<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration PIX525 7.0(4) to ASA5525-X 8.6.1 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311717#M345697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to Julio's good advice, I would use the opportunity to clean up the access-lists. At 1500 lines there is very likely a fair amount of unused and incorrect entries. Since you were running Pix 525 with 7.0(4) I would guess that those firewalls were not given much "love".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use some tools such as Cisco Security Manager and SolarWinds Firewall Service Manager to import your Pix configuration and analyze access-lists for duplicate, shadowed and unused rules. Both of those products have trial versions that you could use to perform analysis of a single firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 28 Jul 2013 15:06:04 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2013-07-28T15:06:04Z</dc:date>
    <item>
      <title>Migration PIX525 7.0(4) to ASA5525-X 8.6.1</title>
      <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311715#M345694</link>
      <description>&lt;P&gt;Hi ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please your advise and help ...&lt;/P&gt;&lt;P&gt;I have a cluster of PIX525 with 7.0(4), some days ago the Primary PIX failed and it was impossible to startup again.&lt;/P&gt;&lt;P&gt;The failover worked and the PIX Secondary worked ... but this Secondary has a fail and every day at 11:00 AM restart without apparent reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We bought a new ASA clusters,&amp;nbsp; two 5525-X but this new firewalls have 8.6.1 software ...&amp;nbsp; I know the migration between 7.0 and 8.6 its hard, I was trying but the configuration of this firewalls are very complex (at least 1500 lines access-lists).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know about the differences in static, global, nat and access-list but I would like to have any cook book or quick reference manual to do this migration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any tool or suggestion to make this migration ?&lt;/P&gt;&lt;P&gt;I'll appreciate any help to do this ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311715#M345694</guid>
      <dc:creator>guigonza</dc:creator>
      <dc:date>2019-03-12T02:18:00Z</dc:date>
    </item>
    <item>
      <title>Migration PIX525 7.0(4) to ASA5525-X 8.6.1</title>
      <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311716#M345696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you have a lot of work to do &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-12690"&gt;https://supportforums.cisco.com/docs/DOC-12690&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation would be get familiar with the new configuration and then start working on it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Jul 2013 06:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311716#M345696</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-28T06:44:56Z</dc:date>
    </item>
    <item>
      <title>Migration PIX525 7.0(4) to ASA5525-X 8.6.1</title>
      <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311717#M345697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to Julio's good advice, I would use the opportunity to clean up the access-lists. At 1500 lines there is very likely a fair amount of unused and incorrect entries. Since you were running Pix 525 with 7.0(4) I would guess that those firewalls were not given much "love".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use some tools such as Cisco Security Manager and SolarWinds Firewall Service Manager to import your Pix configuration and analyze access-lists for duplicate, shadowed and unused rules. Both of those products have trial versions that you could use to perform analysis of a single firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Jul 2013 15:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311717#M345697</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-07-28T15:06:04Z</dc:date>
    </item>
    <item>
      <title>Migration PIX525 7.0(4) to ASA5525-X 8.6.1</title>
      <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311718#M345698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Julio ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had checked the information in the links you sent.&lt;/P&gt;&lt;P&gt;I'll do the analysis for migration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guillo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Jul 2013 18:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311718#M345698</guid>
      <dc:creator>guigonza</dc:creator>
      <dc:date>2013-07-28T18:33:50Z</dc:date>
    </item>
    <item>
      <title>Migration PIX525 7.0(4) to ASA5525-X 8.6.1</title>
      <link>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311719#M345700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marvin ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good idea about Cisco Security Manager for analyze the configuration,&amp;nbsp; I know this is a horrible configuration and it's no easy to clean it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guillo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Jul 2013 18:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-pix525-7-0-4-to-asa5525-x-8-6-1/m-p/2311719#M345700</guid>
      <dc:creator>guigonza</dc:creator>
      <dc:date>2013-07-28T18:35:29Z</dc:date>
    </item>
  </channel>
</rss>

