0x01] lapic_id[0x01] enabled)
Mod-sfr 159> [    0.000000] ACPI: LAPIC (acpi_id[0x02] lapic_id[0x02] enabled)
Mod-sfr 160> [    0.000000] ACPI: LAPIC_NMI (acpi_id[0xff] dfl dfl lint[0x1])
Mod-sfr 161> [    0.000000] ACPI: IOAPIC (id[0x00] address[0xfec00000] gsi_base[0])
Mod-sfr 162> [    0.000000] IOAPIC[0]: apic_id 0, version 17, address 0xfec00000, GSI 0-23
Mod-sfr 163> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
Mod-sfr 164> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 5 global_irq 5 high level)
Mod-sfr 165> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 high level)
Mod-sfr 166> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 10 global_irq 10 high level)
Mod-sfr 167> [    0.000000] ACPI: INT_SRC_OVR (bus 0 bus_irq 11 global_irq 11 high level)
Mod-sfr 168> [    0.000000] Using ACPI (MADT) for SMP configuration information
Mod-sfr 169> [    0.000000] ACPI: HPET id: 0x8086a201 base: 0xfed00000
Mod-sfr 170> [    0.000000] smpboot: Allowing 3 CPUs, 0 hotplug CPUs
Mod-sfr 171> [    0.000000] e820: [mem 0x8cb00000-0xfeffbfff] available for PCI devices
Mod-sfr 172> [    0.000000] Booting paravirtualized kernel on KVM
Mod-sfr 173> [    0.000000] setup_percpu: NR_CPUS:64 nr_cpumask_bits:64 nr_cpu_ids:3 nr_node_id
Mod-sfr 174> s:1
Mod-sfr 175> [    0.000000] PERCPU: Embedded 24 pages/cpu @ffff88008c600000 s68672 r8192 d21440
Mod-sfr 176>  u524288
Mod-sfr 177> [    0.000000] kvm-clock: cpu 0, msr 0:8caf9001, primary cpu clock
Mod-sfr 178> [    0.000000] KVM setup async PF for cpu 0
Mod-sfr 179> [    0.000000] kvm-stealtime: cpu 0, msr 8c60ba40
Mod-sfr 180> [    0.000000] Built 1 zonelists in Node order, mobility grouping on.  Total pages
Mod-sfr 181> : 568256
Mod-sfr 182> [    0.000000] Policy zone: DMA32
Mod-sfr 183> [    0.000000] Kernel command line: auto BOOT_IMAGE=6.2.3 ro root=fd05 console=tty
Mod-sfr 184> S0,9600
Mod-sfr 185> [    0.000000] PID hash table entries: 4096 (order: 3, 32768 bytes)
Mod-sfr 186> [    0.000000] Checking aperture...
Mod-sfr 187> [    0.000000] No AGP bridge found
Mod-sfr 188> [    0.000000] Memory: 2262580k/2305016k available (4805k kernel code, 392k absent
Mod-sfr 189> , 42044k reserved, 2414k data, 896k init)
Mod-sfr 190> [    0.000000] Preemptible hierarchical RCU implementation.
Mod-sfr 191> [    0.000000]     RCU restricting CPUs from NR_CPUS=64 to nr_cpu_ids=3.
Mod-sfr 192> [    0.000000] NR_IRQS:4352 nr_irqs:704 16
Mod-sfr 193> [    0.000000] Console: colour VGA+ 80x25
Mod-sfr 194> [    0.000000] console [ttyS0] enabled
Mod-sfr 195> [    0.000000] allocated 9437184 bytes of page_cgroup
Mod-sfr 196> [    0.000000] please try 'cgroup_disable=memory' option if you don't want memory
Mod-sfr 197> cgroups
Mod-sfr 198> [    0.000000] tsc: Detected 1249.999 MHz processor
Mod-sfr 199> [    0.003000] Calibrating delay loop (skipped) preset value.. 2499.99 BogoMIPS (l
Mod-sfr 200> pj=1249999)
Mod-sfr 201> [    0.005017] pid_max: default: 32768 minimum: 301
Mod-sfr 202> [    0.006142] Security Framework initialized
Mod-sfr 203> [    0.009767] Dentry cache hash table entries: 524288 (order: 10, 4194304 bytes)
Mod-sfr 204> [    0.016041] Inode-cache hash table entries: 262144 (order: 9, 2097152 bytes)
Mod-sfr 205> [    0.019211] Mount-cache hash table entries: 256
Mod-sfr 206> [    0.021357] Initializing cgroup subsys memory
Mod-sfr 207> [    0.023091] Last level iTLB entries: 4KB 0, 2MB 0, 4MB 0
Mod-sfr 208> [    0.023091] Last level dTLB entries: 4KB 0, 2MB 0, 4MB 0
Mod-sfr 209> [    0.023091] tlb_flushall_shift: 6
Mod-sfr 210> [    0.024484] Freeing SMP alternatives: 12k freed
Mod-sfr 211> [    0.028335] ACPI: Core revision 20130328
Mod-sfr 212> [    0.033798] ACPI: All ACPI Tables successfully acquired
Mod-sfr 213> [    0.041243] ..TIMER: vector=0x30 apic1=0 pin1=2 apic2=-1 pin2=-1
Mod-sfr 214> [    0.042010] smpboot: CPU0: Intel QEMU Virtual CPU version 1.5.0 (fam: 06, model
Mod-sfr 215> : 02, stepping: 03)
Mod-sfr 216> [    0.048000] Performance Events: unsupported p6 CPU model 2 no PMU driver, softw
Mod-sfr 217> are events only.
Mod-sfr 218> [    0.055294] smpboot: Booting Node   0, Processors  #1[    0.003000] kvm-clock:
Mod-sfr 219> cpu 1, msr 0:8caf9041, secondary cpu clock
Mod-sfr 220> [    0.072094] KVM setup async PF for cpu 1
Mod-sfr 221>  #2 OK
Mod-sfr 222> [    0.072094] kvm-stealtime: cpu 1, msr 8c68ba40
Mod-sfr 223> [    0.003000] kvm-clock: cpu 2, msr 0:8caf9081, secondary cpu clock
Mod-sfr 224> [    0.091119] Brought up 3 CPUs
Mod-sfr 225> [    0.091019] KVM setup async PF for cpu 2
Mod-sfr 226> [    0.091019] kvm-stealtime: cpu 2, msr 8c70ba40
Mod-sfr 227> [    0.092011] smpboot: Total of 3 processors activated (7499.99 BogoMIPS)
Mod-sfr 228> [    0.095768] devtmpfs: initialized
Mod-sfr 229> [    0.098102] NET: Registered protocol family 16
Mod-sfr 230> [    0.102752] ACPI: bus type PCI registered
Mod-sfr 231> [    0.105426] PCI: Using configuration type 1 for base access
Mod-sfr 232> [    0.156355] bio: create slab <bio-0> at 0
Mod-sfr 233> [    0.160256] ACPI: Added _OSI(Module Device)
Mod-sfr 234> [    0.162013] ACPI: Added _OSI(Processor Device)
Mod-sfr 235> [    0.163014] ACPI: Added _OSI(3.0 _SCP Extensions)
Mod-sfr 236> [    0.164000] ACPI: Added _OSI(Processor Aggregator Device)
Mod-sfr 237> [    0.173323] ACPI: Interpreter enabled
Mod-sfr 238> [    0.174027] ACPI: (supports S0 S5)
Mod-sfr 239> [    0.175008] ACPI: Using IOAPIC for interrupt routing
Mod-sfr 240> [    0.177260] PCI: Using host bridge windows from ACPI; if necessary, use "pci=no
Mod-sfr 241> crs" and report a bug
Mod-sfr 242> [    0.181372] ACPI: No dock devices found.
Mod-sfr 243> [    0.213960] ACPI: PCI Root Bridge [PCI0] (domain 0000 [bus 00-ff])
Mod-sfr 244> [    0.214049] acpi PNP0A03:00: ACPI _OSC support notification failed, disabling P
Mod-sfr 245> CIe ASPM
Mod-sfr 246> [    0.215000] acpi PNP0A03:00: Unable to request _OSC control (_OSC support mask:
Mod-sfr 247>  0x08)
Mod-sfr 248> [    0.215000] acpi PNP0A03:00: fail to add MMCONFIG information, can't access ext
Mod-sfr 249> ended PCI configuration space under this bridge.
Mod-sfr 250> [    0.217500] PCI host bridge to bus 0000:00
Mod-sfr 251> [    0.218018] pci_bus 0000:00: root bus resource [bus 00-ff]
Mod-sfr 252> [    0.220015] pci_bus 0000:00: root bus resource [io  0x0000-0x0cf7]
Mod-sfr 253> [    0.221035] pci_bus 0000:00: root bus resource [io  0x0d00-0xffff]
Mod-sfr 254> [    0.222000] pci_bus 0000:00: root bus resource [mem 0x000a0000-0x000bffff]
Mod-sfr 255> [    0.222000] pci_bus 0000:00: root bus resource [mem 0xc0000000-0xfebfffff]
Mod-sfr 256> [    0.243085] pci 0000:00:01.3: quirk: [io  0xb000-0xb03f] claimed by PIIX4 ACPI
