Cisco
ASA Interim Release Notes
The software images listed below are Interim releases. They contain bug fixes which address specific issues found since the last Feature or Maintenance release. The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.
Important: These images were not fully regression tested. Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality. Keep this testing status in mind if you decide to run them in a production environment. We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.
Revision: Version 8.2.1(11) – 10/01/2009
Files: asa821-11-k8.bin, asa821-11-smp-k8.bin
Defects resolved since 8.2.1:
L2TP & NAC -> Default NAC policy prevents data from passing |
|
Syslog over TCP: Should try to reconnect periodically to the server |
|
ENH - Need ability to clear all captures simultaneously |
|
SIP CRLF keepalives stall TCP-based SIP connections |
|
hic-fail-group-policy command needs to be removed |
|
DAP: Increase DAP aggregation max lists lengths and make them dynamic |
|
SIP does not support 'early RTCP' |
|
PIX/ASA PMTUD: ICMP type 3 code 4 uses wrong source interface |
|
ASA traceback in Dispatch Unit (Old pc 0x00223a67 ebp 0x018b12f8) |
|
High CPU utilization due to OSPF |
|
match resp body length for http class-map doesnt take correct value |
|
traceback netfs_thread_init |
|
ASA decrements TTL twice with AIP module in policy |
|
When routes change, connections should be updated automatically |
|
context using SSM app in promiscuous mode shows incorrect memory usage |
|
Without authproxy currently configured, authproxy DACLs may become stale |
|
ASA: rate-limiting for encrypted s2s traffic not consistently handled |
|
WebVPN: Landing on application other than Home in portal |
|
"show asp table classify" doesn't show WCCP domain |
|
Implement "set connection timeout idle" for ASA/PIX |
|
traceback eip 0x08c4cab2 log_to_servers+1426 at /slib/include/channel.h |
|
Extend show ak47 to display per pool and per block information |
|
WEBVPN RDP plugin window keys are incorrect. Shift (key) .jar |
|
CIFS access to Win2008 server via IP address is not working. |
|
Telnet connection permitted to lowest security level interface |
|
Mapped named interfaces with certain names might not be seen in contexts |
|
ip audit attack config causes info signatures to be triggered |
|
WebVPN Full Customization with tunnel-group-list gives error in IE |
|
ASA 7.2.4.17 traceback at Thread Name: PIX Garbage Collector |
|
ASA may traceback with certain HTTP packets |
|
Webvpn memory leak in ramfs-blocks |
|
Numerous CPU-hogs in vpnfol_thread_timer |
|
Traceback on ASA during configuration of h323 inspection |
|
ASA 8.04 - certificate chain not being sent when configured w/ IPSEC RA |
|
L2TP with EAP auth stuck [%ASA-4-403102 - authentication pending] |
|
Multiple certificates are installed to one trustpoint when importing. |
|
Standby console freezes if user logs in prior to detecting mate |
|
ssl vpn related memory corruption causes traceback |
|
ENH Failover ability to switchover if FO LAN communication is severed |
|
PMTUD - ICMP type 3 code 4 generated for GRE flow is dropped 313005 |
|
Java Applet Signing Error..plugins still use old expired certificate |
|
sqlnet traffic causes traceback with inspection configured |
|
ASA does not decrement TTL for packet destined for VPN tunnel |
|
Remote access vpn unable to est after failover with DHCP assigned addr |
|
SACK is dropped when TCP inspection engines are used |
|
PP: phone cannot register when configured as Authenticated on UCM |
|
SSL VPN: Java-rewriter: memory leak implicating WebVPN |
|
AAA: ASA is not responding in time when wrong credentials are supplied |
|
ASA webvpn auto-signon cmd help for FTP incorrectly show CIFS auth type |
|
