Replacing the existing ISA with ASA

Unanswered Question
Sep 1st, 2010

There is existing IPSEC VPN between two ISA servers, and now i want to replace the headend  ISA with ASA with all the existing rules applied on it. Can you please advice me on anything that will help me on doing this? if there is additional thing to be done on the ASA  please let me know?

Thank You in advance

Mulu

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
lawchung Wed, 09/01/2010 - 10:58

There is no easy way of doing this. You will have to configure the VPN on the ASA per the following document and using the same parameters on the ISA to match the other end. Put the ASA into production during a maintenance window and troubleshoot any issues with the connection.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008045a2d2.shtml

Hope this helps.

mulugojjam abebe Thu, 09/02/2010 - 04:42

Thank you for your help and the document is very helpful. I know IPSEC is an open standard, but i want to be sure if there is something specific or

additional configuration apart from the normal on the ASA to communicate with the ISA server since  its another vendor product.

Thank You

Mulu

lawchung Thu, 09/02/2010 - 09:50

Hi Mulu,

No additional configuration is needed apart from the normal IPSec configuration.

Actions

This Discussion