PIX 520 migration

Answered Question
Oct 17th, 2007
User Badges:

I have Pix 520(6.3(3)) and i'd like to replace it with one ASA5020 but the problem is in the old config ( Conduit ,Fixup,interfaces , VPN and...)

how can i convert the old config (6.3(3)) to the new one (7.2(2))

Correct Answer by JORGE RODRIGUEZ about 9 years 8 months ago

Hi Rafael, there is currently no config conversion tools from goint to one platform of PIX to ASA that Im aware of, if you were upgrading code 6.3 to 7.x on same box the conversion would happened in the upgrade process but not in your case. Is your config a very extensive config on the 520?

I would suggest though to go over this link to reference depricated features that PIX uses and have either been replaced or removed on versions 7.x, for example condult has been depricated and replaced by way of acls , by refering to this link you can start building config on the 5520 ASA platform based on this information.


http://www.cisco.com/en/US/docs/security/asa/asa70/pix_upgrade/upgrade/guide/pixupgrd.html#wp1811886


HTH

Jorge



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
JORGE RODRIGUEZ Wed, 10/17/2007 - 07:54
User Badges:
  • Green, 3000 points or more

Hi Rafael, there is currently no config conversion tools from goint to one platform of PIX to ASA that Im aware of, if you were upgrading code 6.3 to 7.x on same box the conversion would happened in the upgrade process but not in your case. Is your config a very extensive config on the 520?

I would suggest though to go over this link to reference depricated features that PIX uses and have either been replaced or removed on versions 7.x, for example condult has been depricated and replaced by way of acls , by refering to this link you can start building config on the 5520 ASA platform based on this information.


http://www.cisco.com/en/US/docs/security/asa/asa70/pix_upgrade/upgrade/guide/pixupgrd.html#wp1811886


HTH

Jorge



cairnsm Wed, 11/21/2007 - 11:41
User Badges:

An ASA with 7.0(7) code will accept a copy and paste of 6.x configuration and convert to the 7.x format. Example:


FIXUP:

VBASA(config)# fixup protocol dns maximum-length 512

INFO: converting 'fixup protocol dns maximum-length 512' to MPF commands

VBASA(config)# fixup protocol ftp 21

INFO: converting 'fixup protocol ftp 21' to MPF commands

VBASA(config)# fixup protocol h323 h225 1720

INFO: converting 'fixup protocol h323_h225 1720' to MPF commands


VPN:

VBASA(config)# vpngroup vbvpn address-pool vb-vpn-client-pool

WARNING: the 'vpngroup' command has been deprecated, and will be converted to the corresponding tunnel-group and group-policy syntax

VBASA(config)# vpngroup vbvpn dns-server 4.2.2.2

WARNING: the 'vpngroup' command has been deprecated, and will be converted to the corresponding tunnel-group and group-policy syntax

VBASA(config)# vpngroup vbvpn split-tunnel splittunnel

WARNING: the 'vpngroup' command has been deprecated, and will be converted to the corresponding tunnel-group and group-policy syntax


HTH,

Mark


Actions

This Discussion