Mod-sfr 257> [    0.245054] pci 0000:00:01.3: quirk: [io  0xb100-0xb10f] claimed by PIIX4 SMB
Mod-sfr 258> [    0.350360] ACPI: PCI Interrupt Link [LNKA] (IRQs 5 *10 11)
Mod-sfr 259> [    0.353709] ACPI: PCI Interrupt Link [LNKB] (IRQs 5 *10 11)
Mod-sfr 260> [    0.357436] ACPI: PCI Interrupt Link [LNKC] (IRQs 5 10 *11)
Mod-sfr 261> [    0.359000] ACPI: PCI Interrupt Link [LNKD] (IRQs 5 10 *11)
Mod-sfr 262> [    0.360868] ACPI: PCI Interrupt Link [LNKS] (IRQs *9)
Mod-sfr 263> [    0.363965] ACPI: Enabled 16 GPEs in block 00 to 0F
Mod-sfr 264> [    0.367238] vgaarb: device added: PCI:0000:00:02.0,decodes=io+mem,owns=io+mem,l
Mod-sfr 265> ocks=none
Mod-sfr 266> [    0.369027] vgaarb: loaded
Mod-sfr 267> [    0.370000] vgaarb: bridge control possible 0000:00:02.0
Mod-sfr 268> [    0.372479] SCSI subsystem initialized
Mod-sfr 269> [    0.374017] ACPI: bus type ATA registered
Mod-sfr 270> [    0.378445] ACPI: bus type USB registered
Mod-sfr 271> [    0.380566] usbcore: registered new interface driver usbfs
Mod-sfr 272> [    0.382228] usbcore: registered new interface driver hub
Mod-sfr 273> [    0.384493] usbcore: registered new device driver usb
Mod-sfr 274> [    0.387488] pps_core: LinuxPPS API ver. 1 registered
Mod-sfr 275> [    0.388009] pps_core: Software ver. 5.3.6 - Copyright 2005-2007 Rodolfo Giomett
Mod-sfr 276> i <giometti@linux.it>
Mod-sfr 277> [    0.389334] PTP clock support registered
Mod-sfr 278> [    0.391366] PCI: Using ACPI for IRQ routing
Mod-sfr 279> [    0.394646] NetLabel: Initializing
Mod-sfr 280> [    0.396009] NetLabel:  domain hash size = 128
Mod-sfr 281> [    0.397012] NetLabel:  protocols = UNLABELED CIPSOv4
Mod-sfr 282> [    0.398000] NetLabel:  unlabeled traffic allowed by default
Mod-sfr 283> [    0.398000] HPET: 3 timers in total, 0 timers will be used for per-cpu timer
Mod-sfr 284> [    0.398000] hpet0: at MMIO 0xfed00000, IRQs 2, 8, 0
Mod-sfr 285> [    0.398000] hpet0: 3 comparators, 64-bit 100.000000 MHz counter
Mod-sfr 286> [    0.403556] amd_nb: Cannot enumerate AMD northbridges
Mod-sfr 287> [    0.404014] Switching to clocksource kvm-clock
Mod-sfr 288> [    0.405660] pnp: PnP ACPI init
Mod-sfr 289> [    0.407205] ACPI: bus type PNP registered
Mod-sfr 290> [    0.414000] pnp: PnP ACPI: found 8 devices
Mod-sfr 291> [    0.416122] ACPI: bus type PNP unregistered
Mod-sfr 292> [    0.455064] NET: Registered protocol family 2
Mod-sfr 293> [    0.458196] TCP established hash table entries: 32768 (order: 7, 524288 bytes)
Mod-sfr 294> [    0.461888] TCP bind hash table entries: 32768 (order: 7, 524288 bytes)
Mod-sfr 295> [    0.465232] TCP: Hash tables configured (established 32768 bind 32768)
Mod-sfr 296> [    0.468314] TCP: reno registered
Mod-sfr 297> [    0.469865] UDP hash table entries: 2048 (order: 4, 65536 bytes)
Mod-sfr 298> [    0.472693] UDP-Lite hash table entries: 2048 (order: 4, 65536 bytes)
Mod-sfr 299> [    0.476056] NET: Registered protocol family 1
Mod-sfr 300> [    0.478614] RPC: Registered named UNIX socket transport module.
Mod-sfr 301> [    0.481343] RPC: Registered udp transport module.
Mod-sfr 302> [    0.483532] RPC: Registered tcp transport module.
Mod-sfr 303> [    0.485732] RPC: Registered tcp NFSv4.1 backchannel transport module.
Mod-sfr 304> [    0.488718] pci 0000:00:00.0: Limiting direct PCI/PCI transfers
Mod-sfr 305> [    0.491478] pci 0000:00:01.0: PIIX3: Enabling Passive Release
Mod-sfr 306> [    0.494192] pci 0000:00:01.0: Activating ISA DMA hang workarounds
Mod-sfr 307> [    0.501480] microcode: CPU0 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 308> [    0.504085] microcode: CPU1 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 309> [    0.506740] microcode: CPU2 sig=0x623, pf=0x0, revision=0x1
Mod-sfr 310> [    0.509634] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co
Mod-sfr 311> .uk>, Peter Oruba
Mod-sfr 312> [    0.516569] HugeTLB registered 2 MB page size, pre-allocated 0 pages
Mod-sfr 313> [    0.520404] VFS: Disk quotas dquot_6.5.2
Mod-sfr 314> [    0.522342] Dquot-cache hash table entries: 512 (order 0, 4096 bytes)
Mod-sfr 315> [    0.526883] NFS: Registering the id_resolver key type
Mod-sfr 316> [    0.529291] Key type id_resolver registered
Mod-sfr 317> [    0.531241] Key type id_legacy registered
Mod-sfr 318> [    0.533530] msgmni has been set to 4419
Mod-sfr 319> [    0.537130] Block layer SCSI generic (bsg) driver version 0.4 loaded (major 251
Mod-sfr 320> [    0.540518] io scheduler noop registered
Mod-sfr 321> [    0.542385] io scheduler deadline registered
Mod-sfr 322> [    0.544532] io scheduler cfq registered (default)
Mod-sfr 323> [    0.549983] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input
Mod-sfr 324> [    0.553387] ACPI: Power Button [PWRF]
Mod-sfr 325> [    0.563853] ACPI: PCI Interrupt Link [LNKD] enabled at IRQ 11
Mod-sfr 326> [    0.570083] ACPI: PCI Interrupt Link [LNKA] enabled at IRQ 10
Mod-sfr 327> [    0.576825] ACPI: PCI Interrupt Link [LNKC] enabled at IRQ 11
Mod-sfr 328> [    0.585469] Serial: 8250/16550 driver, 4 ports, IRQ sharing enabled
Mod-sfr 329> [    0.616768] 00:05: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
Mod-sfr 330> [    0.647426] 00:06: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
Mod-sfr 331> [    0.653299] Non-volatile memory driver v1.3
Mod-sfr 332> [    0.655287] Linux agpgart interface v0.103
Mod-sfr 333> [    0.658236] [drm] Initialized drm 1.1.0 20060810
Mod-sfr 334> [    0.661540] Floppy drive(s): fd0 is 1.44M, fd1 is 1.44M
Mod-sfr 335> [    0.676866] FDC 0 is a S82078B
Mod-sfr 336> [    0.677253] brd: module loaded
Mod-sfr 337> [    0.685142] loop: module loaded
Mod-sfr 338> [    0.692977]  vda: vda1 vda2 vda3 < vda5 vda6 vda7 >
Mod-sfr 339> [    0.701867] Loading iSCSI transport class v2.0-870.
Mod-sfr 340> [    0.713961] scsi0 : ata_piix
Mod-sfr 341> [    0.716261] scsi1 : ata_piix
Mod-sfr 342> [    0.718194] ata1: PATA max MWDMA2 cmd 0x1f0 ctl 0x3f6 bmdma 0xc0c0 irq 14
Mod-sfr 343> [    0.721341] ata2: PATA max MWDMA2 cmd 0x170 ctl 0x376 bmdma 0xc0c8 irq 15
Mod-sfr 344> [    0.724921] e100: Intel(R) PRO/100 Network Driver, 3.5.24-k2-NAPI
Mod-sfr 345> [    0.727964] e100: Copyright(c) 1999-2006 Intel Corporation
Mod-sfr 346> [    0.730857] igb: Intel(R) Gigabit Ethernet Network Driver - version 5.0.3-k
Mod-sfr 347> [    0.734047] igb: Copyright (c) 2007-2013 Intel Corporation.
Mod-sfr 348> [    0.736966] Fusion MPT base driver 3.04.20
Mod-sfr 349> [    0.738904] Copyright (c) 1999-2008 LSI Corporation
Mod-sfr 350> [    0.741223] Fusion MPT SPI Host driver 3.04.20
Mod-sfr 351> [    0.743597] Fusion MPT FC Host driver 3.04.20
