Pix Firewall 6.x to 7.x configuration change

We just purchased a Cisco 5510 ASA running v. 7.x to replace an old Cisco PIX 520 we've had set up for ages.  ALthough I know the 6.x syntax it turns out that it is very different from the 7.x syntax.

Access-List commands work fine  but not my static commands, route commands, how do I name an interface  (i.e. inside / outside)  and forget about my VPN configuration.  ERROR / ERROR / ERROR  Here are some examples of what I have that I can't seem to get to work.  IP's are all changed to protect the innocent:

route outside 0.0.0.0 0.0.0.0 68.11.67.188 1

http 192.168.1.0 255.255.255.0 inside

static (inside,outside) tcp 68.11.67.175 smtp 192.168.1.175 smtp netmask 255.255.255.255 0 0
static (inside,outside) tcp  68.11.67.176 3389 192.168.13.176 3389 netmask 255.255.255.255 0 0

I'm getting errors specifically with anything that uses inside and outside in the config   like
p1fw01(config)# telnet 192.168.13.0 255.255.255.0 inside
                                                  ^
ERROR: % Invalid input detected at '^' marker.



LVL 2
fredimacAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

lrmooreCommented:
Cisco actually has a conversion tool to help
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808554ed.shtml

Otherwise, upgrade the pix to 7.0 and the upgrade process will automagically convert the config, then you can copy/paste into the ASA
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
yashinchaladCommented:
please execute "sh nameif" and kindly verify that interface has the name as "inside". otherwise we dont see any issue with commands
it works well and syntax is correct.
please let me know, thanks!
0
fredimacAuthor Commented:
Unfortunately the 520 won't support 7.x or I would just  update that one and copy the config over to the ASA - Unless I'm totally mistaken.
0
lrmooreCommented:
The 520 might if you have enough DRAM and flash. Can you post "show ver" from the 520?
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.