?
Solved

Cisco ASA 5510 Pair Upgrade 8.21->8.47->9.14 Proxy Phones and VPN Tunnels

Posted on 2014-08-14
5
Medium Priority
?
642 Views
Last Modified: 2014-08-20
I am planning to upgrade my 5510 ASA pair as described  in the subject.  I am hoping to use the procedure at this petenetlive URL..

http://www.petenetlive.com/KB/Article/0000733.htm

A few concerns.  

Will upgrading from 8.21 to 8.47 and then 8.47 to 9.14 be a good sequence?

Is there any risk to the functionality of my CIsco Proxy phones?  I have about 20 deployed around the country and I am concerned that the upgrade could leave some sales reps without phone service if there's an incompatibility.  Any issues to consider there??

Is there any risk to a VPN tunnel to another ASA 5510 pair which is still using 8.21?  That would likewise be very bad
if after the upgrade I could no longer get to the remote site.  Anything need to be reconfigured on either side after the upgrades?
0
Comment
Question by:amigan_99
  • 2
  • 2
5 Comments
 
LVL 3

Expert Comment

by:Soufiane Adil, Ph.D
ID: 40262140
Why you wanna upgrade ?
0
 
LVL 1

Author Comment

by:amigan_99
ID: 40262353
The primary issue is that I need to apply an upgrade license to accommodate more proxy phones.  I'm at 20 or 24.  I purchased the upgrade I think to 48 phones.  But when I got it I realized it was only associated with the primary member of the pair.  I was told that if I upgraded to 8.4 or beyond that the proxy phone license then works for both primary and the secondary unit.   If I apply the upgrade license to the primary and at some point it went out - then some of my remote users would be unhappy.  But if you see a flaw in my logic I'm all ears.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 40262496
>>Will upgrading from 8.21 to 8.47 and then 8.47 to 9.14 be a good sequence?

Yes in fact Im doing the exact same thing on Saturday! :)

>>Is there any risk to a VPN tunneil to another ASA 5510 pair which is still using 8.21

Not that I have seen- you are into introducing an IKEv2 capable firewall at one end, but both are still running IKEv1 :)

As for the phones I cant comment :( But as usual back up everything first, have copies of all the OS bin files and ASDM bin files. Before attempting an upgrade.

And thanks for the site plug!

Pete
0
 
LVL 1

Author Closing Comment

by:amigan_99
ID: 40271484
Thanks Pete!  I'm getting close on my change doc.  I'm still worried about the proxy phone operation.  That will cause a major ruckus if that stops working.  What I think I'll do is..

>Reboot the failover after upgrade.

5510-1 (config)# failover reload-standby

..And then I will test all of the functionality including the proxy phone operation.  If all is good then I reload and activate the primary.  
If anything's amiss then I can simply take the secondary ASA offline, verify that the bootvar on primary remains as the original and activate it at pre-upgrade level.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 40271845
Sounds like a plan :)

ThanQ
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Considering cloud tradeoffs and determining the right mix for your organization.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month15 days, 12 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question