Cisco ASA 9.2 on Cisco ASA 5505 with Unsupported Memory Configuration Fail

EDIT: 16/11/2015 – It looks like it now works. I am currently running¬†asa924-2-k8.bin on my 5505s, with my 1GB sticks of RAM, and it hasn’t complained! ūüôā

The Cisco ASA 5505 officially supports a maximum of 512MB RAM.

Last year I wrote a post detailing a small experiment I done where I upgrade both my Cisco ASA 5505s to use 1GB sticks of RAM, double the officially supported value.

Since then, it has worked great and both boxes have been chilling out in my rack, but recently Cisco released ASA 9.2.

The full list of new features and changes can be read in the release notes, but the feature I was most excited about was BGP support being added.

The ASA has had OSPF support for some time, but it was lacking BGP, which I always thought was a feature it should have. Now that it has been added, I was quite excited to play with it!

So I grabbed the latest 9.1 image (asa921-k8.bin), and dropped it on both my ASAs. Switched the bootloader configuration to load the new image. Next I reloaded the secondary device, and waited for it to come back up. Half an hour later, nothing. So I connected a serial cable to see what’s up, and to my surprise I find that it not doing anything. It’s just stuck saying:

Loading disk0:/asa921-k8.bin...

Initially I wasn’t really sure what was causing this, so I tried switching out the RAM and putting the stock 512MB stick that I got with the box, and magic! It worked.

I’m quite disappointed that my 1GB sticks won’t work with 9.2, but it’s not a huge loss. My Cacti graphs I only use around 300MB anyway!

Memory Usage on my Cisco ASA 5505s
Memory Usage on my Cisco ASA 5505s

I’m going to have to buy a 512MB stick for my secondary¬†ASA, as now they refuse to be in a failover configuration¬†due to having different software versions and different memory sizes.

Alternatively, I’m thinking of just replacing these boxes with something else. My ISP (Virgin Media) will be upgrading my line to 152Mbit/s¬†later this year. The ASA 5505 only has 100Mbit ports so I will be losing 52Mbits! I don’t want that, so I’ll have to get something faster. I’ll probably either go with just a custom Linux box with IPtables, or maybe a virtual ASA now that Cisco offers that! ūüôā

Home Lab: Added a Cisco 3845 ISR

Why? Well, I wanted more ISRs in my home lab.

That, plus my ISP (Virgin Media), will be upgrading my line from 120mbit to 152mbit in the second half of 2014. Looking at the Cisco docs, the 2851 ISR I am using can only do up to around 112mbit/s.

Although there is a long time for my ISP to go forward with this upgrade, I saw the 3845 going reasonably cheap on eBay, cheaper than what I expect it will be next year when my ISP WILL have upgraded my line. So, I decided to just buy it now. ūüôā

I am really starting to have a problem with space for my home lab. ¬†My rack is already pretty much fully populated, so I now have equipment on top of, and surrounding my rack. I don’t really have space for a second rack at the moment, so it looks like I can’t expand my lab any more for a while. Oh well. ūüôĀ

Two more Cisco 7204 VXRs Added to My Home Lab!

Cisco 7204 VXRs Last week, I was browsing eBay (as you do!), and noticed two Cisco 7204 VXR routers auctions which were about to end pretty soon, price was £0.99, and there were no bids! So, I figured I would go ahead and bid. To my surprise, I won both!

I managed to win one of them for ¬£20, and the other for ¬£0.99! ¬£20.99 for two 7204 VXRs isn’t bad at all, just a quick search on eBay shows that the NPE-300s,¬†which came with both routers, is generally selling for ¬£30, so I’m quite pleased.

The I/O controllers (C7200-I/O) are a bit old, and use DB-25 connector for the console port and not the normal RJ-45 that most Cisco devices use. The I/O controller don’t have any¬†Ethernet¬†ports either, but I did get some FastEthernet modules with both routers. I will probably upgrade the I/O controllers to¬†C7200-I/O-2FE/E some time this year, but for now, it’ll do. ūüôā

I now have three 7204 VXRs in my rack, the first one I bought last year some time.

In the picture:

  • Top 7204 VXR has: NPE-225, 128MB RAM,¬†C7200-I/O, Dual FastEthernet Module and an Enhanced ATM module (ATM PA-A3).
  • Middle 7204 VXR has: NPE-300 with 256MB RAM (if I remember correctly),¬†C7200-I/O, Single EthernetModule, and an¬†Enhanced ATM module (ATM PA-A3).
  • Bottom 7204 VXR has: NPE-300 with 256MB RAM (if I remember correctly),¬†C7200-I/O-2FE/E, and an¬†Enhanced ATM module (ATM PA-A3).

I’m not really sure if the Enhanced ATM modules will be of any use to me, as I don’t think it is possible to use them¬†back-to-back (please correct me if I am wrong!). I do want to get a few¬†Cisco PA-4T+ 4 Port Serial modules but that’s for later on.

Cisco CCNP Lab Kit

Cisco CCNA Lab Kit

UPDATE: You can see the latest pictures of my home lab on my “Home Lab” page

As I have pretty much completed my studies for the Cisco CCNA exams, I decided I would build up my lab so I could “practice” for the Cisco CCNP exams. A lot of people recommend using a simulator/emulator such as Dynamips, but I don’t think that works out to be just as good as using real hardware but that’s a different matter. ūüôā

I had originally bought my CCNA Lab Kit from the nice people at ITelligentsia so I decided I would buy the rest of my equipment from them as well.

My current lab consists of the following:

  • Cisco 1800 Series : 1x Cisco 1841 (I bought this¬†separately¬†from someone else)
  • Cisco 2600 Series: 1x Cisco 2610, 2x Cisco 2511XM, 1x Cisck 2621XM
  • Cisco 2500 Series: 2x Cisco 2501, 1x Cisck 2509
  • Cisco 1700 Series: 1x Cisco 1721 (I bought this¬†separately¬†from someone else)
  • Cisco Catalyst 3550 Series: 2x WS-C3550-24 SMI
  • Cisco Catalyst 2950 Series: 3x WS-C2950-12
  • Catalyst 2900 Series XL: 2x Cisco 2924XL
  • Cisco 2000 Series Wireless LAN Controller: AIR-WLC2006-K9
  • Cisco Aironet 1200 Series: Cisco Aironet 1231 (AIR-LAP1231G-E-K9)
  • 3x Cisco Unified IP Phone 7912G

Hopefully this will be enough to allow me to get going, although I REALLY need a new rack. My 24U rack is already full, so my UPS (4U), Server (4U) and new lab equipment are sitting on the floor, and being very difficult to get access to.

Hopefully I will be able to get two¬†from work in March as we will be moving offices, and from what I can tell, they will be getting new server racks. ūüôā

I also bought a UPS a few weeks ago, but I’ve had some trouble with it. The UPS is a PowerWare 5119 RM 3000VA UPS. I have connected a few of my routers to it, and left it charging for over 24 hours, but when I kill the power the UPS goes into a strange state in which it seems to keep switching on and off and lighting up random lights on the front. From Googling a bit, I found that I might need to change some settings using the management serial port. Unfortunately, the UPS does not use a “standard” serial pin out, so I will have to build a cable when I can. Hopefully I will be able to sort the issue, otherwise I will have to send it back to the place I bought it from for repair. ūüôĀ