Mod-sfr 352> [    0.746001] Fusion MPT SAS Host driver 3.04.20
Mod-sfr 353> [    0.749195] ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
Mod-sfr 354> [    0.752208] ehci-pci: EHCI PCI platform driver
Mod-sfr 355> [    0.754612] ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
Mod-sfr 356> [    0.757779] uhci_hcd: USB Universal Host Controller Interface driver
Mod-sfr 357> [    0.761427] usbcore: registered new interface driver usblp
Mod-sfr 358> [    0.764292] usbcore: registered new interface driver usb-storage
Mod-sfr 359> [    0.767698] i8042: PNP: PS/2 Controller [PNP0303:KBD,PNP0f13:MOU] at 0x60,0x64
Mod-sfr 360> irq 1,12
Mod-sfr 361> [    0.773840] serio: i8042 KBD port at 0x60,0x64 irq 1
Mod-sfr 362> [    0.776262] serio: i8042 AUX port at 0x60,0x64 irq 12
Mod-sfr 363> [    0.779684] mousedev: PS/2 mouse device common for all mice
Mod-sfr 364> [    0.784687] rtc_cmos 00:00: RTC can wake from S4
Mod-sfr 365> [    0.786893] input: AT Translated Set 2 keyboard as /devices/platform/i8042/seri
Mod-sfr 366> o0/input/input1
Mod-sfr 367> [    0.792472] rtc_cmos 00:00: rtc core: registered rtc_cmos as rtc0
Mod-sfr 368> [    0.796182] rtc_cmos 00:00: alarms up to one day, 114 bytes nvram, hpet irqs
Mod-sfr 369> [    0.800099] i2c /dev entries driver
Mod-sfr 370> [    0.802893] md: raid1 personality registered for level 1
Mod-sfr 371> [    0.806387] device-mapper: ioctl: 4.24.0-ioctl (2013-01-15) initialised: dm-dev
Mod-sfr 372> el@redhat.com
Mod-sfr 373> [    0.810357] cpuidle: using governor ladder
Mod-sfr 374> [    0.813476] hidraw: raw HID events driver (C) Jiri Kosina
Mod-sfr 375> [    0.825096] usbcore: registered new interface driver usbhid
Mod-sfr 376> [    0.827978] usbhid: USB HID core driver
Mod-sfr 377> [    0.830273] ipip: IPv4 over IPv4 tunneling driver
Mod-sfr 378> [    0.833701] TCP: cubic registered
Mod-sfr 379> [    0.835307] Initializing XFRM netlink socket
Mod-sfr 380> [    0.837687] NET: Registered protocol family 10
Mod-sfr 381> [    0.840600] NET: Registered protocol family 17
Mod-sfr 382> [    0.842760] Key type dns_resolver registered
Mod-sfr 383> [    0.846149] registered taskstats version 1
Mod-sfr 384> [    0.849390] console [netcon0] enabled
Mod-sfr 385> [    0.851124] netconsole: network logging started
Mod-sfr 386> [    0.879178] ata2.00: ATAPI: QEMU DVD-ROM, 1.5.0, max UDMA/100
Mod-sfr 387> [    0.883217] ata2.00: configured for MWDMA2
Mod-sfr 388> [    0.886521] ata1.00: ATA-7: QEMU HARDDISK, 1.5.0, max UDMA/100
Mod-sfr 389> [    0.889214] ata1.00: 6291456 sectors, multi 16: LBA48
Mod-sfr 390> [    0.892882] ata1.00: configured for MWDMA2
Mod-sfr 391> [    0.895151] scsi 0:0:0:0: Direct-Access     ATA      QEMU HARDDISK    1.5. PQ:
Mod-sfr 392> 0 ANSI: 5
Mod-sfr 393> [    0.900152] sd 0:0:0:0: [sda] 6291456 512-byte logical blocks: (3.22 GB/3.00 Gi
Mod-sfr 394> B)
Mod-sfr 395> [    0.900785] sd 0:0:0:0: Attached scsi generic sg0 type 0
Mod-sfr 396> [    0.906350] sd 0:0:0:0: [sda] Write Protect is off
Mod-sfr 397> [    0.908748] sd 0:0:0:0: [sda] Write cache: enabled, read cache: enabled, doesn'
Mod-sfr 398> t support DPO or FUA
Mod-sfr 399> [    0.913981] scsi 1:0:0:0: CD-ROM            QEMU     QEMU DVD-ROM     1.5. PQ:
Mod-sfr 400> 0 ANSI: 5
Mod-sfr 401> [    0.918243]  sda: sda1 sda2
Mod-sfr 402> [    0.921358] sr0: scsi3-mmc drive: 4x/4x cd/rw xa/form2 tray
Mod-sfr 403> [    0.921998] sd 0:0:0:0: [sda] Attached SCSI disk
Mod-sfr 404> [    0.926050] cdrom: Uniform CD-ROM driver Revision: 3.20
Mod-sfr 405> [    0.931098] sr 1:0:0:0: Attached scsi generic sg1 type 5
Mod-sfr 406> [    1.427070] input: ImExPS/2 Generic Explorer Mouse as /devices/platform/i8042/s
Mod-sfr 407> erio1/input/input2
Mod-sfr 408> [    1.432180] md: Waiting for all devices to be available before autodetect
Mod-sfr 409> [    1.435317] md: If you don't use raid, use raid=noautodetect
Mod-sfr 410> [    1.438940] md: Autodetecting RAID arrays.
Mod-sfr 411> [    1.440877] md: Scanned 0 and added 0 devices.
Mod-sfr 412> [    1.442987] md: autorun ...
Mod-sfr 413> [    1.444336] md: ... autorun DONE.
Mod-sfr 414> [    1.448950] kjournald starting.  Commit interval 5 seconds
Mod-sfr 415> [    1.449022] EXT3-fs (vda5): mounted filesystem with ordered data mode
Mod-sfr 416> [    1.449082] VFS: Mounted root (ext3 filesystem) readonly on device 253:5.
Mod-sfr 417> [    1.449964] devtmpfs: mounted
Mod-sfr 418> [    1.459688] Freeing unused kernel memory: 896k freed
Mod-sfr 419> INIT: version 2.88 booting
Mod-sfr 420> [    1.499159] tsc: Refined TSC clocksource calibration: 1249.999 MHz
Mod-sfr 421> cat: /proc/cmdline: No such file or directory
Mod-sfr 422> cat: /proc/cmdline: No such file or directory
Mod-sfr 423> Mounting proc file system...
Mod-sfr 425>                                                                       [  OK  ]
Mod-sfr 426> Mounting sys file system...
Mod-sfr 428>                                                                       [  OK  ]
Mod-sfr 429> Starting udev [    1.690619] udevd (767): /proc/767/oom_adj is deprecated, please
Mod-sfr 430> use /proc/767/oom_score_adj instead.
Mod-sfr 431> [    1.695256] udevd version 124 started
Mod-sfr 432> [    1.907261] sfpacket: module license 'Proprietary' taints kernel.
Mod-sfr 433> [    1.919834] Disabling lock debugging due to kernel taint
Mod-sfr 434> [    1.929455] Sourcefire Bridging Packet Driver - version 6.0.0
Mod-sfr 435> [    1.944621] Copyright (c) 2004-2010 Sourcefire, Inc.
Mod-sfr 436> [    1.962609] SFPacket Inter-VM Shared Memory Driver - version 6.0.0
Mod-sfr 437> [    1.975425] Copyright (c) 2014 Cisco Systems, Inc.
Mod-sfr 438> [    1.986000] KVM_IVSHMEM: Major device number is: 247
Mod-sfr 439> [    1.988564] KVM_IVSHMEM: Probing for KVM_IVSHMEM Device
Mod-sfr 440> [    1.991825] KVM_IVSHMEM: result is 0
Mod-sfr 441> [    1.993727] KVM_IVSHMEM: iomap base = 0x18446683600577888256
Mod-sfr 442> [    1.996855] KVM_IVSHMEM: ioaddr = fc000000 ioaddr_size = 16777216
Mod-sfr 443> [    2.016164] SFIVMSHM info: Registered device 'kvm_ivshmem'.
Mod-sfr 444> [    2.034089] KVM_IVSHMEM: Registered with the SFIVMShm driver.
Mod-sfr 445> [    2.042463] KVM_IVSHMEM: irq = 11 regaddr = febf1000 reg_size = 256
Mod-sfr 446> Activating all swap files/partitions...
Mod-sfr 447> [    2.274662] Adding 1000444k swap on /dev/vda2.  Priority:-1 extents:1 across:10
Mod-sfr 448> 00444k
Mod-sfr 450>                                                                       [  OK  ]
Mod-sfr 451> Mounting root file system in read-only mode...
Mod-sfr 453>                                                                       [  OK  ]
