cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
515
Views
0
Helpful
5
Replies

ASA 8.2 > 8.4 > 9.1 possible with no downtime as we run active/standby?

Andy White
Level 3
Level 3

Hello,

We have 2 x ASA 5520s (with 2GB mem) in active/standby mode, they also include the IPS modules.

The current firmware is 8.2 and I was wondering if it is possible to upgrade these firewalls with no downtimes?  In the past I have upgraded the standby ASA, rebooted it and then made it the active ASA then upgraded the new standby ASA.

I have have quite a lot of NAT Exempts (No-NATs?) and a few static NATs, how did you approach this during your upgrades?

I guess I can roll back as the 8.2 firmware will still be on the flash and I will have the config?

Thanks

5 Replies 5

jumora
Level 7
Level 7

Yeah it's supported:

Release Notes for the Cisco ASA Series, 9.1(x)

http://www.cisco.com/en/US/docs/security/asa/asa91/release/notes/asarn91.html#wp732442

This document has the information that you need; it talks about the requirements and zero downtime procedure.

But you need to take a lot of considerations that you can reference in the document:

https://supportforums.cisco.com/docs/DOC-12690

If you don't mind me asking why are you upgrading?

Because of a fix or feature?

Value our effort and rate the assistance!

Thanks.

I will have Cisco TAC on he phone to help and Webex, but we want to use te clientless VPN and use ACLs with FQDNS too for some hosted clusters we have.

Please rate the assistance.

Value our effort and rate the assistance!

Please rate the assistance.

Value our effort and rate the assistance!

Please rate the assistance.

Value our effort and rate the assistance!
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: