Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Moving Cisco ASA t new lcoation, new external IP's

Posted on 2010-09-03
4
Medium Priority
?
388 Views
Last Modified: 2012-05-10
We are moving a Cisco 5510 from one location to another and the internet provider is changing.  Nothing with the internal network is changing.  I'm trying to determine my easiest path in completing this.  I have a spare test 5510 that I can bring in.  Is the best way just to start with a fresh config the test asa, get it the way I need it then copy that to the asa once it is moved or should I try editing the current config once its been moved?

It has 2 DMZ's setup and about 12 external firewall rules.
0
Comment
Question by:dmwynne
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 4

Expert Comment

by:keith_opswat
ID: 33600194
If nothing on your internal network is changing just remove the old IP address from the outside interface and add a new one. Also, change any static routes you had pointing to the old ISP's gateway and that should be it.

Why go through the hassle of re-configuring everything and possibly making an error on it when you know it works and only one small area is going to change. I just recently changed ISP's and did exactly what I said above. Changed IP address on one I/F and edited the static routes. It came up flawlessly.
0
 
LVL 14

Author Comment

by:dmwynne
ID: 33600236
Yup you are right the only thing that concerns me is we have several external facing boxes with firewall rules and access lists.  Do you see any issue there?
0
 
LVL 4

Accepted Solution

by:
keith_opswat earned 2000 total points
ID: 33600293
Most firewall rules are generic... If any of the rules are dealing specifically with an IP address or subnet of your old IP's then change those rules.

Most of the rules are just going to say if you have traffic coming from this range or from anywhere with this port... allow to a certain location or deny.

So like I said the only thing that will cause you any issues with your move is any rules, IP address, static routes, or default gateways set need ot be reconfigured to point to their new counterpart. If that's all done then you should have a seamless transition.

Good luck!!
0
 
LVL 14

Author Closing Comment

by:dmwynne
ID: 33600977
Thanks
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question