Mod-sfr 454> Checking file systems...
Mod-sfr 455> e2fsck 1.42.9 (28-Dec-2013)
Mod-sfr 456> 3D-6.2.3: clean, 19754/244320 files, 215973/976384 blocks
Mod-sfr 457> e2fsck 1.42.9 (28-Dec-2013)
Mod-sfr 458> e2fsck 1.42.9 (28-Dec-2013)
Mod-sfr 459> Setting free inodes count to 26166 (was 26158)
Mod-sfr 460> Setting free blocks count to 94976 (was 79848)
Mod-sfr 461> BOOT: clean, 42/26208 files, 9444/104420 blocks
Mod-sfr 462> /Volume: clean, 34007/2498560 files, 636886/9979492 blocks
Mod-sfr 464>                                                                       [  OK  ]
Mod-sfr 465> Remounting root file system in read-write mode...
Mod-sfr 466> [    2.459910] EXT3-fs (vda5): using internal journal
Mod-sfr 468>                                                                       [  OK  ]
Mod-sfr 469> Mounting remaining file systems...
Mod-sfr 470> [    2.474145] kjournald starting.  Commit interval 5 seconds
Mod-sfr 471> [    2.476846] EXT3-fs (sda1): using internal journal
Mod-sfr 472> [    2.479111] EXT3-fs (sda1): mounted filesystem with ordered data mode
Mod-sfr 473> [    2.487118] kjournald starting.  Commit interval 5 seconds
Mod-sfr 474> [    2.487625] EXT3-fs (vda7): using internal journal
Mod-sfr 475> [    2.487630] EXT3-fs (vda7): mounted filesystem with ordered data mode
Mod-sfr 477>                                                                       [  OK  ]
Mod-sfr 478> Removing /var/run/* and /var/lock/subsys/*
Mod-sfr 480>                                                                       [  OK  ]
Mod-sfr 481> Removing /var/sf/run/*
Mod-sfr 482> Removing /tmp/cgi* files
Mod-sfr 483> Creating new /var/run/utmp...
Mod-sfr 485>                                                                       [  OK  ]
Mod-sfr 486> Removing possible /etc/nologin /fastboot and /forcefsck...
Mod-sfr 488>                                                                       [  OK  ]
Mod-sfr 489> Removing dhcp lock files...
Mod-sfr 491>                                                                       [  OK  ]
Mod-sfr 492> /etc/rc.d/rcsysinit.d/S51udev_retry: line 35: log_info_msg: command not found
Mod-sfr 494>                                                                       [  OK  ]
Mod-sfr 495> Setting clock...
Mod-sfr 497>                                                                       [  OK  ]
Mod-sfr 498> Initializing kernel random number generator...
Mod-sfr 500>                                                                       [  OK  ]
Mod-sfr 501> Saving dmesg boot log
Mod-sfr 503>                                                                       [  OK  ]
Mod-sfr 504> Loading fuse module failed!
Mod-sfr 505> Bringing up the loopback interface...
Mod-sfr 506> Upping interface lo
Mod-sfr 508>                                                                       [  OK  ]
Mod-sfr 509> Configuring address the lo interface...
Mod-sfr 511>                                                                       [  OK  ]
Mod-sfr 512> Configuring hostname to firepower
Mod-sfr 514>                                                                       [  OK  ]
Mod-sfr 515> Configuring IPv6 address the lo interface...
Mod-sfr 517>                                                                       [  OK  ]
Mod-sfr 518> Disable IPv6 default route
Mod-sfr 520>                                                                       [  OK  ]
Mod-sfr 521> Configuring hostname to firepower
Mod-sfr 523>                                                                       [  OK  ]
Mod-sfr 524> Configuring Static Routes
Mod-sfr 525> Writing hosts file
Mod-sfr 527>                                                                       [  OK  ]
Mod-sfr 529>                                                                       [  OK  ]
Mod-sfr 530> verify_fsic(start)
Mod-sfr 531> Running file integrity checks...
Mod-sfr 532> FIPS mode is disabled. Skip verifying file integrity
Mod-sfr 533> Setting kernel paramaters
Mod-sfr 535>                                                                       [  OK  ]
Mod-sfr 536> INIT: Entering runlevel: 3
Mod-sfr 537> Starting system log daemon...
Mod-sfr 539>                                                                       [  OK  ]
Mod-sfr 540> Starting cron daemon...
Mod-sfr 541> cron: No such file or directory
Mod-sfr 542> cron: created
Mod-sfr 544>                                                                       [  OK  ]
Mod-sfr 545> Disk free check passed, creating swap...
Mod-sfr 546> Building swapfile /Volume/.swaptwo
Mod-sfr 547> 2258458+0 records in
Mod-sfr 548> 2258458+0 records out
Mod-sfr 549> 2312660992 bytes (2.3 GB) copied, 42.8861 s, 53.9 MB/s
Mod-sfr 550> Setting up swapspace version 1, size = 2258452 KiB
Mod-sfr 551> no label, UUID=cadd9442-d0f6-4e24-8f97-12c02777f2ac
Mod-sfr 552> Adding swapfile /Volume/.swaptwo
Mod-sfr 553> [   49.417335] Adding 2258452k swap on /Volume/.swaptwo.  Priority:-2 extents:571
Mod-sfr 554> across:2318544k
Mod-sfr 555> [   49.615427] udev: renamed network interface eth0 to cplane
Mod-sfr 556> Flushing all current IPv4 rules and user defined chains: [   50.518366] ip_tables:
Mod-sfr 557>  (C) 2000-2006 Netfilter Core Team
Mod-sfr 558> ...success
Mod-sfr 559> Clearing all current IPv4 rules and user defined chains: ...success
Mod-sfr 560> Applying iptables firewall rules:
Mod-sfr 561> Flushing chain `PREROUTING'
Mod-sfr 562> Flushing chain `INPUT'
Mod-sfr 563> Flushing chain `FORWARD'
Mod-sfr 564> Flushing chain `OUTPUT'
Mod-sfr 565> Flushing chain `POSTROUTING'
Mod-sfr 566> Flushing chain `INPUT'
Mod-sfr 567> Flushing chain `FORWARD'
Mod-sfr 568> Flushing chain `OUTPUT'
Mod-sfr 569> [   50.578594] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
Mod-sfr 570> Applying rules successed
Mod-sfr 571> Flushing all current IPv6 rules and user defined chains: [   50.659088] ip6_tables
Mod-sfr 572> : (C) 2000-2006 Netfilter Core Team
Mod-sfr 573> ...success
Mod-sfr 574> Clearing all current IPv6 rules and user defined chains: ...success
Mod-sfr 575> Applying ip6tables firewall rules:
Mod-sfr 576> Flushing chain `PREROUTING'
Mod-sfr 577> Flushing chain `INPUT'
Mod-sfr 578> Flushing chain `FORWARD'
Mod-sfr 579> Flushing chain `OUTPUT'
Mod-sfr 580> Flushing chain `POSTROUTING'
Mod-sfr 581> Flushing chain `INPUT'
Mod-sfr 582> Flushing chain `FORWARD'
Mod-sfr 583> Flushing chain `OUTPUT'
Mod-sfr 584> Applying rules successed
Mod-sfr 585> Upping interface eth0
Mod-sfr 587>                                                                       [  OK  ]
Mod-sfr 588> No dns server or search domain specified
Mod-sfr 589> No ntp server specified
