AIP - SSM recreate the image in secondary ASA 5500 (failover) with virtual contexts

Hello guys,.

The scenario is as follows:

2 ASA 5500 with virtual contexts for failover.

The ASA elementary school has the work of the AIP-SSM20.

ASA school (which is in active / standby) has its SSM20 AIP to work now and everything is in production.

Someone tried to configure this 2nd AIP - SSM, changed the password and lost, so I tried to re - the image (without authorized passage recovery), but the connection fails on the TFTP server, where is the image of the AIP - SSM.

Now questions, documentation Cisco re-imaging view orders under ASA #.

but as this scenario has several virtual contexts the ASA # shell contains no IP address as you know (which I suppose is the reason why the ASA cannot download the image from the TFTP server) and switch to another context (ASA / admin #) re-imaging commands do not work (hw-module module 1... etc...).

What is the solution? Is there documentation for it (with security contexts)?

Thank you very much for reading ;) comment on possible solutions.

Yes,

Some things to keep in mind.

(1) run 'debug module start' on the SAA before running the command "hw-module module 1 recover boot. This will show you the ROMMON of the MSS output as it tries to make the new image and you can look for any errors.

(2) before trying to download from the SSM, first use a machine separate download tftp from your laptop. This will ensure the TFTP on your laptop works and confirm what directory (if any) that you can use as the file location.

(3) if the tftp download does not SSM, then the SSM is unable to properly connect to your laptop. You need a crossover cable to connect your laptop to the SSM. If you have a crossover cable, then you could try to connect the MSS and your laptop to a small hub, or configure a new vlan on your switch with only 2 ports and connect the MSS and your computer laptop this vlan 2 port.

(4) also try the download first at the end of the gateway to 0.0.0.0 since your laptop and the SSM will be on the same subnet. If this does not work then you can try a non-existent 30.0.0.4 address as gateway.

(5) understand that the IP address that you specify for the MSS using the command "configure the hw-module module 1 recover" is just temporary for download. Once an image is installed, then sitting at the module and run the "setup" command in order to configure the permanent address you want ure on external port of the SSM. This address in the "setup" command can the same as that used in the command 'get the 1 hw-module module configure' or a completely new (as in your case). Just make sure that you connect to the network just to what address you give.

Tags: Cisco Security

Similar Questions

  • 210 mobile G1: how to recreate the image on a laptop with Windows 7 210 installed on the device

    Hello

    I try to put an image that has been created in the image of fog service 1.2 and am having problems starting the fog in ipxe. I tried to update the chip set drivers and the network drivers with no luck. When you start first in ipxe, the machine acts like it wants to register the machine, but then it just keeps restarting. I can never get fog gui so that I can recreate the image on the machine. Any suggestions on what I need to do to make this work. I have 30 laptops to recreate the image.

    Thank you in advance,

    Angie

    Step 1: Copy the Source files to the PXE server

    In this step, you copy Windows PE source files to your PXE server.

    1. On your computer, click Start, point to programs, point to Microsoft Windows OPK or Windows AIK, and then click Windows PE tools command prompt.
      The menu shortcut opens a command prompt window and automatically sets environment variables to point to all the necessary tools. By default, all tools are installed in C:\Program Files\\Tools, where can be Windows OPK or Windows AIK.
    2. Run the Copype.cmd script. The script requires two arguments: architecture and destination location of the hardware store.
       
  • replaceable hard disk on almost identical machine or recreate the image?

    I have an old Dell Latitude D830, which seems to have a dead motherboard.

    Its backed up and photographed using Windows Image in Win 7 Ultimate.

    Search on ebay for an identical machine so that I can just swap the HARD drive or recreating the image.

    Those that I find is built within months of the mine, but have slightly improved processors.

    Mine has a core 2 duo t7250 and some that seem to be good have the same thing with a t7500.

    He screw it all or if it's similar enough for a HARD drive swap might work.

    If this isn't the case, a HARD swap disc then a new image perhaps?

    IF I bought a replacement motherboard would only be re-inage?

    Thanks for the help.

    As long as the Windows 7 Ultimate FULL retail sales license, you can transfer; read this part of my answer.

    If this is an upgrade license, you can transfer it to another computer, but you need an operating system that is installed to upgrade.

