Table Of Contents
Cisco ASA 5500 Series Release Notes Version 7.0(8)
Determining the Software Version
Upgrading to a New Software Release
Enhancement—failover timeout Command
Enhancement—show access-list Output
Enhancement—show asp drop Output
Enhancement—show asp table classify Command
Enhancement—show asp table counters Command
Enhancement—show conn Command Syntax
Enhancement—show perfmon Command
Enhancement—static Command Error Message
Hostname and Domain Name Limitation
ACS Radius Authorization Server
Readme Document for the Conduits and Outbound List Conversion Tool 1.2
Features not Supported in Version 7.0
Obtaining Documentation and Submitting a Service Request
Cisco ASA 5500 Series Release Notes Version 7.0(8)
June 2008Contents
This document includes the following sections:
•
Obtaining Documentation and Submitting a Service Request
Introduction
The Cisco ASA 5500 series adaptive security appliance delivers unprecedented levels of defense against threats to the network with deeper web inspection and flow specific analysis, improved secure connectivity through end-point security posture validation and voice and video over VPN support. It also provides enhanced support for intelligent information networks through improved network integration, resiliency, and scalability. This release introduces enhancements to the following areas: firewall services, and management/monitoring.
For more information on all the new features, see New Features, page 3.
Additionally, the Cisco ASA 5500 series adaptive security appliance software supports Adaptive Security Device Manager. ASDM is a browser-based, Java applet used to configure and monitor the software on the security appliances. ASDM is loaded from the adaptive security appliance, then used to configure, monitor, and manage the device.
System Requirements
The sections that follow list the system requirements for operating a Cisco ASA 5500 series adaptive security appliance. This section includes the following topics:
•
Determining the Software Version
•
Upgrading to a New Software Release
Memory Requirements
Table 1 lists the DRAM memory requirements for the Cisco ASA 5500 series adaptive security appliance.
Table 1 DRAM Memory Requirements
ASA Model DRAM MemoryASA 5510
256 MB
ASA 5520
512 MB
ASA 5540
1 GB
All Cisco ASA 5500 series adaptive security appliances require a minimum of 64 MB of internal CompactFlash.
Determining the Software Version
Use the show version command to verify the software version of your Cisco ASA 5500 series adaptive security appliance.
Upgrading to a New Software Release
If you have a Cisco.com (CDC) login, you can obtain software from the following website:
http://www.cisco.com/public/sw-center/index.shtml
New Features
Version 7.0(8) includes the following new features:
Enhancement—capture Command
The capture asp type asp-drop all command will capture all packets that the security appliance drops.
Enhancement—failover timeout Command
The failover timeout command no longer requires a failover license for use with the static nailed feature.
Enhancement—fragment Command
The fragment command was enhanced with the reassembly full keywords to enable full reassembly for fragments that are routed through the device. Fragments that terminate at the device are always fully reassembled.
Enhancement—show access-list Output
Expanded access list output is indented to make it easier to read.
Enhancement—show arp Output
In transparent firewall mode, you might need to know whether an ARP entry is statically configured or dynamically learned. ARP inspection drops ARP replies from a legitimate host if a dynamic ARP entry has already been learned. ARP inspection only works with static ARP entries. The show arp command now shows each entry with its age if it is dynamic, or no age if it is static.
Enhancement—show asp drop Output
The show asp drop command output now includes a timestamp indicating when the counters were last cleared (see the clear asp drop command). It also displays the drop reason keywords next to the description, so you can easily use the capture asp-drop command using the keyword.
Enhancement—show asp table classify Command
An enhancement was made to the show asp table classify command to only show rules that have a hits value not equal to zero. The enhanced show asp table classify hits command, enables for a quick review of what rules are being hit, especially since a simple configuration may end up with hundreds of entries in the show asp table classify command.
Enhancement—show asp table counters Command
Added a timestamp indicating when the show asp table counters were cleared. This enhancement is to keep track of the time the user executed the command and who executed the command, this would allow the user to know how long it had been since the counters were last cleared.