Mod-sfr 590> Configuring address the eth0 interface...
Mod-sfr 592>                                                                       [  OK  ]
Mod-sfr 593> Configuring hostname to firepower
Mod-sfr 595>                                                                       [  OK  ]
Mod-sfr 596> Unconfiguring IPv6
Mod-sfr 598>                                                                       [  OK  ]
Mod-sfr 599> Configuring Static Routes
Mod-sfr 600> Writing hosts file
Mod-sfr 602>                                                                       [  OK  ]
Mod-sfr 603> Starting portmap...
Mod-sfr 605>                                                                       [  OK  ]
Mod-sfr 607>                                                                       [  OK  ]
Mod-sfr 608> Starting nscd...
Mod-sfr 609> mkdir: created directory '/var/run/nscd'
Mod-sfr 611>                                                                       [  OK  ]
Mod-sfr 612> Setting video params
Mod-sfr 613> setterm: cannot (un)set powersave mode: Inappropriate ioctl for device
Mod-sfr 614> Loading fuse module failed!
Mod-sfr 615> Generating public/private rsa1 key pair.
Mod-sfr 616> Saving key "/etc/ssh/ssh_host_key" failed: unknown or unsupported key type
Mod-sfr 617> Generating public/private dsa key pair.
Mod-sfr 618> Your identification has been saved in /etc/ssh/ssh_host_dsa_key.
Mod-sfr 619> Your public key has been saved in /etc/ssh/ssh_host_dsa_key.pub.
Mod-sfr 620> The key fingerprint is:
Mod-sfr 621> SHA256:Q9S3UW9eQrEB6c9W4j9E9dXz357ZKYN6nT1F7N0AK8Y root@firepower
Mod-sfr 622> The key's randomart image is:
Mod-sfr 623> +---[DSA 1024]----+
Mod-sfr 624> |        ..  .+=..|
Mod-sfr 625> |       .  . =. =+|
Mod-sfr 626> |        .. o =o.X|
Mod-sfr 627> |       .  E + o=B|
Mod-sfr 628> |        S. . +.**|
Mod-sfr 629> |         .    =.B|
Mod-sfr 630> |            o.+o*|
Mod-sfr 631> |           o = B+|
Mod-sfr 632> |         .o   o o|
Mod-sfr 633> +----[SHA256]-----+
Mod-sfr 634> Generating public/private rsa key pair.
Mod-sfr 635> Your identification has been saved in /etc/ssh/ssh_host_rsa_key.
Mod-sfr 636> Your public key has been saved in /etc/ssh/ssh_host_rsa_key.pub.
Mod-sfr 637> The key fingerprint is:
Mod-sfr 638> SHA256:pg9YvBQ5ONCcJPiauI2NisA2jYKgUVLKrQis+akrNNM root@firepower
Mod-sfr 639> The key's randomart image is:
Mod-sfr 640> +---[RSA 2048]----+
Mod-sfr 641> | .++..           |
Mod-sfr 642> |+o.o+. .         |
Mod-sfr 643> |++..o +          |
Mod-sfr 644> |++o  o o         |
Mod-sfr 645> |B+.   + S        |
Mod-sfr 646> |O*oE + +         |
Mod-sfr 647> |*@=.. +          |
Mod-sfr 648> |X.+    o         |
Mod-sfr 649> |B.      .        |
Mod-sfr 650> +----[SHA256]-----+
Mod-sfr 651> Generating public/private ecdsa key pair.
Mod-sfr 652> Your identification has been saved in /etc/ssh/ssh_host_ecdsa_key.
Mod-sfr 653> Your public key has been saved in /etc/ssh/ssh_host_ecdsa_key.pub.
Mod-sfr 654> The key fingerprint is:
Mod-sfr 655> SHA256:7zwtrXL0Oxlmg+PHCrE/ezPR13uP6vA5JL49DGCUytc root@firepower
Mod-sfr 656> The key's randomart image is:
Mod-sfr 657> +---[ECDSA 256]---+
Mod-sfr 658> |         .       |
Mod-sfr 659> |        o        |
Mod-sfr 660> |     . o .       |
Mod-sfr 661> |      o + E      |
Mod-sfr 662> |       oS. . .  .|
Mod-sfr 663> |         +* B . o|
Mod-sfr 664> |        o+o& = ..|
Mod-sfr 665> |        .=B+/. o.|
Mod-sfr 666> |         oO%BO. +|
Mod-sfr 667> +----[SHA256]-----+
Mod-sfr 668> Generating public/private ed25519 key pair.
Mod-sfr 669> Your identification has been saved in /etc/ssh/ssh_host_ed25519_key.
Mod-sfr 670> Your public key has been saved in /etc/ssh/ssh_host_ed25519_key.pub.
Mod-sfr 671> The key fingerprint is:
Mod-sfr 672> SHA256:PPLutfUlSa7+7Ju/7EWO3G++zUjBBRht6nGPdakvBvA root@firepower
Mod-sfr 673> The key's randomart image is:
Mod-sfr 674> +--[ED25519 256]--+
Mod-sfr 675> |            .+.  |
Mod-sfr 676> |            . o. |
Mod-sfr 677> |             o  o|
Mod-sfr 678> |       . .  o..oo|
Mod-sfr 679> |      . S o. o=+o|
Mod-sfr 680> |       o . E.=.B.|
Mod-sfr 681> |        . . o O =|
Mod-sfr 682> |       . . o B.B=|
Mod-sfr 683> |       .o ..+o@XO|
Mod-sfr 684> +----[SHA256]-----+
Mod-sfr 686>                                                                       [  OK  ]
Mod-sfr 687> Starting , please wait......complete.
Mod-sfr 689> Starting xinetd:                                                      [  OK  ]
Mod-sfr 690> Firstboot detected, executing scripts
Mod-sfr 691> Executing S01reset_failopen_if
Mod-sfr 692> [   58.158405] Intel(R) PRO/1000 Network Driver - version 8.0.35-HS-6.1.0
Mod-sfr 693> [   58.161809] Copyright (c) 1999-2010 Intel Corporation.
Mod-sfr 694> [   58.165575] ACPI: PCI Interrupt Link [LNKB] enabled at IRQ 10
Mod-sfr 695> [   58.635684] e1000: 0000:00:06.0: e1000_probe: (PCI:33MHz:32-bit) 52:54:00:12:34
Mod-sfr 696> :56
Mod-sfr 697> [   58.687396] e1000: eth1: e1000_probe: Intel(R) PRO/1000 Network Connection
Mod-sfr 699>                                                                       [  OK  ]
Mod-sfr 700> Executing S01virtual-machine-reconfigure
Mod-sfr 702>                                                                       [  OK  ]
Mod-sfr 703> Executing S02aws-pull-cfg
Mod-sfr 705>                                                                       [  OK  ]
Mod-sfr 706> Executing S04fix-httpd.sh
Mod-sfr 708>                                                                       [  OK  ]
Mod-sfr 709> Executing S05set-default-ipv4.pl
Mod-sfr 711>                                                                       [  OK  ]
Mod-sfr 712> Executing S05set-mgmnt-port
Mod-sfr 714>                                                                       [  OK  ]
Mod-sfr 715> Executing S06addusers
Mod-sfr 717>                                                                       [  OK  ]
Mod-sfr 718> Executing S07uuid-init
Mod-sfr 720>                                                                       [  OK  ]
Mod-sfr 721> Executing S08configure_mysql
Mod-sfr 723>                                                                       [  OK  ]
Mod-sfr 724> ************ Attention *********
Mod-sfr 725>    Initializing the configuration database.  Depending on available
Mod-sfr 726>    system resources (CPU, memory, and disk), this may take 30 minutes
Mod-sfr 727>    or more to complete.
Mod-sfr 728> ************ Attention *********
Mod-sfr 729> Executing S09database-init
Mod-sfr 730>
Mod-sfr 731>                                                                       [  OK  ]
Mod-sfr 732> Executing S11database-populate