    When you move a BONE on another machine, clean install is the recommendation

  • Recreate the image MARCH issue 20

    When I try to recreate the image on my device on 20 MARCH with the ISO collection downloaded from the OCC and I burn the ISO as it says when booting from the DVD it gets to the menu to choose how I want to recreate the image and it crashes.  We never saw this, and how solve you this problem.  I had 3 different devices and they all do the same thing.

    Hi James.

    When I try to re-image my MARS 20 appliance with the recovery ISO downloaded from the CCO and I burn the ISO as it says when booting from the DVD it gets to the menu to select how I want to re-image and it locks up.  Has anyone ever seen this and how did you fix it.  I have had 3 different appliances and they all do the same thing.

    You are connected through the Console directly (VGA + PS/2 keyboard) device, right? If you are using a USB keyboard, try a PS/2 keyboard instead.

    In addition, if it is a model CS-MARCH 20, make sure you select option '1. Distributed March - controller Local", not the #3 option (i.e. option valid only for models generation material 2)."

    If none of the foregoing is the cause, then it looks like a problem with the burned disc.

    • Verify the signature MD5 from your local copy of the. ISO image file matches what is shown on cisco.com.
    • Re-burn the ISO image to a disc up, forcing a 'slow' burning speed (4 x or less), try a different brand of media as well (I ran into a few cases where when other media brands have been used, these types of questions went).
  • CC have reinstalled due to the failure of the system.  When opened in the image space RAW goes yellow spot, with blue background.  I reinstalled without effect.  At the opening, in RAW, the image is restored for future treatment.  Error occurs with both d

    CC have reinstalled due to the failure of the system.  When opened in the image space RAW goes yellow spot, with blue background.  I reinstalled without effect.  At the opening, in RAW, the image is restored for future treatment.  Error occurs with both dng and arw.  Ideas.

    Try the following:

    In the Camera Raw window, press Ctrl + K (Cmd + K on a Mac) to bring up the preferences.

    Uncheck the box processor graphics use.

    If that suits him, update your graphics driver may allow you to work with the checked graphics processor.

  • sensor to recreate the image via the service account?

    Hello, I have the following problem with a JOINT-2 (4.1.5 S211) module:

    I am able to get to the screen to login via SSH. I connect with my login and my password but the following error: cannot communicate with authenticationApp (getUserAccountConfig). Please contact your system administrator.

    You want to run cidDump? [No]: _

    I can, however, enter into the sensor via the service account. I tried to stop and restart the CID as well as restart the sensor, unfortunately without success. At this point, the only thing I know to do is run partition recovery for reimage the sensor - is it possible to do it on the service account?

    -Patrick

    Hello

    You use the set of user name and password? What happened to the sensor through telnet and HTTPS access? Are you facing the same problem with above all?

    If the password is correct then the engine of Authantication could have been corrupted.

    You can rebuild image of the sensor through the service account.

    Start the JOINT-2 to the maintenance partition:

    cat6k # hw - module module reset cf:1 module_number

    Session in the partition maintenance CLI:

    processor cat6k # session slot slot_number 1

    Connect to the partition maintenance CLI:

    Login: guest

    Password: cisco

    If it is possible, then you can recreate the application partition image:

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/csids/csids10/hwguide/hwclipr.htm#wp91045

    After you re-create the image restart us the JOINT-2 for the application partition:

    cat6k # hw - module module reset hdd:1 module_number

    Check that the JOINT-2 is online and that the version of the software is correct and that the status is ok:

    cat6k # see the module_number module

    Connect to the JOINT-2 application partition:

    processor cat6k # session slot slot_number 1

    You have to retrieve your backup configuration.

    Note the post if it helps.

    Ashish

  • Question on the CSC - ssm modules and aip - ssm in the ASA5500

    Is it true that the CSC - ssm and aip - ssm modules cannot coexist in the device of ASA5500 at the same time?

    Another issue is the site of cisco using the command keyword intra-interface involving NO IPSEC TRAFFIC, there are example of config/example

    It is true that the CSC - ssm and aip - ssm modules cannot coexist in the device of ASA5500 at the same time.

    It is not a sample configuration partitions on the spot yet. However, outside the control of the same security, you must the ordinary rule of translation to pass traffic. Also, because of the dynamic nature, it allows only one-way traffic. For example:

    NAT (inside) 10 192.168.1.0 255.255.255.0

    Global interface (10 Interior)

    Global (ouotside) 10 interface (is not required however)

    Sincerely,

    ~ AJ

  • Need to recreate the image tool for px4 - 300 d

    I have a PX4 - 300 d, which was not used for some time, and readers have been removed for something else. I'm looking to return to service as storage for a VMWare ESX host iSCSI. I put new readers in and started, it took a bit, but she finally found the dhco server and made an IP address. I can access the px4 - 300 d, but it's a secutiry configuration screen and I can't spent to set up the storage. Is complaining about the Security screen "can not configure security up to this storage is configured.