Enhancement—show conn Command Syntax
The syntax was simplified to use source and destination concepts instead of "local" and "foreign." In the new syntax, the source address is the first address entered and the destination is the second address. The old syntax used keywords like foreign and port to determine the destination address and port.
Enhancement—show perfmon Command
Added the following rate outputs: TCP Intercept Connections Established, TCP Intercept Attempts, TCP Embryonic Connections Timeout, and Valid Connections Rate in TCP Intercept.
Enhancement—static Command Error Message
An error message is generated if an actual interface IP address is used instead of the keyword interface when configuring static PAT.
Ethertype ACL MAC Enhancement
EtherType ACLs have been enhanced to allow non-standard MACs. Existing default rules are retained, but no new ones need to be added.
Local Address Pool Edit
Address pools can be edited without affecting the desired connection. If an address in use is not being eliminated from the pool, the connection is not affected. However, if the address in use is being eliminated from the pool, the connection is brought down.
New—clear asp table Command
Added the clear asp table command to clear the hits output by the show asp table commands.
New—clear conn Command
The clear conn command lets you clear connections, including a specific connection between hosts on particular ports. The existing clear local-host command clears all connections between two IP addresses (on all ports), so the new clear conn command offers greater control.
New—memory tracking Commands
The following new commands are introduced in this release:
•
memory tracking enable-This command enables the tracking of heap memory requests.
•
no memory tracking enable-This command disables tracking of heap memory requests, cleans up all currently gathered information, and returns all heap memory used by the tool itself to the system.
•
clear memory tracking-This command clears out all currently gathered information but continues to track further memory requests.
•
show memory tracking-This command shows currently allocated memory tracked by the tool, broken down by the topmost caller function address.
•
show memory tracking address-This command shows currently allocated memory broken down by each individual piece of memory. The output lists the size, location, and topmost caller function of each currently allocated piece memory tracked by the tool.
•
show memory tracking dump-This command shows the size, location, partial callstack, and a memory dump of the given memory address.
•
show memory tracking detail-This command shows various internal details to be used in gaining insight into the internal behavior of the tool.
Syslog Enhancements
In addition to updated syslogs for failover, SNMP, and IPSec, the following new syslogs were added: syslog for cleared TCP urgent flag, and syslog for aggressive mode aborted when spoofed.
Important Notes
This section lists important notes related to Version 7.0(8).
Common Criteria EAL4+
For information on common criteria EAL4+, see the Installation and Configuration for Common Criteria EAL4 Evaluated Cisco Adaptive Security Appliance, Version 7.0(6) document.
FIPS 140-2
Cisco ASA 5510, 5520, and 5540 adaptive security appliances are FIPS 140-2, Level 2 validated. You can view the official certificate (#655) via the following URL:
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140crt/140crt655.pdf
See the FIPS 140-2 Non-Proprietary Security Policy for the Cisco ASA 5500 Series Security Appliance at the following URL:
http://www.cisco.com/en/US/docs/security/asa/asa70/hw/fips_asa.html
Hostname and Domain Name Limitation
When using ASDM, the hostname and domain names combined should not be more than 63 characters long. If the hostname and domain names combined is more than 63 characters, you will get an error message.
WebVPN ACLS and DNS Hostname
When a deny webtype URL ACL (DNS-based) is defined, but the DNS-based URL is not reachable, a "DNS Error" popup is displayed on the browser. The ACL hitcounter is also not incremented.
If the URL ACL is defined by an IP instead of DNS name, then the traffic flow hitting the ACL will be recorded in the hitcounter and a "Connection Error" is displayed on the browser.
Proxy Server and ASA
If WebVPN is configured to use an HTTP(S)-proxy server to service all requests for browsing HTTP and/or HTTPS sites, the client/browser may expect the following behavior:
1.
If the ASA cannot communicate with the HTTPS or HTTPS proxy server, a "connection error" is displayed on the client browser.
2.