Identity cert being imported without errors, if conflicting with CA cert |
|
1550 block leaks leading active ASA to reload |
|
PIX/ASA LDAP authentication doesn't work over tunnel |
|
Traffic shaping with priority queueing causes packet delay and drops |
|
set nat-t-disable in crypto map does not override global nat-t config |
|
IGMP Join fails on subinterface after upgrade to 8.1(2) |
|
Wrong counters in "show int" for Redundant interface |
|
PPPoE re-negotiation does not start after short disconnect |
|
VPN: TCP traffic allowed on any port with management-access enabled. |
|
%PIX|ASA-3-713128 should be logged as a lower level message |
|
5580 traceback implicating snp_nat_find_portlist w/ stress test |
|
Entering interface ? from cmd specific config mode returns to global cfg |
|
ASDM might show 'n/a - config out of sync' for top ACLs |
|
SNMP traps for certain contexts not generated |
|
uauth inactivity timer not taking effect |
|
ASA/CSD - certificate mapping does not work if CSD is enabled |
|
static route: ASA should not accept static multicast routes |
|
WebVPN CIFS: uploading files fails sometimes to HomeServer |
|
Traceback during large ACL Compilation - driver ioctl call |
|
WebVPN: RDP Plugin does not work with ActiveX with large cert chain |
|
ip verify reverse-path interferes with packet-tracer's result output |
|
OCSP revocation stops working after some time on Cisco ASA |
|
Anyconnect unable to establish DTLS tunnel if ASA IP address change |
|
Adding shared interface to second context stops traffic to 1st context |
|
No focus on 'More information required' radius challenge/response page |
|
Traceback on telnet/ci from "show nat" command |
|
ASA may processe LDAP password policy with no password-management |
|
CSD: Unable to run smart-tunnel inside "browser only" vault |
|
SIP Inspection Doesn't NAT Call-info field in SIP Notify message |
|
ASA Local CA and caSe SenSiTiviTy - p12 file vs. username conflict |
|
ASA allows VPN user although Zonelabs Integrity firewall rejects |
|
Automatically added AAA command break ASA5505EasyVPN client after reboot |
|
Tacacs Command Accounting does not send packet for 'nat-control' |
|
aaa Page fault: Invalid permission when box is under moderate stress |
|
Page fault: Address not mapped with telnet traffic. eip and cr2 = 0 |
|
CIFS URI cutoff after 15 characters |
|
ASA traceback upon failover with interface monitor enabled |
|
High memory usage in chunk_create |
|
ASA - High CPU by function "branch_height" from CPU profile |
|
VMWARE web applications (view/vdm) do not work with smart-tunnel |
|
TCP Proxy drops the keepalives ACK sent on H225 conn, call gets dropped |
|
Traceback in thread name Dispatch Unit |
|
Stateful Conns Disappear From Standby During Failover |
|
CSD: Group-url fails in Vault. |
|
Adding shared interface to second context stops traffic to 1st context |
|
Crypto CA limited to 65536 requests |
|
ASA might automatically restart after issuing 'show vpdn' |
|
ASA 8.0.4 traceback in Thread Name: IKE Daemon |
|
WCCP Service Ports Missing in ASP Table when Adding Redirect ACL Entry |
|
AC with CSD and DAP for Posture Assement matches wrong DAP Policy |
|
Unpredictable behavior after failover w/shortest timeout conf. |
|
Adding host to http access results in Could not start Admin error |
|
ifHighSpeed and ifSpeed values are zero for 10G operational interfaces |
|
ifType values returns as other (1) for 10G interfaces |
|
PIX/ASA traceback with Thread Name: CMGR Server Process |
|
ASA5580-20 traceback in CP Processing |
|
Standby ASA traceback after becoming active, EIP snp_fp_inspect_dns+42 |
|
Syslog 113019 Disconnect reason not working |
|
Adding pause frame sending capability for ASA 5580 10GE interface |
|
