16-12
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 16 ASA FirePOWER (SFR) Module
Configure the ASA FirePOWER Module
Step 3
Set the ASA FirePOWER module boot image location in ASA disk0 by entering the following command:
hostname#
sw-module module sfr recover configure image disk0:
file_path
If you get a message like “ERROR: Another service (cxsc) is running, only one service is allowed to run
at any time,” it means that you already have a different software module configured. You must shut it
down and remove it to install a new module as described in the prerequisites section above.
Example:
hostname#
sw-module module sfr recover configure image
disk0:asasfr-5500x-boot-5.3.1-58.img
Step 4
Load the ASA FirePOWER boot image by entering the following command:
hostname#
sw-module module sfr recover boot
Step 5
Wait approximately 5-15 minutes for the ASA FirePOWER module to boot up, and then open a console
session to the now-running ASA FirePOWER boot image. You might need to press enter after opening
the session to get to the login prompt. The default username is
admin
and the default password is
Admin123
.
hostname#
session sfr console
Opening console session with module sfr.
Connected to module sfr. Escape character sequence is 'CTRL-^X'.
Cisco ASA SFR Boot Image 5.3.1
asasfr login:
admin
Password:
Admin123
If the module boot has not completed, the
session
command will fail with a message about not being
able to connect over ttyS1. Wait and try again.
Step 6
Use the
setup
command to configure the system so that you can install the system software package.
asasfr-boot>
setup
Welcome to SFR Setup
[hit Ctrl-C to abort]
Default values are inside []
You are prompted for the following. Note that the management address and gateway, and DNS
information, are the key settings to configure.
•
Host name—Up to 65 alphanumeric characters, no spaces. Hyphens are allowed.
•
Network address—You can set static IPv4 or IPv6 addresses, or use DHCP (for IPv4) or IPv6
stateless autoconfiguration.
•
DNS information—You must identify at least one DNS server, and you can also set the domain name
and search domain.
•
NTP information—You can enable NTP and configure the NTP servers, for setting system time.
Step 7
Install the System Software image using the
system install
command:
system install
[
noconfirm
]
url
Include the
noconfirm
option if you do not want to respond to confirmation messages. Use an HTTP,
HTTPS, or FTP URL; if a username and password are required, you will be prompted to supply them.
When installation is complete, the system reboots. Allow 10 or more minutes for application component
installation and for the ASA FirePOWER services to start. (The
show module sfr
output should show
all processes as Up.)
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......