ASA5506W-X# show module    // 1 HOUR HAS PASSED

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5506-X with FirePOWER services, WiFi, 8G ASA5506W           JAD20080123
 sfr Unknown                                      N/A                JAD20080123
wlan WLAN AP                                      N/A                N/A       

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 0078.884b.bf62 to 0078.884b.bf6b  2.0          1.1.8        9.8(2)38
 sfr 0078.884b.bf61 to 0078.884b.bf61  N/A          N/A         
wlan none                              N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 sfr Recover            Not Applicable       
wlan Up                 Up                   

ASA5506W-X# session sfr console
ERROR: Failed opening console session with module sfr. Module is in "Recover" state.
Please try again later.


Mod-sfr 733>
Mod-sfr 734>                                                                       [  OK  ]
Mod-sfr 735> Executing S12install_infodb
Mod-sfr 737>                                                                       [  OK  ]
Mod-sfr 738> Executing S15set-locale.sh
Mod-sfr 740>                                                                       [  OK  ]
Mod-sfr 741> Executing S16update-sensor.pl
Mod-sfr 743>                                                                       [  OK  ]
Mod-sfr 744> Executing S19cert-tun-init
Mod-sfr 746>                                                                       [  OK  ]
Mod-sfr 747> Executing S20cert-init
Mod-sfr 749>                                                                       [  OK  ]
Mod-sfr 750> Executing S21disable_estreamer
Mod-sfr 752>                                                                       [  OK  ]
Mod-sfr 753> Executing S25create_default_des.pl
Mod-sfr 755>                                                                       [  OK  ]
Mod-sfr 756> Executing S30init_lights_out_mgmt.pl
Mod-sfr 758>                                                                       [  OK  ]
Mod-sfr 759> Executing S40install_default_filters.pl
Mod-sfr 761>                                                                       [  OK  ]
Mod-sfr 762> Executing S42install_default_dashboards.pl
Mod-sfr 764>                                                                       [  OK  ]
Mod-sfr 765> Executing S43install_default_report_templates.pl
Mod-sfr 767>                                                                       [  OK  ]
Mod-sfr 768> Executing S44install_default_app_filters.pl
Mod-sfr 770>                                                                       [  OK  ]
Mod-sfr 771> Executing S45install_default_realms.pl
Mod-sfr 773>                                                                       [  OK  ]
Mod-sfr 774> Executing S47install_default_sandbox_EO.pl
Mod-sfr 776>                                                                       [  OK  ]
Mod-sfr 777> Executing S50install-remediation-modules
Mod-sfr 779>                                                                       [  OK  ]
Mod-sfr 780> Executing S51install_health_policy.pl
Mod-sfr 782>                                                                       [  OK  ]
Mod-sfr 783> Executing S52install_system_policy.pl
Mod-sfr 785>                                                                       [  OK  ]
Mod-sfr 786> Executing S53change_reconciliation_baseline.pl
Mod-sfr 788>                                                                       [  OK  ]
Mod-sfr 789> Executing S53createcsds.pl
Mod-sfr 791>                                                                       [  OK  ]
Mod-sfr 792> Executing S70remove_casuser.pl
Mod-sfr 794>                                                                       [  OK  ]
Mod-sfr 795> Executing S70update_sensor_objects.sh
Mod-sfr 797>                                                                       [  OK  ]
Mod-sfr 798> Executing S85patch_history-init
Mod-sfr 800>                                                                       [  OK  ]
Mod-sfr 801> Executing S90banner-init
Mod-sfr 803>                                                                       [  OK  ]
Mod-sfr 804> Executing S95copy-crontab
Mod-sfr 806>                                                                       [  OK  ]
Mod-sfr 807> Executing S96grow_var.sh
Mod-sfr 809>                                                                       [  OK  ]
Mod-sfr 810> Executing S96install_sf_whitelist
Mod-sfr 812>                                                                       [  OK  ]
Mod-sfr 813> Executing S96install_vmware_tools.pl
Mod-sfr 815>                                                                       [  OK  ]
Mod-sfr 816> ********** Attention **********
Mod-sfr 817>    Initializing the system's localization settings.  Depending on available
Mod-sfr 818>    system resources (CPU, memory, and disk), this may take 10 minutes
Mod-sfr 819>    or more to complete.
Mod-sfr 820> ********** Attention **********
Mod-sfr 821> Executing S96localize-templates
Mod-sfr 823>                                                                       [  OK  ]
Mod-sfr 824> Executing S96ovf-data.pl
Mod-sfr 826>                                                                       [  OK  ]
Mod-sfr 827> Executing S97compress-client-resources
Mod-sfr 829>                                                                       [  OK  ]
Mod-sfr 830> Executing S97create_platinum_forms.pl
Mod-sfr 832>                                                                       [  OK  ]
Mod-sfr 833> Executing S97install_cas
Mod-sfr 835>                                                                       [  OK  ]
Mod-sfr 836> Executing S97install_cloud_support.pl
Mod-sfr 838>                                                                       [  OK  ]
Mod-sfr 839> Executing S97install_geolocation.pl
Mod-sfr 841>                                                                       [  OK  ]
Mod-sfr 842> Executing S97install_ssl_inspection.pl
Mod-sfr 843>
Mod-sfr 844>                                                                       [  OK  ]
Mod-sfr 845> Executing S97update_modprobe.pl
Mod-sfr 847>                                                                       [  OK  ]
Mod-sfr 848> Executing S98check-db-integrity.sh
Mod-sfr 850>                                                                       [  OK  ]
Mod-sfr 851> Executing S98htaccess-init
Mod-sfr 853>                                                                       [  OK  ]
Mod-sfr 854> Executing S99correct_ipmi.pl
Mod-sfr 856>                                                                       [  OK  ]
Mod-sfr 857> Executing S99start-system
Mod-sfr 859>                                                                       [  OK  ]
Mod-sfr 860> Executing S99z_db_restore
Mod-sfr 862>                                                                       [  OK  ]
Mod-sfr 863> Firstboot scripts finished.
Mod-sfr 864> Model reconfigure detected, executing scripts
Mod-sfr 865> Pinging mysql
Mod-sfr 866> Found mysql is running
Mod-sfr 867> Executing 45update-sensor.pl
Mod-sfr 869>                                                                       [  OK  ]
Mod-sfr 870> Executing 55recalculate_arc.pl
Mod-sfr 872>                                                                       [  OK  ]
Mod-sfr 873> Sat Sep 1 08:14:05 UTC 2018
Mod-sfr 874> Starting MySQL...
Mod-sfr 875> Pinging mysql
Mod-sfr 876> Pinging mysql, try 1
Mod-sfr 877> Pinging mysql, try 2
Mod-sfr 878> Found mysql is running
Mod-sfr 879> Running initializeObjects...
Mod-sfr 880> Stopping MySQL...
Mod-sfr 881> Killing mysqld with pid 25084
Mod-sfr 882> Wait for mysqld to exit\c
Mod-sfr 883>  done
Mod-sfr 884> Sat Sep 1 08:14:31 UTC 2018
Mod-sfr 885> Warning: speed or duplex not found in config file for eth0, using defaults...
Mod-sfr 886> Warning: speed or duplex not found in config file for eth1, using defaults...
Mod-sfr 887> modprobe: FATAL: Module ipmi_si not found in directory /lib/modules/3.10.107sf.cis
Mod-sfr 888> co-1
Mod-sfr 889> Starting Cisco ASA5506W, please wait...No PM running!
Mod-sfr 890> ...started.
Mod-sfr 891> Sep 01 08:14:39 firepower SF-IMS[25476]: [25476] init script:system [INFO] pmmon S
Mod-sfr 892> etting affinity to 0-2...
Mod-sfr 893> pid 25470's current affinity list: 0-2
Mod-sfr 894> pid 25470's new affinity list: 0-2
Mod-sfr 895> Sep 01 08:14:39 firepower SF-IMS[25478]: [25478] init script:system [INFO] pmmon T
Mod-sfr 896> he Process Manager is not running...
Mod-sfr 897> Sep 01 08:14:39 firepower SF-IMS[25479]: [25479] init script:system [INFO] pmmon S
Mod-sfr 898> tarting the Process Manager...
Mod-sfr 899> Sep 01 08:14:39 firepower SF-IMS[25480]: [25480] pm:pm [INFO] Using model number 7
Mod-sfr 900> 2L
Mod-sfr 901> Cisco ASA5506W v6.2.3 (build 83)
Mod-sfr 902> firepower login: [ 3415.334125] SFHS[25481] - kvm_ivshmem: Set max latency to 0 ms
Mod-sfr 903> ecs (0 jiffies)
Mod-sfr 904> [ 3415.634339] tun: Universal TUN/TAP device driver, 1.6
Mod-sfr 905> [ 3415.637233] tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Mod-sfr 906> [ 3415.856560] IPv6: ADDRCONF(NETDEV_UP): tun1: link is not ready
Mod-sfr 907> [ 3415.910195] SFIVMSHM info: Initializing Channel 0 Client Descriptor Base...
Mod-sfr 908> [ 3415.913545] SFIVMSHM info: Initializing Channel 1 Client Descriptor Base...
Mod-sfr 909> [ 3415.916864] SFIVMSHM info: Initializing packet buffer pool...
Mod-sfr 910> [ 3415.920552] SFIVMSHM info: Initializing packet buffer pool done!
Mod-sfr 911> [ 3416.605560] SFIVMSHM info: Shared Memory start addr = ffffc90000780000 size = 1
Mod-sfr 912> 6777216
Mod-sfr 913> [ 3416.609306] SFIVMSHM info: magicNum = 0x2a1337 version = 3 asa_state = INIT_COM
Mod-sfr 914> PLETE ips_state = INIT_COMPLETE lineStatus = 1 mode = 0 totalSize = 16777216
Mod-sfr 915> [ 3416.616441] SFIVMSHM info: Channel Info ch_count = 2
Mod-sfr 916> [ 3416.619320] SFIVMSHM info:   Channel Info #0: [TS pool_offset = 0 nextToRead =
Mod-sfr 917> 0 nextToWrite = 0 count = 1008 pad = 0]
Mod-sfr 918> [ 3416.624716] SFIVMSHM info:   Channel Info #0: [FS pool_offset = 36288 nextToRea
Mod-sfr 919> d = 0 nextToWrite = 0 count = 1008 pad = 0]
Mod-sfr 920> [ 3416.629861] SFIVMSHM info:   Channel Info #1: [TS pool_offset = 72576 nextToRea
Mod-sfr 921> d = 0 nextToWrite = 0 count = 1008 pad = 0]
Mod-sfr 922> [ 3416.635064] SFIVMSHM info:   Channel Info #1: [FS pool_offset = 108864 nextToRe
Mod-sfr 923> ad = 0 nextToWrite = 0 count = 1008 pad = 0]
Mod-sfr 924> [ 3416.640207] SFIVMSHM info: Packet Buffer pools [server start=147456 count=6902
Mod-sfr 925> size=14135296] [client start=14282752 count=1218 size=2494464] [pktbuf_size = 2048
Mod-sfr 926> [ 3416.648790] SFIVMSHM info: Allocated 165648 bytes for the array of 6902 IvmShm
Mod-sfr 927> Buffers.
Mod-sfr 928> [ 3416.654218] SFIVMSHM info: [25696]: Ring kvm_ivshmem - RX/TX thread created and
Mod-sfr 929>  started (ffff880088c85180)
Mod-sfr 930> [ 3416.659003] SFIVMSHM info: [25696]: Ring kvm_ivshmem - Done with index -1 and r
Mod-sfr 931> val 0
Mod-sfr 932> [ 3416.890538] IPv6: ADDRCONF(NETDEV_CHANGE): tun1: link becomes ready
Mod-sfr 933> [ 3460.547530] SFPacket_AFBP: Copied first heartbeat for future use (78 bytes)


ASA5506W-X# show module      // SFR WENT UP AFTER 1.5 HOURS 

Mod  Card Type                                    Model              Serial No.
---- -------------------------------------------- ------------------ -----------
   0 ASA 5506-X with FirePOWER services, WiFi, 8G ASA5506W           JAD20080123
 sfr FirePOWER Services Software Module           ASA5506W           JAD20080123
wlan WLAN AP                                      N/A                N/A       

Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version    
---- --------------------------------- ------------ ------------ ---------------
   0 0078.884b.bf62 to 0078.884b.bf6b  2.0          1.1.8        9.8(2)38
 sfr 0078.884b.bf61 to 0078.884b.bf61  N/A          N/A          6.2.3-83
wlan none                              N/A          N/A         

Mod  SSM Application Name           Status           SSM Application Version
---- ------------------------------ ---------------- --------------------------
 sfr ASA FirePOWER                  Up               6.2.3-83

Mod  Status             Data Plane Status     Compatibility
---- ------------------ --------------------- -------------
   0 Up Sys             Not Applicable       
 sfr Up                 Up                   
wlan Up                 Up   


ASA5506W-X# show module sfr details
Getting details from the Service Module, please wait...

