Solved

Upgrading Flash in Cisco ASA Firewall

Posted on 2011-02-21
7
1,001 Views
Last Modified: 2012-05-11
I have a 5510 ASA Firewall that I'm upgrading the flash on.  I've read that I need to basically copy the files off the existing flash onto the new flash.  I don't have a reader that I can use to connect to the new flash.  Here are my questions:

1.  I copied the IOS and ASDM images off the exising flash via tftp.  There are a couple other files that I can't copy due to permissions.  Those are the log, crypto_archive and coredump files.  Do I need those at all?

2.  I've read that I need a hidden file that has the activation key, or else I can just re-enter it?  Which file is this and can I copy it with tftp?

3.  I don't have a flash card reader.  Can I put the new flash in a spare ASA that I have and save the files onto it?  Would I then need to delete from it the file that has the activation key?
0
Comment
Question by:jpletcher1
  • 4
  • 3
7 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 34944177
Ive only attempted this once and failed :(
If its a non Cisco Flash read this http://cisconews.co.uk/2007/12/27/asa-5505-flash-memory-hack/


0
 
LVL 57

Expert Comment

by:Pete Long
ID: 34944190
>>I don't have a flash card reader

in this day and age you can pick one up on ebay for buttons !
0
 

Author Comment

by:jpletcher1
ID: 34944193
This was the article that I was going off so far, but the part below I'm not sure how to do.  It is genuine Cisco flash.

Note: If you do not have a compact flash card reader you can still perform the upgrade. You will need to write down the activation key of your ASA (show ver displays this). You will then need to use a TFTP server to transfer the ASA image and other files!

0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 

Assisted Solution

by:jpletcher1
jpletcher1 earned 0 total points
ID: 34946637
I put the flash into one of my spare asas and I was able to go in rommon mode and tftp files to the flash.  I called Cisco support and I have to note the existing activation key and manually put that in after I install the flash and boot up the asa.  I'll post back with my results once I have a chance to change it out now.
0
 

Accepted Solution

by:
jpletcher1 earned 0 total points
ID: 35039937
The method below worked for me.  There was a big problem though with the existing config not being saved in NVRAM.  It was saved on the flash so that was lost and I had to save it back up.  The cisco tech said that sometimes that happens and the config doesn't get saved to the right area.  Weird, but that's what he said.  I was later able to get a flash card reader and I could see the config was saved in a hidden folder called private.  This foldler also had the key code which I manually input, but had I copied it over it would have gone more seamless.  

"I put the flash into one of my spare asas and I was able to go in rommon mode and tftp files to the flash.  I called Cisco support and I have to note the existing activation key and manually put that in after I install the flash and boot up the asa.  I'll post back with my results once I have a chance to change it out now."
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 35042214
jpletcher1 great news! keep me posted. If you have five minutes spare, jot down the steps you have taken and post them here, if info on this subject is so thin on the ground, lets see it we can get the steps posted here - nice work!

Pete
0
 

Author Closing Comment

by:jpletcher1
ID: 35081112
The solution I went with worked for me.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now