Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.4.3(9) – 03/22/2012

Files:  asa843-9-k8.bin, asa843-9-smp-k8.bin

Defects resolved since 8.4.3(8):

 

CSCta06013

Fuzzing testbed, traceback in the javascript parser

CSCtf79704

ASA -crasActGrNumUsers does not update tunnel groups after upgrade

CSCtn40707

assert traceback for ifc cfg removal with same-security intra-interface

CSCtr44930

Nested obj does not work if contained in src and dst of ACL

CSCts89642

 'show mroute' has null Outgoing Interface List for (*,G) entry w/ bidir

CSCts89806

'Route-Lookup' Option Should be Allowed if One Real Interface is Known

CSCtu42856

ASA: May fail FIPS Self-Test

CSCtu51799

Traceback in Thread Name: CP Processing

CSCtv00813

ASA NAT fails to due route look with any as destination interface

CSCtw72728

AdvCrypt: AnyConnect can connect but can't pass data

CSCtx02122

Post request for OCSP using non default port is missing the port number

CSCtx22242

HTTP TRACE method allowed when EASY-VPN enabled

CSCtx66538

ASA: Traceback in thread name EAPoUDP

CSCtx68075

ASA WebVPN breaking when Windows Patch KB2585542 is applied

CSCtx70122

ASA traceback in thread fover_parse while upgrading from 8.4.2 to 8.4.3

CSCtx73124

WEBVPN - upload of files larger then 2GB fails through CIFS

CSCtx81792

ASA: OSPF redist with prefix routemap advertises all static after reboot

CSCtx82637

tcp-proxy with skinny v17 inspection not allowing 7962 phone to register

CSCtx92801

ASA: Failover due to data channel failure when making IPS config changes

CSCty05763

ASA5585X PS0 does not send "entity power-supply" trap

CSCty32899

PDP context idle timer is reset when using the TID option in show cmd

 

 

Revision:  Version 8.4.3(8) – 03/01/2012

Files:  asa843-8-k8.bin, asa843-8-smp-k8.bin

Defects resolved since 8.4.3:

 

CSCsv94848

Warning message for, "igmp static-group" - affective should be effective

CSCsz04730

PIX/ASA: When route changes connections over IPSEC tunnel not torn down

CSCtj45148

ASA 8.3 upgrade traceback in thread pix_flash_config_thread

CSCtj79795

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtk97719

WebVPN & ASDM doesn't work on Chrome with AES & 3DES ciphers

CSCto34765

ASA may traceback in Thread Name: DATAPATH-1-1235 (ipsecvpn-crypto)

CSCto88412

Radius Proxy to SDI - AnyConnect prompts for next PASSCODE but shouldn't

CSCtq15197

WebVPN:flv file within the Flowplayer object is not mangled correctly

CSCtq88111

object group not cleared when used for pat pool

CSCtr31788

Standby ASA generates syslog 210005 while transmitting data on FTP

CSCtr38739

Link outage in Etherchannel causes interface down and failover

CSCtr44930

Nested obj does not work if contained in src and dst of ACL

CSCts10661

SSM-4GE doesn't handle unicast packets after "hw-module module 1 reset"