Card Type:          FirePOWER Services Software Module
Model:              ASA5506W
Hardware version:   N/A
Serial Number:      JAD20080123
Firmware version:   N/A
Software version:   6.2.3-83
MAC Address Range:  0078.884b.bf61 to 0078.884b.bf61
App. name:          ASA FirePOWER
App. Status:        Up
App. Status Desc:   Normal Operation
App. version:       6.2.3-83
Data Plane Status:  Up
Console session:    Ready
Status:             Up
DC addr:            No DC Configured                                           
Mgmt IP addr:       192.168.45.45                                              
Mgmt Network mask:  255.255.255.0                                              
Mgmt Gateway:       0.0.0.0                                                    
Mgmt web ports:     443                                                        
Mgmt TLS enabled:   true 


Don't forget to disable the debug command (or just type undebug all). The default login is still: admin / Admin123

Once login, you'll need to access the End User License Agreement (EULA) and configure the FirePower module IP address.


ASA5506W-X# no debug module-boot
debug module-boot  disabled.

ASA5506W-X# session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.

Cisco ASA5506W v6.2.3 (build 83)
firepower login: admin
Password:  <Admin123>

Copyright 2004-2018, Cisco and/or its affiliates. All rights reserved.
Cisco is a registered trademark of Cisco Systems, Inc.
All other trademarks are property of their respective owners.

Cisco Fire Linux OS v6.2.3 (build 13)
Cisco ASA5506W v6.2.3 (build 83)

Last login: Sat Sep  1 08:01:01 UTC 2018 on cron
Last login: Sat Sep  1 08:22:42 UTC 2018 on ttyS1
You must accept the EULA to continue.
Press <ENTER> to display the EULA: <ENTER>
End User License Agreement

Effective: May 22, 2017

This is an agreement between You and Cisco Systems, Inc. or its affiliates
("Cisco") and governs your Use of Cisco Software. "You" and "Your" means the
individual or legal entity licensing the Software under this EULA. "Use" or
"Using" means to download, install, activate, access or otherwise use the
Software. "Software" means the Cisco computer programs and any Upgrades made
available to You by an Approved Source and licensed to You by Cisco.
"Documentation" is the Cisco user or technical manuals, training materials,
specifications or other documentation applicable to the Software and made
available to You by an Approved Source. "Approved Source" means (i) Cisco or
(ii) the Cisco authorized reseller, distributor or systems integrator from whom
you acquired the Software. "Entitlement" means the license detail; including
license metric, duration, and quantity provided in a product ID (PID) published
on Cisco's price list, claim certificate or right to use notification.
"Upgrades" means all updates, upgrades, bug fixes, error corrections,
enhancements and other modifications to the Software and backup copies thereof.

This agreement, any supplemental license terms and any specific product terms
at www.cisco.com/go/softwareterms (collectively, the "EULA") govern Your Use of
the Software.

1. Acceptance of Terms. By Using the Software, You agree to be bound by the
terms of the EULA. If you are entering into this EULA on behalf of an entity,
you represent that you have authority to bind that entity. If you do not have
such authority or you do not agree to the terms of the EULA, neither you nor
the entity may Use the Software and it may be returned to the Approved Source
for a refund within thirty (30) days of the date you acquired the Software or
Cisco product. Your right to return and refund applies only if you are the
original end user licensee of the Software.

2. License. Subject to payment of the applicable fees and compliance with this
EULA, Cisco grants You a limited, non-exclusive and non-transferable license to
Use object code versions of the Software and the Documentation solely for Your
internal operations and in accordance with the Entitlement and the
Documentation. Cisco licenses You the right to Use only the Software You
acquire from an Approved Source. Unless contrary to applicable law, You are not
licensed to Use the Software on secondhand or refurbished Cisco equipment not
authorized by Cisco, or on Cisco equipment not purchased through an Approved
Source. In the event that Cisco requires You to register as an end user, Your
license is valid only if the registration is complete and accurate. The
Software may contain open source software, subject to separate license terms
made available with the Cisco Software or Documentation.

If the Software is licensed for a specified term, Your license is valid solely
for the applicable term in the Entitlement. Your right to Use the Software
begins on the date the Software is made available for download or installation
and continues until the end of the specified term, unless otherwise terminated
in accordance with this Agreement.

3. Evaluation License. If You license the Software or receive Cisco product(s)
for evaluation purposes or other limited, temporary use as authorized by Cisco
("Evaluation Product"), Your Use of the Evaluation Product is only permitted
for the period limited by the license key or otherwise stated by Cisco in
writing. If no evaluation period is identified by the license key or in
writing, then the evaluation license is valid for thirty (30) days from the
date the Software or Cisco product is made available to You. You will be
invoiced for the list price of the Evaluation Product if You fail to return or
stop Using it by the end of the evaluation period. The Evaluation Product is
licensed "AS-IS" without support or warranty of any kind, expressed or implied.
Cisco does not assume any liability arising from any use of the Evaluation
Product. You may not publish any results of benchmark tests run on the
Evaluation Product without first obtaining written approval from Cisco. You
authorize Cisco to use any feedback or ideas You provide Cisco in connection
with Your Use of the Evaluation Product.

4. Ownership. Cisco or its licensors retain ownership of all intellectual
property rights in and to the Software, including copies, improvements,
enhancements, derivative works and modifications thereof. Your rights to Use
the Software are limited to those expressly granted by this EULA. No other
rights with respect to the Software or any related intellectual property rights
are granted or implied.

5. Limitations and Restrictions. You will not and will not allow a third party
to:

a. transfer, sublicense, or assign Your rights under this license to any other
person or entity (except as expressly provided in Section 12 below), unless
expressly authorized by Cisco in writing;

b. modify, adapt or create derivative works of the Software or Documentation;

c. reverse engineer, decompile, decrypt, disassemble or otherwise attempt to
derive the source code for the Software, except as provided in Section 16
below;

d. make the functionality of the Software available to third parties, whether
as an application service provider, or on a rental, service bureau, cloud
service, hosted service, or other similar basis unless expressly authorized by
Cisco in writing;

e. Use Software that is licensed for a specific device, whether physical or
virtual, on another device, unless expressly authorized by Cisco in writing; or

f. remove, modify, or conceal any product identification, copyright,
proprietary, intellectual property notices or other marks on or within the
Software.

6. Third Party Use of Software. You may permit a third party to Use the
Software licensed to You under this EULA if such Use is solely (i) on Your
behalf, (ii) for Your internal operations, and (iii) in compliance with this
EULA. You agree that you are liable for any breach of this EULA by that third
party.

7. Limited Warranty and Disclaimer.

a. Limited Warranty. Cisco warrants that the Software will substantially
conform to the applicable Documentation for the longer of (i) ninety (90) days
following the date the Software is made available to You for your Use or (ii)
as otherwise set forth at www.cisco.com/go/warranty. This warranty does not
apply if the Software, Cisco product or any other equipment upon which the
Software is authorized to be used: (i) has been altered, except by Cisco or its
authorized representative, (ii) has not been installed, operated, repaired, or
maintained in accordance with instructions supplied by Cisco, (iii) has been
subjected to abnormal physical or electrical stress, abnormal environmental
conditions, misuse, negligence, or accident; (iv) is licensed for beta,
evaluation, testing or demonstration purposes or other circumstances for which
the Approved Source does not receive a payment of a purchase price or license
fee; or (v) has not been provided by an Approved Source. Cisco will use
commercially reasonable efforts to deliver to You Software free from any
viruses, programs, or programming devices designed to modify, delete, damage or
disable the Software or Your data.

b. Exclusive Remedy. At Cisco's option and expense, Cisco shall repair,
replace, or cause the refund of the license fees paid for the non-conforming
Software. This remedy is conditioned on You reporting the non-conformance in
writing to Your Approved Source within the warranty period. The Approved Source
may ask You to return the Software, the Cisco product, and/or Documentation as
a condition of this remedy. This Section is Your exclusive remedy under the
warranty.

c. Disclaimer.

Except as expressly set forth above, Cisco and its licensors provide Software
"as is" and expressly disclaim all warranties, conditions or other terms,
whether express, implied or statutory, including without limitation,
warranties, conditions or other terms regarding merchantability, fitness for a
particular purpose, design, condition, capacity, performance, title, and
non-infringement. Cisco does not warrant that the Software will operate
uninterrupted or error-free or that all errors will be corrected. In addition,
Cisco does not warrant that the Software or any equipment, system or network on
which the Software is used will be free of vulnerability to intrusion or
attack.

8. Limitations and Exclusions of Liability. In no event will Cisco or its
licensors be liable for the following, regardless of the theory of liability or
whether arising out of the use or inability to use the Software or otherwise,
even if a party been advised of the possibility of such damages: (a) indirect,
incidental, exemplary, special or consequential damages; (b) loss or corruption
of data or interrupted or loss of business; or (c) loss of revenue, profits,
goodwill or anticipated sales or savings. All liability of Cisco, its
affiliates, officers, directors, employees, agents, suppliers and licensors
collectively, to You, whether based in warranty, contract, tort (including
negligence), or otherwise, shall not exceed the license fees paid by You to any
Approved Source for the Software that gave rise to the claim. This limitation
of liability for Software is cumulative and not per incident. Nothing in this
Agreement limits or excludes any liability that cannot be limited or excluded
under applicable law.

