<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5510 code version upgrade in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147544#M357133</link>
    <description>&lt;P&gt;I am looking to upgrade a 5510 that is currently on code version 8.0(4) to code version 9.1. I know I will have to upgrade to 1gb ram, but can i just upgrade straight to version 9.1 or do I need to follow an upgrade path? This is a standalone device so I am planning on downtime. Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:56:04 GMT</pubDate>
    <dc:creator>Benjamin Saito</dc:creator>
    <dc:date>2019-03-12T00:56:04Z</dc:date>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147544#M357133</link>
      <description>&lt;P&gt;I am looking to upgrade a 5510 that is currently on code version 8.0(4) to code version 9.1. I know I will have to upgrade to 1gb ram, but can i just upgrade straight to version 9.1 or do I need to follow an upgrade path? This is a standalone device so I am planning on downtime. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147544#M357133</guid>
      <dc:creator>Benjamin Saito</dc:creator>
      <dc:date>2019-03-12T00:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: 5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147545#M357134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally it would be adviced to reboot the device to the next new software compared to the current one so that the configuration converts correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;8.0 -&amp;gt; 8.2 -&amp;gt; 8.3 -&amp;gt; 8.4 -&amp;gt; 9.0 -&amp;gt; 9.1 (If I dont remember wrong)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the 8.1 software was used only for certain ASA model or I just have never run into it. Think the model was ASA5580&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant really say for certain what happens if you make the jump directly from 8.0 to 9.1. The most critical point of configuration conversion to newer format is between 8.2 and 8.3 as that was when the NAT configuration and ACL configuration formats were changed drasticly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be good to get used to the new NAT format before rebooting to the new software with automatically converted configurations. Some of the generated configuration might be useless or not work right at all. Also when you know how to configure them yourself, you can make them ALOT simpler.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally rewrite the whole configuration for older software myself and then just apply the configurations to a updated device or a totally fresh new ASA to make the configuration as simple as possible. So in that case it doesnt really matter how big the software jump is. In your case I would suggest taking backups of the configurations and doing the upgrade in steps if you are not at all familiar with the new NAT format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 20:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147545#M357134</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-04T20:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: 5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147546#M357135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can safely upgrade from 8.0 to 9.1.&amp;nbsp; The configuration changes introduced in 8.3 regarding NAT will be converted when you upgrade to 9.1.&amp;nbsp;&amp;nbsp; As always, make sure you save the configuration on the 8.0 code. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct that the 8.1 code was only for a specific model of ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 21:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147546#M357135</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2013-02-04T21:27:52Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147547#M357136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you to both of you for your answers. I was able to upgrade straight from 8.0.4 to 9.1. I have a few questions though about the asa code version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. access-list outside_access_in_1 extended permit ip object-group ADMIN_NETWORKS any4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why did the destination get changed from "any" to "any4"? It did this for all rules that had "any", i guess is this related to ipv4? Becasue Any6 is an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. &lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was thrown in the running config, what is it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. What version of java is required for asdm version 711? I have java 6 update 7 on my computer because it's the only version that works with pix's and older asdm versions, but i can't open the asdm using the Java web start application, I can only access it as a local application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 19:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147547#M357136</guid>
      <dc:creator>Benjamin Saito</dc:creator>
      <dc:date>2013-02-05T19:54:16Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147548#M357137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the "any" keyword (9.0(x) Release Notes)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"any" now means both ipv4 and ipv6. "any4" for only ipv4 and "any6" for ipv6 only&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt; Any Keyword &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp582904"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Now that ACLs support both IPv4 and IPv6, the &lt;STRONG&gt;any&lt;/STRONG&gt; keyword now represents "all IPv4 and IPv6 traffic." Any existing ACLs that use the &lt;STRONG&gt;any&lt;/STRONG&gt; keyword will be changed to use the &lt;STRONG&gt;any4&lt;/STRONG&gt; keyword, which denotes "all IPv4 traffic." &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp583140"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; In addition, a separate keyword was introduced to designate "all IPv6 traffic": &lt;STRONG&gt;any6&lt;/STRONG&gt;. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found at (Along with other information):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa90/release/notes/asarn90.html#wp582903"&gt;http://www.cisco.com/en/US/docs/security/asa/asa90/release/notes/asarn90.html#wp582903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the Xlate settings (9.0(x) Release Notes)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Used to keep the original old software behaviour identical even when doing a software jump from old to new&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Per-session&amp;nbsp; PAT disabled when upgrading— Starting in Version 9.0, by default, all&amp;nbsp; TCP PAT traffic and all UDP DNS traffic use per-session PAT (see the &lt;STRONG&gt;xlate per-session &lt;/STRONG&gt;command&amp;nbsp; in the command reference). If you upgrade to Version 9.0 from an&amp;nbsp; earlier release, to maintain the existing functionality of multi-session&amp;nbsp; PAT, the per-session PAT feature is disabled during configuration&amp;nbsp; migration. The ASA adds the following deny rules: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp636526"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny tcp any4 any4
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636527"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny tcp any4 any6 
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636528"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny tcp any6 any4 
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636529"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny tcp any6 any6 
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636530"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny udp any4 any4 eq domain
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636531"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny udp any4 any6 eq domain
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636532"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny udp any6 any4 eq domain
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636468"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;xlate per-session deny udp any6 any6 eq domain
&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636539"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt; &lt;/DIV&gt;
&lt;P&gt; &lt;A name="wp636428"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt; To enable per-session PAT after you upgrade, enter: &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt; &lt;A name="wp636292"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;PRE&gt;&lt;STRONG&gt;clear configure xlate
&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found at:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa90/release/notes/asarn90.html#wp593140"&gt;http://www.cisco.com/en/US/docs/security/asa/asa90/release/notes/asarn90.html#wp593140&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 20:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147548#M357137</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-05T20:13:17Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147549#M357138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response again Jouni, that was very helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 20:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147549#M357138</guid>
      <dc:creator>Benjamin Saito</dc:creator>
      <dc:date>2013-02-05T20:26:43Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147550#M357139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am still unable to access the asdm using the java web start application. I try to but a window pops up saying unable to launch application. I have to click on "install asdm launcher" in order to get it to run. I was able to just click on "run asdm" and it worked in earlier versions. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 21:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147550#M357139</guid>
      <dc:creator>Benjamin Saito</dc:creator>
      <dc:date>2013-02-05T21:45:20Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147551#M357140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally use the software installed from the ASA on my computer. I dont launch it through the web browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I havent really had the need to troubleshoot this much. I can only remember one occasion where a new Java update broke the ASDM. I personally dont use much ASDM also so even less likely that I run into these problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres some information of my setup and versions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Java&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/9/8/127895-Java1.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/9/8/127896-Java2.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My ASA5505&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.1(1)&lt;/P&gt;&lt;P&gt;Device Manager Version 7.1(1)52&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And everything works fine. ASDM shows the following when it has launched through the browser&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/9/8/127897-ASDM1.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 22:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147551#M357140</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-05T22:15:06Z</dc:date>
    </item>
    <item>
      <title>5510 code version upgrade</title>
      <link>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147552#M357141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni, it must be the version of java I am running on this computer. I confirmed from a different computer with an updated version of Java that I was able to access the asdm normally. Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 22:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5510-code-version-upgrade/m-p/2147552#M357141</guid>
      <dc:creator>Benjamin Saito</dc:creator>
      <dc:date>2013-02-05T22:26:35Z</dc:date>
    </item>
  </channel>
</rss>