CSCts18480

ASA IKEv1 Traceback in vpnfol_thread_msg ike_fo_create_new_sa on Standby

CSCts42362

Message from ASA is not displayed about password complexity requirements

CSCts98806

Standby ASA 5585 Reporting Service Card Failure on Signature Update

CSCtt03492

ASA should not send data in the 3rd message of TCP 3WHS w/ LDAP over SSL

CSCtt13455

netflow: template only send once with default timeout-rate

CSCtt45090

ASA5505: Primary active unit crash due to mismatched host-limit license

CSCtt47502

show vpn-sessiondb does not show LZS compression stats for Anyconnect

CSCtt74695

wrong vpn-filter gets applied when peers have overlapping address space

CSCtt96526

SharePoint2010:Cannot create new document

CSCtt98991

ASA: Decrypted VPN packets dropped due to bad-tcp-cksum when using NAT-T

CSCtu00961

Some specific flash file doesn't work through WebVPN on ASA

CSCtu03117

npshim: Shared License Registration Fails w/ Empty TP applied to Int

CSCtu04723

vpnclient mac-exempt cmd inconsistent when adding more than 16 entries

CSCtu04754

ASA may traceback citing Thread Name: qos_metric_daemon as culprit

CSCtu10620

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtu14396

ASA has stale ASP classification entries for Anyconnect tunnels

CSCtu21128

cannot pass "=" sign within the value of a parameter for the SSH plugin

CSCtu26615

Clientless VPN paging application failure

CSCtu27846

Backup Shared license server remains ACTIVE even when the Master is up

CSCtu30581

ASA 5580 traceback when CSM attempts deployment

CSCtu39200

ASA traceback in emweb/https while bringing up many webvpn sessions

CSCtu42772

ASA webvpn doesn't rewrite some redirect messages properly

CSCtu57453

ASA: Traceback after removing 'ip address dhcp setroute' with DDNS

CSCtv19046

DACL is not applied to AC when connection via the webportal

CSCtv19854

Incorrect MPF conn counts cause %ASA-3-201011 and DoS condition for user

CSCtw45576

TCP sequence space check ignored in some cases

CSCtw45723

WebVPN: CIFS: Incorrect MIME type for PDF files - iPad/iPhone

CSCtw50362

ASA - Failover message may be lost during transition to active state

CSCtw52591

Environmental SNMP Traps Are Not Available on ASA5585 SSP-40

CSCtw52716

ASA5585 show inventory not updated

CSCtw55462

Traceback: assert failure on thread radius_snd

CSCtw56707

%ASA-3-201011: Connection limit exceeded when not hitting value

CSCtw56859

Natted traffic not getting encrypted after reconfiguring the crypto ACL

CSCtw58640

When ASA sends a username with a "\", WSA logs errors.

CSCtw58682

SSLVPN Portal uses incorrect DNS Group after failover

CSCtw58945

L2TP over IPSec connections fail with ldap authorization and mschapv2

CSCtw59562

ACL Hashes calculated during config migration are wrong

CSCtw60220

Port Address Translation (PAT) causes higher CPU after upgrade

CSCtw63996

Page fault traceback with thread name "pix_flash_config_thread".

CSCtw71420

ASA 5585-X does not provide aggregate system CPU load value via SNMP

CSCtw75613

ASA: Traceback in Unicorn Admin Handler when making DAP changes via ASDM

CSCtw78059

print warning if interface in logging host cmd conflicts with routes

CSCtw78415

ASA may reload with traceback in Dispatch Unit related to WAAS inspect

CSCtw84007

ASA does not recognize IPv6 VPN filter access-list for AnyConnect client

CSCtw84087

IKEv2: ASA does not re-establish more than one SA after disconnect

CSCtw89522

Cut-through proxy - users unable to log in

CSCtw90179

ASA:In a rare corner case ASA may crash while modifying FQDN object/acl

CSCtw93059

Page fault traceback in crypto_lib_keypair_show_mypubkey_all

CSCtw95487

ASA mem leak w/EZVPN when Subject DN has Multiple C,O,OU,CN fields.

CSCtx01251

ASA: May traceback in DATAPATH during capture

CSCtx03464

Standby ASA traceback in DATAPATH-0-1400 or Dispatch Unit

CSCtx08182

 Nas-Port attribute different for authentication and accounting

CSCtx08346

tunnel-group-preference not respected for AnyConnect 3.0 aggregate_auth

CSCtx08354

Traceback when memory low and memory profile enabled

CSCtx10196

Webvpn : Javascript rewrite causing login button to be inactive

CSCtx11578

ASA does not start DPD when phase 1 up but phase 2 down

CSCtx16166

ASA may not log syslogs 611101, 605005 for asdm sessions to certain int

CSCtx25170

Configuring a network object with an invalid range causes traceback

CSCtx25910

class-map doesn't work after replacing ACL

CSCtx28628

Clientless - VLAN assign't under group-policy breaks tunneled dflt route

CSCtx32455

SunRpc: Change from dynamic ACL to pin-hole mechanism

CSCtx33347

Standby ASA traceback while trying to replicate xlates

CSCtx36026

VPN session failure due to auth handle depletion

CSCtx38644

Webvpn: Can't copy & paste in web portal with IE8 and IE9

CSCtx42643

Received unexpected event EV_REMOVE in state AM_WAIT_DELETE

CSCtx42746

cut through proxy authentication vulnerability

CSCtx57829

Syslog 324001 Reason string is missing

CSCtx58556

ActiveX RDP Plugin fails to connect from WIn7 PC after upgrade to 8.4(3)

CSCtx62037

"X-CSTP-Tunnel-All-DNS" not properly set in SMP images for split-dns

CSCtx65353

ASA: 8.4 Page fault traceback while displaying "sh run threat-detection"

CSCtx69008

ASA: Page Fault traceback in ssh thread when changing IKEv2 config

CSCtx69018

MSFT KB2585542 breaks cut-thru proxy and IUA

CSCtx69059

Traceback in Unicorn Proxy Thread under heavy WebVPN load

CSCtx69498

Traceback when Converting ACL Remarks of 100 Characters

CSCty11414

ASA Crashes or Simply Reloads With Signal 11 in Unicorn Proxy Thread