Solved

loading cisco ASA config into new ASA

Posted on 2014-01-27
8
656 Views
Last Modified: 2014-01-28
I just had an ASA fail on me and now I need to load the old ASA config into the new ASA. I need to setup SSH. I also have IPsec VPN tunnels setup as wel. I know some of the basic SSH commands but I also remember that when it was setup, I needed to setup something using a crypto command or RSA? Can someone let me know how to setup SSH on the ASA from scratch? Also, do I have to setup the rsa/crypto for my IPsec tunnel as well?

Thanks,

Justin
0
Comment
Question by:JustinGSEIWI
  • 4
  • 4
8 Comments
 
LVL 19

Expert Comment

by:Patricksr1972
ID: 39812902
Hi Justin,

Cant you boot up using the serial cable and software like putty?
From there you can restore your config.
0
 

Author Comment

by:JustinGSEIWI
ID: 39812907
I am off site and have a vendor working on this. I am asking this just for my reference. When you load the config, the passwords are not in it so we will need to add the passwords again right? I figured we would also have to redo the cyrpto part of SSH. Is that not true? If that is the case, then it should just work once we enter the new password for SSH.
0
 
LVL 19

Expert Comment

by:Patricksr1972
ID: 39812961
Hi

Passwords are encrypted in your config file so if you restore a working config you have cloned your previous ASA.
0
 

Author Comment

by:JustinGSEIWI
ID: 39813034
I have the config in a text file and the password shows as *. Are they encrypted somewhere else? I think we need to set up the passwords for the ipsec connections again. I am wondering if I also need to setup the RSA/crypto as well?
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 19

Expert Comment

by:Patricksr1972
ID: 39813082
The login password is used for Telnet and SSH connections.

Little quote from Cisco

The password is saved in the configuration in encrypted form, so you cannot view the original password after you enter it. Use the no password command to restore the password to the default setting.
0
 

Author Comment

by:JustinGSEIWI
ID: 39813161
I tried entering the following syntax into my ASA to establish the ipsec vpn tunnel between two ASA's.

crypto map vpnmap 20 match address vpn2RI
crypto map vpnmap 20 set peer 242.119.136.92
crypto map vpnmap 20 set transform-set STRONG
crypto map vpnmap 20 set security-association lifetime seconds 28800
crypto map vpnmap 20 set security-association lifetime kilobytes 4608000


tunnel-group 192.119.236.10 type ipsec-l2l
tunnel-group 192.119.236.10 ipsec-attributes
pre-shared-key password

When I did that, I got this error.

ERROR: transform set with tag "STRONG" does not exist.


What does that mean? I am unable to establish the VPN tunnel.
0
 
LVL 19

Accepted Solution

by:
Patricksr1972 earned 500 total points
ID: 39813212
Have a look into the ASA site to site step by step from Cisco Here
0
 

Author Comment

by:JustinGSEIWI
ID: 39813395
I took down my config.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now