    So I'm in a catch 22, so I want to just reload the firmeware and start from scratch. There is no data on the drives, nothing in the configuration of the PX4 - 300 d, which is necessary.

    And the best thing is the big missed 30 days ago and support is not interested to talk to me. they will provide this utility? I know it exists they sent me a version of it about 2 years ago although he has failed, they had to send me a replacement unit.

    Anyone know how we can get a copy?

    Thank you

    Jmorrison919,

    The imager can be engaged on the forums, but you can contact support here:
    https://Lenovo-na-en.custhelp.com/app/ask/

  • I want to recreate the image on my laptop but I'm going to lose my microsoft software?

    I want to get my laptop reconfigured sometime soon, but I want to install my microsoft first pack, I can start on some work. But if I do, will I lose my through my laptop microsoft software being released image? and I have to install another new microsoft pack?
    Thanks, I hope you can help.

    Hi Sophie,.

    As long as you have a software license, after creating the image you can reinstall the same on your laptop!

  • Recreate the Image sensor 4235FE problem

    I can't connect to the device ID using SSH and account netrangr and su more late-root. But although I had the sign #, when I run the terminal command configures, he returned with a configuration not found message.

    Here's a screenshot...

    Last login: kills Jun 1 18:22:03 2004, by 10.31.166.30

    Sun Microsystems Inc. SunOS 5.8 generic February 2000

    Sun Microsystems Inc. SunOS 5.8 generic February 2000

    You have logged out of the 10 using vt100

    using DISPLAY = 10:0

    [email protected] / * /-inside: / usr/nr

    > su-root

    Password:

    Sun Microsystems Inc. SunOS 5.8 generic February 2000

    # configure terminal

    Configure: not found

    #

    I checked my working directory is the root. See below

    # pwd

    / root

    # ls - al

    Total 25490

    -rw - r - r - 1 root other 7784 11 May 15:01 - r

    drwxr-xr-x 4 root other 512 11 May 15:10.

    drwxr-xr-x 21 root root 512 20 May 16:03...

    drwx - 2 root root 512 .ssh December 6, 2001

    -rw - r - r - 1 root other 69680 r 11 May 15:00

    drwxr-xr-x 2 root other 512 tmp December 3, 2003

    Note that when I'm in the root, the cursor reads that #, it does not read XYX # where XYZ is the name of the sensor. Does this mean something? This is why I am unable to make the terminal command configures. The device also does NOT recognize the command configures the sensor either.

    What directory I was in before I can issue the terminal command configures. I connect remotely using ssh. The device's ID NetRanger 4235FE.

    Personally, I would get a free exchange on your old 4230-FE for a new 4235-FE. There is a bulletin for 4230-FE sensors that indicates that they are subject to a motherboard failure. Cisco to exchange your old 4230-FE for a current 4235-FE. Follow this link: (http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_field_notice09186a00801850de.shtml) and fill out the form. I traded my sensors 8 and got the last expedition just 2 weeks after submitting the paperwork. I find this very much, since the 4230's are anyway end of sale.

    Now, the answers to your questions:

    (1) the CD upgrade you received must be Version 4. (1) S47, this is your starting point.

    (2) to install the image on the sensor, that you should just hang a keyboard and the sensor screen, insert the upgrade CD and allow it to start. The installation process is very intuitive. After installation, the sensor will reboot. You can connect the sensor freshly installed with the name of user and password cisco/cisco.

    (3) see #2 above

    (4) the command and control interface is the port through which the sensor can be controlled and the interface through which it makes alarms to external sources. After the basic installation, you can connect to this interface with a cord connection (crossover) or via a switch (straight through) and use IDM (GUI of the probe).

    (5) see responses to the tightening of the bolts 2 and 4 above.

    2nd n ° 5) the 4230-FE and 4235-FE have all two CD players.

    (6) this is a good starting point for more information about the Cisco IDS sensors (http://www.cisco.com/pcgi-bin/Support/browse/psp_view.pl?p=Software:Cisco_IDS_Sensor_Software)

    I hope this helps.

