We're considering replacing a pair of PIX 525s and a pair of VPN 3005s with a single pair of ASA 5520s. I'm looking at the configuration changes that will be needed. The PIX side seems pretty easy... I've run the PIX-to-ASA conversion utility on the config, and it looks like only a few changes are needed. Is there any kind of utility or process like that on the VPN side? I didn't set the VPN 3005s up originally, and it will be a bit of work to set the vpn stuff on the ASA and make sure all features are copied over.
You will have to build what is in vpn3k onto the ASA manually, but you should be able to run both the VPN3k and ASA in parallel and gradually migrate any l2l ipsec tunnels, ra tunnels onto the new ASAs.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...