cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
417
Views
0
Helpful
5
Replies

Pix to asa 5510

mrehman02
Level 1
Level 1

Dears, I am trying to upgrade my pix 515 to ASA 5510 . I have mostly copied the configuration but is stuck on one part where we have  set the IP next hop in the pix. For some reason I cant find the SET IP NEXT HOP command in the asa. What could be the reason? Please advice

1 Accepted Solution

Accepted Solutions

So it seems like you are trying to running PBR (Policy Based Routing). This feature was not available in the ASA code until 9.4:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html

Unfortunately, ASA 5510 is End-of-Life/End-of-Sale and as a result, the latest version that it can run is 9.1. Thus, you should look into replacing that ASA with a next-generation model ASA (X series). This will allow you to run the desired code for PBR and will also give you the option(s) to run some next-generation features (NGIPS, Malware inspection, etc). 

I hope this helps!

Thank you for rating helpful posts!

View solution in original post

5 Replies 5

nspasov
Cisco Employee
Cisco Employee

Hi there, can you post the exact syntax from the PIX?

Thank you for rating helpful posts!

Hi, Please find it below.

route-map NETWORK-1 permit 10
set metric 2
set ip next-hop 10.40.60.5
match ip address 150
route-map NETWORK-1 permit 20
set metric 5
set ip next-hop 10.40.60.8
match ip address 160

So it seems like you are trying to running PBR (Policy Based Routing). This feature was not available in the ASA code until 9.4:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html

Unfortunately, ASA 5510 is End-of-Life/End-of-Sale and as a result, the latest version that it can run is 9.1. Thus, you should look into replacing that ASA with a next-generation model ASA (X series). This will allow you to run the desired code for PBR and will also give you the option(s) to run some next-generation features (NGIPS, Malware inspection, etc). 

I hope this helps!

Thank you for rating helpful posts!

Thank you. That explains!!

No problem. Sorry to bring the bad news :(

Thank you for rating helpful posts!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card