?
Solved

Cisco ASA 5510 - migration problems from ASA 8.0.2 --> 8.3.2

Posted on 2010-09-08
6
Medium Priority
?
1,240 Views
Last Modified: 2012-06-21
I am trying to upgrade the ASA.  The newer version of ASA is 8.3.2.

I loaded a 2nd ASA 5510 with the new ASA software and then applied the running config from my production 5510, which is running 8.0.2.

Now I have no NAT Rules...  Is there a way to migrate the existing rules into the newer ASA software?  After this is resolve, I could really use more help getting these firewalls setup...

I can include the configs in private e-mail if necessary...
0
Comment
Question by:Talon0926
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 17

Accepted Solution

by:
Kvistofta earned 1000 total points
ID: 33631301
Read the release notes for 8.3, it says that you should upgrade to 8.2 prior to 8.3. The upgrade-gap between 8.0 and 8.3 is to big for the upgrade-script to handle.

/Kvistofta
0
 

Author Comment

by:Talon0926
ID: 33631435
In going from 8.0.2 to 8.2 - what method of upgrade is most reliable?  Using ASDM or...
0
 
LVL 37

Expert Comment

by:ArneLovius
ID: 33650543
it doesn't matter how you get the file on there, reload the asa at the software level of your production asa, with a copy of your production config on, then reload at the intermediate stage an it will upgrade the config, then reload again at the final one and it will upgrade it again
0
WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

 
LVL 37

Assisted Solution

by:ArneLovius
ArneLovius earned 1000 total points
ID: 33650595
for clarity, you can have multiple ASA images on the ASA at the same time

The ASA will upgrade the automatically when it loads

load all three images, but set it to boot from 8.0.2

copy on your config and reload the ASA, check that the config is still correct

set the ASA to boot from 8.2 and reload it, when it reloads the config will be upgraded to 8.2, check that the config is still correct

set the ASA to boot from 8.3.2 and reload it, when it reloads the config will be upgraded to 8.3.2, check that the config is still correct

your only issue is that to do this with your exact config, you'll have to set-up a "lab" environment as it will have the same network address as your production ASA...

0
 

Author Comment

by:Talon0926
ID: 33668196
I will try the migration path suggested by Arne.  For now I will accept that reply and close the ticket.  I was also recently told by a Cisco engineer that 8.3.2 takes more memory.  So, for now, I will stay at the 8.0.x release...  
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33669295
Yes, the memory requirements are higher, that is another reason for you to read the release notes before upgrading.

/Kvistofta.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question