Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1017
  • Last Modified:

Upgrading Flash in Cisco ASA Firewall

I have a 5510 ASA Firewall that I'm upgrading the flash on.  I've read that I need to basically copy the files off the existing flash onto the new flash.  I don't have a reader that I can use to connect to the new flash.  Here are my questions:

1.  I copied the IOS and ASDM images off the exising flash via tftp.  There are a couple other files that I can't copy due to permissions.  Those are the log, crypto_archive and coredump files.  Do I need those at all?

2.  I've read that I need a hidden file that has the activation key, or else I can just re-enter it?  Which file is this and can I copy it with tftp?

3.  I don't have a flash card reader.  Can I put the new flash in a spare ASA that I have and save the files onto it?  Would I then need to delete from it the file that has the activation key?
0
jpletcher1
Asked:
jpletcher1
  • 4
  • 3
2 Solutions
 
Pete LongConsultantCommented:
Ive only attempted this once and failed :(
If its a non Cisco Flash read this http://cisconews.co.uk/2007/12/27/asa-5505-flash-memory-hack/


0
 
Pete LongConsultantCommented:
>>I don't have a flash card reader

in this day and age you can pick one up on ebay for buttons !
0
 
jpletcher1Author Commented:
This was the article that I was going off so far, but the part below I'm not sure how to do.  It is genuine Cisco flash.

Note: If you do not have a compact flash card reader you can still perform the upgrade. You will need to write down the activation key of your ASA (show ver displays this). You will then need to use a TFTP server to transfer the ASA image and other files!

0
Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
jpletcher1Author Commented:
I put the flash into one of my spare asas and I was able to go in rommon mode and tftp files to the flash.  I called Cisco support and I have to note the existing activation key and manually put that in after I install the flash and boot up the asa.  I'll post back with my results once I have a chance to change it out now.
0
 
jpletcher1Author Commented:
The method below worked for me.  There was a big problem though with the existing config not being saved in NVRAM.  It was saved on the flash so that was lost and I had to save it back up.  The cisco tech said that sometimes that happens and the config doesn't get saved to the right area.  Weird, but that's what he said.  I was later able to get a flash card reader and I could see the config was saved in a hidden folder called private.  This foldler also had the key code which I manually input, but had I copied it over it would have gone more seamless.  

"I put the flash into one of my spare asas and I was able to go in rommon mode and tftp files to the flash.  I called Cisco support and I have to note the existing activation key and manually put that in after I install the flash and boot up the asa.  I'll post back with my results once I have a chance to change it out now."
0
 
Pete LongConsultantCommented:
jpletcher1 great news! keep me posted. If you have five minutes spare, jot down the steps you have taken and post them here, if info on this subject is so thin on the ground, lets see it we can get the steps posted here - nice work!

Pete
0
 
jpletcher1Author Commented:
The solution I went with worked for me.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now