Webvpn error recovery events caused by improper error handling |
|
no pim on one subif disables eigrp on same physical of 4 ge module |
|
process_create corrupt ListQ memory when MAX_THREAD is exceeded |
|
ASA Improve RADIUS accounting disconnect codes for vpn client |
|
Proper handling of robots.txt on Cisco ASA SSLVPN |
|
DDNS: A RR update fails if cache entry exists in show dns-host |
|
ASA might automatically restart in Thread Name: ppp_timer_thread |
|
Incorrectly submit wrong code |
|
The ASA traceback intermittent in IPSec |
|
Large CRLs freeze processing on the ASA for extended time periods |
|
File upload causes hang without recovery |
|
Traceback in Thread Name: aaa when using Anyconnect with certificate |
|
PP: ASA should not reply to pings sent to MTA with outside interface IP |
|
Failover pair is not able to sync config and stuck in Sync Config state |
|
Cisco ASA may traceback after processing certain TCP packets |
|
Smart Tunnels and POST parameters should be interoperable |
|
5505:high memory use, Panic:vpnfol_thread_init create main VPNFO_LIB thr |
|
ASA 8.2 Beta does not work with /31 subnet on failover interface config |
|
qos: traceback in thread name: ssh, eip mqc_get_blt_def |
|
Using phone-proxy got assertion "ip.ip_version == IP_VERSION_4" |
|
ESMTP inspection drops DKIM signatured emails with content-type |
|
inspect-mgcp: call-agent name and gateway name disappears after a reboot |
|
Keepalive not processed correctly thru TCP Proxy |
|
5505: High memory use, traceback in td_port_stat_update_timeout_func+142 |
|
Incorrect severity for ASA syslog message 106102 |
|
WebVPN OWA 2007 + AttachView Freezes IE6 and will not close |
|
allow-ssc-mgmt command under redundant interface configuration |
|
Names not supported in EIGRP summary-address command |
|
"clear crypto ipsec sa entry" command doesnt seem to work |
|
"clear crypto ipsec sa entry" command doesnt work |
|
Traceback due to illegal address access in Thread Name: DATAPATH-0-466 |
|
webvpn cifs unc url doesn't work |
|
Interface fails to pass traffic because soft-np shows interface as down |
|
ASA Traceback in Thread fover_FSM_thread with A/A FO testing |
|
Lua recovery errors observed during boot in multiple-context mode |
|
traceback in Dispatch Unit: Page fault: Address not mapped |
|
page fault while adding/enrolling users to Local CA w/script |
|
Tacacs connection match accounting does not display port information |
|
" crypto map does not hole match" message pops up during conditon debug |
|
Memory leak in 72 / 80 / 192 bytes memory blocks [ tmatch] |
|
Redundant interface as failover link lose peer route after reload |
|
Traceback on standby while processing write memory if context is removed |
|
AC asks for Username/Password after certs fail with group-url cert only |
|
Unable to SSH over remote access VPN (telnet, asdm working) |
|
WebVPN: hide internal password in customization doesn't work |
|
FW sends rst ack for tcp packet with L2 multicast mac not destined to it |
|
SSL rekey fails for AnyConnect when using client-cert authentication |
|
WebVPN: NTLM authentication does not work on a cu server |
|
ASA: traceback with thread name "email client" |
|
ASA 5580 reboots with traceback in threat detection |
|
Traceback when editing object-group |
|
WebVPN: ASA sends a bad If-Modified-Since header |
|
subintefaces on 4ge-ssm ports fail with mac-address auto and failover |
|
Traceback from thread DATAPATH-0-483 on failover |
|
asdm does not connect to secondary on failover |
|
Shared int Mac add auto reload primary there will be some packet loss |
|
Not able utilize search engine via webvpn |
|
Issue with RTP Pinhole timeout |
|
the procedure of copying a file from ramfs to flash should be atomic |
|
CPOC: Watchdog Traceback in snp_flow_free / snp_conn_release |