9. Upgrades and Additional Copies of Software. Notwithstanding any other
provision of this EULA, You are not permitted to Use Upgrades unless You, at
the time of acquiring such Upgrade:

a. already hold a valid license to the original version of the Software, are in
compliance with such license, and have paid the applicable fee for the Upgrade;
and

b. limit Your Use of Upgrades or copies to Use on devices You own or lease; and

c. unless otherwise provided in the Documentation, make and Use additional
copies solely for backup purposes, where backup is limited to archiving for
restoration purposes.

10. Audit. During the license term for the Software and for a period of three
(3) years after its expiration or termination, You will take reasonable steps
to maintain complete and accurate records of Your use of the Software
sufficient to verify compliance with this EULA. No more than once per twelve
(12) month period, You will allow Cisco and its auditors the right to examine
such records and any applicable books, systems (including Cisco product(s) or
other equipment), and accounts, upon reasonable advanced notice, during Your
normal business hours. If the audit discloses underpayment of license fees, You
will pay such license fees plus the reasonable cost of the audit within thirty
(30) days of receipt of written notice.

11. Term and Termination. This EULA shall remain effective until terminated or
until the expiration of the applicable license or subscription term. You may
terminate the EULA at any time by ceasing use of or destroying all copies of
Software. This EULA will immediately terminate if You breach its terms, or if
You fail to pay any portion of the applicable license fees and You fail to cure
that payment breach within thirty (30) days of notice. Upon termination of this
EULA, You shall destroy all copies of Software in Your possession or control.

12. Transferability. You may only transfer or assign these license rights to
another person or entity in compliance with the current Cisco
Relicensing/Transfer Policy (www.cisco.com/c/en/us/products/
cisco_software_transfer_relicensing_policy.html). Any attempted transfer or,
assignment not in compliance with the foregoing shall be void and of no effect.

13. US Government End Users. The Software and Documentation are "commercial
items," as defined at Federal Acquisition Regulation ("FAR") (48 C.F.R.) 2.101,
consisting of "commercial computer software" and "commercial computer software
documentation" as such terms are used in FAR 12.212. Consistent with FAR 12.211
(Technical Data) and FAR 12.212 (Computer Software) and Defense Federal
Acquisition Regulation Supplement ("DFAR") 227.7202-1 through 227.7202-4, and
notwithstanding any other FAR or other contractual clause to the contrary in
any agreement into which this EULA may be incorporated, Government end users
will acquire the Software and Documentation with only those rights set forth in
this EULA. Any license provisions that are inconsistent with federal
procurement regulations are not enforceable against the U.S. Government.

14. Export. Cisco Software, products, technology and services are subject to
local and extraterritorial export control laws and regulations. You and Cisco
each will comply with such laws and regulations governing use, export,
re-export, and transfer of Software, products and technology and will obtain
all required local and extraterritorial authorizations, permits or licenses.
Specific export information may be found at: tools.cisco.com/legal/export/pepd/
Search.do

15. Survival. Sections 4, 5, the warranty limitation in 7(a), 7(b) 7(c), 8, 10,
11, 13, 14, 15, 17 and 18 shall survive termination or expiration of this EULA.

16. Interoperability. To the extent required by applicable law, Cisco shall
provide You with the interface information needed to achieve interoperability
between the Software and another independently created program. Cisco will
provide this interface information at Your written request after you pay
Cisco's licensing fees (if any). You will keep this information in strict
confidence and strictly follow any applicable terms and conditions upon which
Cisco makes such information available.

17. Governing Law, Jurisdiction and Venue.

If You acquired the Software in a country or territory listed below, as
determined by reference to the address on the purchase order the Approved
Source accepted or, in the case of an Evaluation Product, the address where
Product is shipped, this table identifies the law that governs the EULA
(notwithstanding any conflict of laws provision) and the specific courts that
have exclusive jurisdiction over any claim arising under this EULA.


Country or Territory     | Governing Law           | Jurisdiction and Venue
=========================|=========================|===========================
United States, Latin     | State of California,    | Federal District Court,
America or the           | United States of        | Northern District of
Caribbean                | America                 | California or Superior
                         |                         | Court of Santa Clara
                         |                         | County, California
-------------------------|-------------------------|---------------------------
Canada                   | Province of Ontario,    | Courts of the Province of
                         | Canada                  | Ontario, Canada
-------------------------|-------------------------|---------------------------
Europe (excluding        | Laws of England         | English Courts
Italy), Middle East,     |                         |
Africa, Asia or Oceania  |                         |
(excluding Australia)    |                         |
-------------------------|-------------------------|---------------------------
Japan                    | Laws of Japan           | Tokyo District Court of
                         |                         | Japan
-------------------------|-------------------------|---------------------------
Australia                | Laws of the State of    | State and Federal Courts
                         | New South Wales         | of New South Wales
-------------------------|-------------------------|---------------------------
Italy                    | Laws of Italy           | Court of Milan
-------------------------|-------------------------|---------------------------
China                    | Laws of the People's    | Hong Kong International
                         | Republic of China       | Arbitration Center
-------------------------|-------------------------|---------------------------
All other countries or   | State of California     | State and Federal Courts
territories              |                         | of California
-------------------------------------------------------------------------------


The parties specifically disclaim the application of the UN Convention on
Contracts for the International Sale of Goods. In addition, no person who is
not a party to the EULA shall be entitled to enforce or take the benefit of any
of its terms under the Contracts (Rights of Third Parties) Act 1999. Regardless
of the above governing law, either party may seek interim injunctive relief in
any court of appropriate jurisdiction with respect to any alleged breach of
such party's intellectual property or proprietary rights.

18. Integration. If any portion of this EULA is found to be void or
unenforceable, the remaining provisions of the EULA shall remain in full force
and effect. Except as expressly stated or as expressly amended in a signed
agreement, the EULA constitutes the entire agreement between the parties with
respect to the license of the Software and supersedes any conflicting or
additional terms contained in any purchase order or elsewhere, all of which
terms are excluded. The parties agree that the English version of the EULA will
govern in the event of a conflict between it and any version translated into
another language.


Cisco and the Cisco logo are trademarks or registered trademarks of Cisco
and/or its affiliates in the U.S. and other countries. To view a list of Cisco
trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks
mentioned are the property of their respective owners. The use of the word
partner does not imply a partnership relationship between Cisco and any other
company. (1110R)

Please enter 'YES' or press <ENTER> to AGREE to the EULA:   <ENTER>

System initialization in progress.  Please stand by. 
You must change the password for 'admin' to continue.
Enter new password:   <cisco>
Confirm new password:   <cisco>
You must configure the network to continue.
You must configure at least one of IPv4 or IPv6.
Do you want to configure IPv4? (y/n) [y]:
Do you want to configure IPv6? (y/n) [n]:
Configure IPv4 via DHCP or manually? (dhcp/manual) [manual]:
Enter an IPv4 address for the management interface [192.168.45.45]: 192.168.1.2
Enter an IPv4 netmask for the management interface [255.255.255.0]:
Enter the IPv4 default gateway for the management interface []: 192.168.1.1
Enter a fully qualified hostname for this system [firepower]: ASA5506X-FP
Enter a comma-separated list of DNS servers or 'none' []: 8.8.8.8
Enter a comma-separated list of search domains or 'none' [example.net]: lab.com
If your networking information has changed, you will need to reconnect.
For HTTP Proxy configuration, run 'configure network http-proxy'

Creating default Identity Policy.
Creating default SSL Policy.

Update policy deployment information
    - add device configuration
    - add network discovery
    - add system policy
    - add access control policy
    - applying access control policy

You can register the sensor to a Firepower Management Center and use the
Firepower Management Center to manage it. Note that registering the sensor
to a Firepower Management Center disables on-sensor Firepower Services
management capabilities.

When registering the sensor to a Firepower Management Center, a unique
alphanumeric registration key is always required.  In most cases, to register
a sensor to a Firepower Management Center, you must provide the hostname or
the IP address along with the registration key.
'configure manager add [hostname | ip address ] [registration key ]'

However, if the sensor and the Firepower Management Center are separated by a
NAT device, you must enter a unique NAT ID, along with the unique registration
key.
'configure manager add DONTRESOLVE [registration key ] [ NAT ID ]'

Later, using the web interface on the Firepower Management Center, you must
use the same registration key and, if necessary, the same NAT ID when you add
this sensor to the Firepower Management Center.

> show version
Last login: Sat Sep  1 08:28:06 UTC 2018 on pts/0
------------------[ ASA5506X-FP ]-------------------
Model                     : ASA5506W (72) Version 6.2.3 (Build 83)
UUID                      : 45094da6-adb7-11e8-b474-c2bbe704956c
Rules update version      : 2017-09-13-001-vrt
VDB version               : 290
----------------------------------------------------


You can view the FirePOWER module status and its details in ASDM under ASA FirePOWER Status tab.


You'll need to re-login in order for ASDM to initialize the FirePOWER module. I tried to connect via ASDM from outside but a pop-up message appeared saying it can't connect to the FirePOWER module. Either you connect via VPN or the Management 1/1 interface is on the same local switch/VLAN with the management PC (running ASDM).


I tried using the ASDM from inside and the new FirePOWER module tabs appeared: ASA FirePOWER Dashboard and ASA FirePOWER Reporting.



No comments:

Post a Comment