cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1421
Views
0
Helpful
21
Replies

Cisco PIX 515 E to ASA upgrade?

m-abooali
Level 4
Level 4

Hi, I need to upgrade/ replace a Cisco 515 E firewall with a Cisco ASA. Not sure what model yet! The pix has about 80 lines of ACLs and I side and outside interfaces with No VPNs.. I was wondering of those lines of ACLs can be transferred over to ASA as is or there are things I need to watch for ?

No VPN

Only inside and outside interfaces

80 lines of ACLs

Please advise.

Regards,

Masood

Sent from Cisco Technical Support iPhone App

21 Replies 21

Hi Varun,

I have more information now.

here is what the ASa is:

The IOS on the ASA was updatewd by the client to Version 843 and ASDM to version 647

both ASA have active/Avtive Failover Licenses

I assume with ASA now version 843, I need o tewaks teh PIX configs a little like listed in Cisco documnetation with that line that says: jobect..

Thanks,

masood

Hello,

My recomendation is the same that Varun suggested before,

1- Downgrade the ASA version to 8.2

2- Migrate to Pix 8.0(4) to ASA 8.2

3-Upgrade the ASA form 8.2 to 8.4

With this all the major changes from 8.2 to 8.4 will be done automatically by the ASA.

If any help is need it in the process just let us know, we will be more than glad to help.

Regards,

Do rate all the helfpul posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Hi Julio,

this install is approaching as it was put on hold for some times but active now.

I see you mentioned:

My recomendation is the same that Varun suggested before,

1- Downgrade the ASA version to 8.2

2- Migrate to Pix 8.0(4) to ASA 8.2

3-Upgrade the ASA form 8.2 to 8.4

With this all the major changes from 8.2 to 8.4 will be done automatically by the ASA.

Now, I was wondering if I need to make any changes to the pIXs i.e. downgrade or upgrade the pIXs that has the cofiguration or just downgrade the ASAs to 8.2, transfer configs from PIX over to ASA 8.2 and then up[grade ASA to 8.4?

Also, I had done Active/standby failover configuration in the past using the command line (private IPs using gigi interfaces in teh ASAs - i.e. no siwtch in between) but I cannot find the conmfogs I created a few years ago and i wa swondering if you guys do have a working Active/Standby configuration? I remember that I dcouldn;'t get to work using ASDM (the GUI) and had to do that using command line.

Please advise,

Regards,

Masood

Do rate all the helfpul posts

Thanks Julio,

the client had upgraded the ASA to 834 and now I need to make sure that I can downgrad to 8.2 before I start my work.

question: how can I downgrade to 8.2? ----> just reset to Factory Default?

I will see what cleint says to that but I don't think they protest!?

Thanks so much for your advise.

Regards,

Masood

Hello,

If you have no configuration yet on the ASA, just donwload from CISCO.com the ASA8.2 image and then upload it to the ASA using a TFTP server or ASDM.

Then change the boot system process with the

boot system flash:asa8.2.bin

Save the configuration

wr

and finally reload the ASA.

Regards,

Please rate all the post that helps

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks much. This will certainly help and I need to get the image downloaded and perform a down grade before going any further.

Regards,

Masood

Sent from Cisco Technical Support iPhone App

Hello Masood,

Sure, it is my pleasure to help!!

If there is something else I can do for you just let me know.I will be more than glad to help.

Have a good one!!!

Do Rate all the helpful posts

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card