|
ASA: LDAP Password-expiry with Group-Lock locks users out |
|
ASA's DOM wrapper issue- Clientless XSS |
|
ASA WebVPN HTTP server issue-XSS |
|
WebVPN FTP and CIFS issue |
|
WebVPN: full customization disables dap message |
|
Sip inspection is dropping ftp secondary connection on port 5060 |
|
Traceback due to assert in Thread Name: DATAPATH-0-466 |
|
XSS via Host: header in WebVPN Request. |
|
WebVPN: ASA can't support IP/mask based NTLM SSO consistently |
|
ASA fails to redirect traffic to WCCP cache server |
|
Redundant interface is down if any member is down at boot |
|
Unable to add member interface to Redundant Interface |
|
AIP-SSM stays in Unresponsive state after momentary voltage drop |
|
websense restriction access page does not display |
|
Remove "Server:" directive from SSL replies when CSD enabled |
|
ASA5505 should not allow pkts to go thru prior to loading config |
|
ASA - Log messages for all subinterfaces seen when adding just one vlan |
|
ASA inspect pptp does not alter Call ID in inbound Set-Link-info packets |
|
Smart Tunnel failing on MAC 10.5.6 with Firefox 2 and Safari |
|
ESMTP inspection "match MIME filetype" matches on file content as well |
|
Memory leak in Webvpn related to CIFS |
|
ASA doesn't properly handle large SubjectAltName field - UPN parse fails |
|
Using name aliases for the interface will cause vpn lb to break |
|
Traceback in Thread Name: Dispatch Unit (Old pc 0x081727e4 ebp 0xaad3cd1 |
|
DWA 8.5: Unable to send an e-mail with attachment. |
|
asa in tfw mode reboots on ping to ipv6 addr with no ipv6 addr on box |
|
WebVPN Flash rewriter may not clean up all temporary files |
|
SNMP community string not hidden in 'show startup' or 'show conf' |
|
Memory leaked when matching tunnel group based on URL |
|
Support for Macro insertion for auto-signon commd for non-forms apps |
|
Traceback on Thread Name: AAA due to downloadable ACL processing |
|
Access-list allows port ranges with start-port greater than end-port |
|
Logging standby can create logging loop with syslogs 418001 and 106016 |
|
Long delay before standby becomes active if unit holdtime misconfigured |
|
Unexpect Syslog: No SPI to identify Phase 2 SA |
|
ASA traceback in inspect Skinny |
|
ASA: scp connection fails with error: unexpected filename |
|
console hangs for extended period of time when config-url is applied |
|
Management port in promiscuous mode processes packets not destined to it |
|
TCP Proxy mis-calculates TCP window causing connectivity problems |
|
ASA intermittently drops traffic for authenticated users w/auth-proxy |
|
L2TP: DACL w/ Wildcard Mask not applied to L2TP over IPSec Clients |
|
Certificate mapping does not override the group chosen by URL |
|
webpage showing missing content. |
|
ASA disconnects IPSec VPN client at P2 rekey with vlan mapping in grppol |
|
Stuck EIGRP ASP entry prevents neighbor from coming up |
|
CRL request failure for Local CA server after exporting and importing |
|
ASA: If CA cert import fails will delete id cert under same trustpoint |
|
Remove ability to add WebVPN group-alias with non-English chars via CLI |
|
Traceback in thread SSH related to using help in policy-map config mode |
|
"switch ingress policy drops" are corrupted every 65535 packets |
|
PIX/ASA don't generate syslog 305005 on nat-rpf-failed counter increase |
|
acl-netmask-convert auto-detect cannot convert wildcard mask of 0.0.0.0 |
|
Session MIB to mirror sh vpn-sessiondb summary doesn't show proper info |
|
Failover pair with CSC-SSM: High CPU usage by SSM Accounting Thread |
|
OCSP connection failures leaks tcp socket causing sockets to fail |
|
"vpn-simultaneous-logins 0" does not prevent user access in all cases |
|