If the HTTP(S) proxy cannot resolve or reach the requested URL, it should send an appropriate error to the ASA, which in turn will display it to the client browser.
Only when the HTTP(S) proxy server notifies the ASA of the inaccessible URL, can the ASA notify the error to the client browser.
Mismatch PFS
The PFS setting on the VPN client and the adaptive security appliance must match.
ACS Radius Authorization Server
When certificate authentication is used in conjunction with Radius authorization, the ACS server sends a bogus Group=CISCOACS:0003b9c6/5a940131/username and is displayed in the vpn-session database.
Readme Document for the Conduits and Outbound List Conversion Tool 1.2
The Cisco ASA 5500 series adaptive security appliance Outbound/Conduit Conversion tool assists in converting configurations with outbound or conduit commands to similar configurations using ACLs. ACL-based configurations provide uniformity and leverage the powerful ACL feature set. ACL based configurations provide the following benefit:
•
ACE Insertion capability - System configuration and management is greatly simplified by the ACE insertion capability that allows users to add, delete or modify individual ACEs.
User Upgrade Guide
•
For a list of deprecated features, and user upgrade information, go to the following URL:
http://www.cisco.com/en/US/docs/security/asa/asa70/vpn3000_upgrade/upgrade/guide/migr_vpn.html
Features not Supported in Version 7.0
The following features are not supported in Version 7.0(8):
•
PPPoE
•
L2TP over IPSec
•
PPTP
MIB Supported
For information on MIB Support, go to: http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml
Downgrade to Previous Version
To downgrade to a previous version of the operating system software (software image), use the downgrade command in privileged EXEC mode. For more information and a complete description of the command syntax, see the Cisco Security Appliance Command Reference.
Caveats
The following sections describe the caveats for the Version 7.0(8).
For your convenience in locating caveats in Cisco's Bug Toolkit, the caveat titles listed in this section are drawn directly from the Bug Toolkit database. These caveat titles are not intended to be read as complete sentences because the title field length is limited. In the caveat titles, some truncation of wording or punctuation may be necessary to provide the most complete and concise description. The only modifications made to these titles are as follows:
•
Commands are in boldface type.
•
Product names and acronyms may be standardized.
•
Spelling errors and typos may be corrected.
Note
If you are a registered cisco.com user, view Bug Toolkit on cisco.com at the following website:
http://www.cisco.com/cgi-bin/Support/Bugtool/launch_bugtool.pl
To become a registered cisco.com user, go to the following website:
http://tools.cisco.com/RPF/register/register.do
Open Caveats
Table 2 lists the open caveats for Version 7.0(8).
Resolved Caveats
Table 3 lists the resolved caveats for Version 7.0(8).
Related Documentation
For additional information on the Cisco ASA 5500 series adaptive security appliance, see the following URL on Cisco.com: http://www.cisco.com/en/US/products/ps6120/tsd_products_support_series_home.html
Obtaining Documentation and Submitting a Service Request
For information on obtaining documentation, submitting a service request, and gathering additional information, see the monthly What's New in Cisco Product Documentation, which also lists all new and revised Cisco technical documentation, at:
http://www.cisco.com/en/US/docs/general/whatsnew/whatsnew.html
Subscribe to the What's New in Cisco Product Documentation as a Really Simple Syndication (RSS) feed and set content to be delivered directly to your desktop using a reader application. The RSS feeds are a free service and Cisco currently supports RSS version 2.0.
This document is to be used in conjunction with the documents listed in the "Related Documentation" section.
CCVP, the Cisco logo, and the Cisco Square Bridge logo are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn is a service mark of Cisco Systems, Inc.; and Access Registrar, Aironet, BPX, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, IP/TV, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, iQuick Study, LightStream, Linksys, MeetingPlace, MGX, Networking Academy, Network Registrar, Packet, PIX, ProConnect, ScriptShare, SMARTnet, StackWise, The Fastest Way to Increase Your Internet Quotient, and TransPath are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0711R)
© 2008 Cisco Systems, Inc.
All rights reserved.