    Don

  • Recreate the image on new computer or former

    When I reimage a machine with a license of Windows 7 OEM to an image that has a volume license at some point at the end of the preparation of the machine before I can return the OEM license to be able to use a volume license?  In order to not consume a volume license and use the OEM license that is on this unit.  Basically so we are not pay twice for a single machine.  If you could give me the steps on how to do it,

    Thank you

    Dave Aceret

    The fact is the Windows 7 Enterprise volume license is actually an upgrade license and to use it, the computer must be running a qualifying business of premium SKY version full retail or OEM, examples: Windows XP Professional, Windows Vista professional/ultimate, Windows 7 Professional/Ultimate Edition.

    In addition, the machine is supplied already with the OEM license as part of the purchase price. The only way that you would pay several times if the machine had come is pre-installed with say no eligible SKUs such as Windows XP Home Edition, Windows Vista Home Basic/Premium, Windows 7 Starter, Home Basic/Premium. Those is not eligible for the Windows 7 Enterprise, you must first upgrade to a SKU company before you can use Windows 7 Enterprise or professional VL.

  • External hard drive where the stored images has been corruptd. The images recorded, but now cannot connect with LR

    I got LR cc 2015 put in place so that the images have been imported on my external hard drive and lightroom files were stored there. This hard drive has failed, but I was able to save all my files (original) and I transferred to a new external hard drive. Now, I can't get LR to recognize the new drive and location. LR albums have? next to them. I would appreciate any help you can give me that I have try to reconnect LR with the new source of my images. Sorry, I'm not very technologically.

    Tom

    There are 153 images in this catalog, all on 1 external. Which does not seem right, or you expect very different numbers, could you give me an idea of what numbers you expect?

    This seems to be an empty catalog with any folder. It seems to me that you have opened an empty catalog somehow. Could you please try file-> open the recent item and see if any of the other catalogues listed is the one you want? If this does not work, could you please try to restore a recent backup of your catalog file and see if the situation is resolved?

  • Reinstall the image on HP Mini 210 HD with XP Pro

    I have not find a relocation or partition disc to create the original disk image, where can I find it for my HP Mini 210 HD?

    Yes, I tried to enter this part of the page, but the links everyone to bike to the front page!    I said something on this subject earlier today.   Now I just get an error HTTP 500 Internal Server Error when I click on the link that indicates the recovery media for XP.  (Sorry, is XP Home edition - too many computers!)

    http://h10025.www1.HP.com/ewfrf/wc/softwareCategory?OS=228&LC=en&cc=us&DLC=en&sw_lang=&product=4075983#N744

    I don't think it works anyway, as I was expecting to have a disk image or a DVD of recovery with the drivers and all.   My other HPs have a recovery partition, the Mini does not.

    Thank you

    Mary

  • Want to use my current logo and apply it to the images of clothing: is it possible with elements?

    I want a tool that will allow me to use my current logo and apply it to the images of clothing. Elements will be able to accomplish this task. I'm not a pro and you are looking for the best product from Adobe, these simple tasks.

    any suggestions will be very useful... Thank you

    You should be able to do this in Photoshop Elements.

    The drill is to isolate the logo in the background, and then copy/paste for the clothing.

    Suggest you download the free trial 30 days of PSE13 which is a fully functional program.

    Here are some prepared before:

    How can I add a logo to my photos?

  • VPN with ASA 5500 VPN with PIX 515E vs

    I wonder what are the differences between the use of an exisitng PIX 515E for VPN remote users as appossed to acquire an ASA 5500 VPN remote users? Information or advice are appreciated to help me lean toward one or the other.

    Craig

    According to the version of the code that you run on the PIX on the PIX or ASA VPN features must be the same. So if the choice is not based on differences in features, what else would help guide the choice? You can consider if the existing PIX has sufficient resources to add the extra processing VPN load or if you should put that on another box. You might consider that the PIX is an older product range, and his end is near, while the ASA is the product that is the strategic replacement for the PIX. Given a choice I probably prefer to use a technology newer than the old technology. I also believe that the ASA will give you more choice of technology to go forward (a way of better growth) while the PIX provides current capacity but no path of growth.

    On the other hand, there is the aspect of consider that using the existing PIX does not need not to buy something new and ASA would be an expense you have to cover in the budget. And for some people the budget constraint is an important consideration.

    HTH

    Rick

Maybe you are looking for