Customization editor: wrong URL of Save icon (text link is OK) |
|
ASA SSLVPN: Error contacting hosts when auto-signon configured |
|
Floating toolbar missing for ARWeb (Remedy) via clientless WebVPN |
|
Reseting the AIP module may cause the ASA to reload with a traceback |
|
ASA 5510 traceback with skinny inspection and phone proxy |
|
AC re-directed to IP address instead of hostname causes cert error |
|
Anyconnect fails to launch if interface ip address is mapped to a name |
|
Port Forwarding creates memory leak |
|
Traceback in capture when adding a dataplane match command |
|
Enhancement request to have the RDP plugin working with Portuguese keys |
|
PIX/ASA: L2L RRI routes removed after failover when using originate-only |
|
PP: One way audio between out-phones when they are behind a Nat router |
|
WebVPN: RDP plug-in SSO fails. |
|
ASA traceback in Thread Name: Dispatch Unit with TCP intercept |
|
1550 Block Depletions leading to unresponsiveness |
|
ASA 5580 traceback in failover with DATAPATH-3-555 thread |
|
WebVPN: Specific RSS feed give blank page |
|
Burst Traffic causes underrun when QoS shaping is enabled on ASA |
|
Webvpn ACL that permits on tcp with no range does not work using DAP |
|
ASA should reject unuseable ip pool config |
|
ASA5580 snmpget will not provide output for certain OIDs |
|
Memory leak in 72 / 80 bytes memory blocks [ tmatch] |
|
Stateful Failover looses connections following link down |
|
IP address in RTSP Reply packet payload not translated |
|
Smart Tunnels and POST params should support "\" in the username |
|
WebVPN: ST on Mac should popup the tunneled application when started |
|
Strip Realm for WebVPN broken in 8.2, also implement strip-group |
|
IPsec/TCP fails due to corrupt SYN+ACK from ASA when SYN has TCP options |
|
CSD: flash:/sdesktop/data.xml file gets truncated when it is > 64kB |
|
L2TP with EAP auth stuck [%ASA-4-403102 - authentication pending] |
|
Traceback on Standby unit during configuration sync |
|
InCorectly added "Host Scan File Check e.g 'C:\' " breaks DAP Policies |
|
vpn-sessiondb : Address sorting is incorrect |
|
DAP dap.xml file corrupt after replication |
|
ASA 8.2.1 reloads in "ldap_client_thread" on "Get AD Groups" via ASDM |
|
WebVPN: IE shows secure/unsecure items messages |
|
sh vpn-sessiondb displays incorrect peer for dynamic to static l2l |
|
dhcprelay issue after configuration changes in multi context mode |
|
Traceback - Thread Name: Dispatch Unit with skinny inspect enabled |
|
Citrix ICA on Macintosh over Smart Tunnel fails |
|
WebVPN: Disabling CIFS file-browsing still allows shares to be viewed. |
|
Clientless WebVPN memory leak in rewriter while compressing/decompressin |
|
ASA5580 interfaces does not come up when interfaces are shut/no shut |
|
Syslogs are incorrectly logged at level 0 - emergencies |
|
coredump.cfg file gets rewritten every time show run is executed |
|
Traceback when threat detection is disabled and using jumbo frames |
|
ASA - traceback in datapath |
|
Traceback in Thread Name: Dispatch Unit, Page fault |
|
Duplicate shun exemption lines allowed in configuration |
|
Traceback in ak47 debug command. |
|
Clientless SSL VPN Script Errors when accessing DWA 8.5 |
|
WebVPN: Silverlight player does not appear |
|
WebVPN: Flash does not play video |
|
WebVPN:Silverlight player does not play |
|
WebVPN: JavaScript does not process an expression correctly |
|
Memory leak associated with WebVPN inflate sessions |
|
MAC Smart Tunnel fails for certain Java web-applications |
|
webvpn: Issue w/ processing cookie with quoted value of expire attribute |
|
IGMP Join From Second Interface Fails to Be Processed |
|
SQLNET query via inspection cause communication errors |
|
ASA traceback in Thread Name: Unicorn Proxy Thread |
|
