Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Context Migration from FWSM to ASA

Hi there ,

     What would be best way to migrate a Context from FWSM to ASA (non SM)  with minimal down time & effort .

I am thinking of these steps :

1) Preconfigure  the new ASA with the same IP-Address as FWSM for the interfaces (keep the ASA subinterfaces in shut state ) , configure Access rules .

     ( Want to retain same ip for the interfaces , since there are many hosts behind the FWSM with this gateway IP configured )

2) Shut the context specific interfaces on FWSM & bring up the Context specific interfaces on the ASA.

   ( Also a query - If I introduce ASA into the Network with the same IP as of FWSM , though the interfaces would be in shut state , should i expect any IP Conflicts )

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Silver

Context Migration from FWSM to ASA

I'd suggest opening a TAC case for assistance. Let us know what you find out.

6 REPLIES
Hall of Fame Super Silver

Context Migration from FWSM to ASA

That sounds like a good plan.

You should not see any IP conflicts as long as both the FWSM context interfaces and corresponding ASA subinterfaces are not up simultaneously.

You may need to flush arp caches on the hosts since I do not believe the ASA will send a gratuitous ARP announcing it owns the interface addresses once they are brought out of shutdown.

New Member

Context Migration from FWSM to ASA

ok , gratuitous ARP behavior post migration could cause issues then , as we have around 300 - 400 virtual servers behind this ASA context , so flushing ARP on all these boxes may not be possible ; do we have any other recommendations , as our ASA5585X will be running on 9.0.1 code.

Thanks

Super Bronze

Context Migration from FWSM to ASA

Hi,

Well you probably have the option to configure the old FWSMs interface MAC address to the ASAs corresponding interface manually, this way there will be no change in the ARP from the perspective of the server/host.

I guess depending on if you have a single firewall or failover firewall the command is a bit different as you define either 1 or 2 MAC addresses.

I think this was the command to modify the MAC address

http://www.cisco.com/en/US/docs/security/asa/command-reference/m1.html#wp2111205

- Jouni

New Member

Context Migration from FWSM to ASA

Thanks Jouni,  however we are planning to migrate some 20 contexts with 6 - 8 subinterfaces in each of them ; is their any other way to tweak this gratuitous ARP problem , without having to flush the ARP cache on hosts or replicating mac address from FWSM to ASA.

Hall of Fame Super Silver

Context Migration from FWSM to ASA

I'd suggest opening a TAC case for assistance. Let us know what you find out.

New Member

Context Migration from FWSM to ASA

ok thanks

414
Views
0
Helpful
6
Replies