Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Changing public IP

After many years with the same ISP, we are switching. We will not be able to use the same public IP address. For those of you who have had to completely review your firewall rules, is there any easy way or documentation on doing this?

5 REPLIES

Re: Changing public IP

My friend I ran into the exact same scenario, there is no other way other than conduct a thorough fw configuration isnpection, however, since you are chanching ISP which is mosutly your public IP block, glocal NAT, static NATs new defualt routes etc.. you can do the complete migration from PDM/ASDM, when chnaging these PDM automcatically updates rules, but good to have a backout plan or script for CLI as other resource of changing configuration . If you have any particular question Im sure someone will provide some hints.

Rgds

Jorge

Community Member

Re: Changing public IP

The way we designed it, we have one vlan that faces the internet. We also have redundant ISPs as one of the requirements. For us that is not a huge load to migrate between ISPs.

Satya

Community Member

Re: Changing public IP

Thanks Jorge & Satya. I was afraid it was going to be pretty much of a manual process. Luckily, we are a small org with less than 10 VPN's so, hopefully, downtime will be minimal.

Re: Changing public IP

Hi,

If possible, you could make it easier by getting a new box, configure for the new isp and then cutover with minimal downtime. I always find these exercises a good time to upgrade hardware as well.

Thanks

John

Community Member

Re: Changing public IP

:) Thanks, John, that would be great but the $ just aren't there. We're able to do the switch because it's basically just paying a different vendor. I'd love to swap out the 515E's but I guess that'll have to wait.

124
Views
0
Helpful
5
Replies
CreatePlease to create content