traceback: netfs_request+289 at netfs/netfs_api.c:89 |
|
Clientless Webvpn is not working with SAP adobe/acrobat forms |
|
ASA 5580 traceback in thread name DATAPATH-0-550 |
|
Exhaustion of 256 byte blocks and traceback in fover_serial_rx |
|
WEBVPN - CIFS needs to be able to ask IPV4 address from DNS |
|
ASA WEBVPN causes javascript error when using a ASP.NET application |
|
n2h2 Redirect Page Fails To Forward Under Load |
|
vpn-framed-ip-address does not accept /32 netmask |
|
Traceback in Thread Name: DATAPATH-2-567 |
|
CPU Hog in IKE Daemon |
|
'Per-User-Override' Keyword Removed from an 'Access-Group' Line |
|
PIX/ASA: IOS ezvpn ipsec decompression fails with ASA as ezvpn server |
|
Clientless SSL: Citrix Web Interface XenApps 5.1 client detection fails |
|
Traceback in Datapath-1-480 |
|
Active/Active FO fails when using a shared interface with the same name |
|
The logic for tunnel group list to anyconnect is incorrect |
|
L2TP still has auth stuck [%ASA-4-403102 - authentication pending] |
|
PAT Replication failures on ASA failover |
|
WebVPN: RDP plugin shell parameter not working for ActiveX |
|
Standby ASA leaking memory in webvpn environment |
|
WebVPN: SAP Adobe Acrobat form does not send POST |
|
Traceback in Thread Name: aaa |
|
"show service-policy" output for policing shows wrong "actions: drop" |
|
ASA VPN dropping self-sourced ICMP packets (PMTUD) |
|
POST plugin uses Port 80 by default even when csco_proto=https |
|
Smart tunnel bookmark failed with firefox browser |
|
Strip-realm is not working with L2TP-IPSEC connection type |
|
"show conn detail" does not indicate actual timeout |
|
H323: Disable H323 inspect in one context affects H323 inspect in other |
|
Group requiring cert-auth not shown in AnyConnect Group-List |
|
WebVPN: Plugin parameter "csco_sso=1" doesn't work in browser favorites |
|
WebVPN: Plugin parameter "csco_sso=1" doesn't work with "=" in password |
|
WebVPN: XML parser and tags with dot. |
|
"Lost connection to firewall" Message in ASDM with "&" in nameif |
|
WebVPN: wrong arg count in Flash rewriter |
|
ASA traceback in Thread Name: Dispatch Unit, Abort: Assert Failure |
|
WebVPN - PeopleSoft issue |
|
Traceback when adding "crypto ca server user-db email-otp" |
|
ASA5580 8.1.2 without NAT RTSP inspection changes video server's IP |
|
ASA WEBVPN page rendering issue with forms and Modal dialog |
|
H323 inspection fails when multiple TPKT messages in IP packet |
|
ASA: Threat Detection may not release all TD hosts upon disabling |
|
Group Alias no longer accepts spaces - Broadview |
|
WebVPN Traceback in Unicorn Proxy while rewriting Java applets |
|
Doc: RDP Plugin /?console=yes parameter |
|
Inspect ESMTP messages have flipped source and destination |
|
ASA SMP traceback in CP Midpath Processing |
|
ASA traceback has affected failover operation |
|
assert in thread DATAPATH-1-467 on ASA5580 |
|
show chunkstat should not output empty sibling chunks |
|
memory leak in SNP Conn Core exhausts all memory via chunk_create |
|
When CRL cache is empty revocation check falls back to "NONE" |
|
Policy NAT ignored if source port used in access-list |
|
8.2 Auto Signon domain parameter does not work with CIFS |
|
Trustpoint certificate will not be updated after re-enrollment |
|
WebVPN: rewriter adds port 80 to server without checking |
|
ASA tracebacks in Thread Name: vPif_stats_cleaner |
|
Traceback in Thread Name: PIX Garbage Collector |
|
MAC OS VMWARE web applications VDI do not work with smart-tunnel |
|
Unnecessary SNAP frame is sent when redundant intf switchover occurs |
|
Show service-policy output needs to be present in show tech |
|
WEBVPN: page fault in thread name dispath unit, eip udpmod_user_put |
|
AAA session limit reached with cert-only authentication |