<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Migration Problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-migration-problems/m-p/1907192#M458428</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to migrate a configuration of an ASA 5520(Version: ASA 8.0(5)) to an ASA 5585 (Version: 8.4(2)). I keep getting some errors which are included below. I've been struggling with these for some copule of weeks and read the documentation on cisco.com (&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html&lt;/A&gt;&lt;SPAN&gt;) and also some pages on this forum. Some lines are written in bold of which I wasn't able to find any information about. Any help is appreciated. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INFO: MIGRATION - Saving the startup errors to file 'flash:upgrade_startup_errors_201203062349.log'&lt;/P&gt;&lt;P&gt;Reading from flash...&lt;/P&gt;&lt;P&gt;!!!!!!!!!!!!!!!!!!!WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: Failed to create acl element to track during migration&lt;/P&gt;&lt;P&gt;*** Output from config line 1291, "access-group outside_acc..."&lt;/P&gt;&lt;P&gt;WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;*** Output from config line 1292, "access-group inside_acce..."&lt;/P&gt;&lt;P&gt;WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;*** Output from config line 1293, "access-group DMZ_access_..."&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: During migration of access-list &amp;lt;XXXXXXX&amp;gt; expanded&lt;/P&gt;&lt;P&gt;this object-group ACE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit object-group DM_INLINE_SERVICE_5 XXX 255.255.255.0 DMZnet 255.255.255.0 &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: Failed to create acl element to track during migration&lt;/P&gt;&lt;P&gt;*** Output from config line 1298, "access-group XXXXX..."&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 6&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 7&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 9&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 11&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;*** Output from config line 1797, "service-policy global-po..."&lt;/P&gt;&lt;P&gt;NAT migration logs:&lt;/P&gt;&lt;P&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'dmz' and was not migrated.&lt;/P&gt;&lt;P&gt;nat (inside) 1 access-list inside_nat_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WARNING: The following identity NAT was not migrated. If required, an appropriate bypass NAT rule needs to be added.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (outside) 10 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 logserver 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WARNING: The following identity NAT was not migrated. If required, an appropriate bypass NAT rule needs to be added.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 logserver 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'dmz' and was not migrated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 1 icnetwork 255.255.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'TAV' and was not migrated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz) 1 access-list dmz_nat_outbound&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INFO: NAT migration completed.&lt;/P&gt;&lt;P&gt;ERROR: an object-group with the same name (egitim) exist. &lt;/P&gt;&lt;P&gt;WARNING: Failed to create an object for name 'egitim' in the following ACL:&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 9.1.1.90 object-group egitim any &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:39:02 GMT</pubDate>
    <dc:creator>hellishglare</dc:creator>
    <dc:date>2019-03-11T22:39:02Z</dc:date>
    <item>
      <title>ASA Migration Problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-migration-problems/m-p/1907192#M458428</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to migrate a configuration of an ASA 5520(Version: ASA 8.0(5)) to an ASA 5585 (Version: 8.4(2)). I keep getting some errors which are included below. I've been struggling with these for some copule of weeks and read the documentation on cisco.com (&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html&lt;/A&gt;&lt;SPAN&gt;) and also some pages on this forum. Some lines are written in bold of which I wasn't able to find any information about. Any help is appreciated. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INFO: MIGRATION - Saving the startup errors to file 'flash:upgrade_startup_errors_201203062349.log'&lt;/P&gt;&lt;P&gt;Reading from flash...&lt;/P&gt;&lt;P&gt;!!!!!!!!!!!!!!!!!!!WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: Failed to create acl element to track during migration&lt;/P&gt;&lt;P&gt;*** Output from config line 1291, "access-group outside_acc..."&lt;/P&gt;&lt;P&gt;WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;*** Output from config line 1292, "access-group inside_acce..."&lt;/P&gt;&lt;P&gt;WARNING: &lt;/P&gt;&lt;P&gt;MIGRATION: NAT Exempt command is encountered in config.&lt;/P&gt;&lt;P&gt;Static NATs which overlap with NAT Exempt source are not migrated.&lt;/P&gt;&lt;P&gt;Please check migrated ACLs for accuracy.&lt;/P&gt;&lt;P&gt;*** Output from config line 1293, "access-group DMZ_access_..."&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: During migration of access-list &amp;lt;XXXXXXX&amp;gt; expanded&lt;/P&gt;&lt;P&gt;this object-group ACE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit object-group DM_INLINE_SERVICE_5 XXX 255.255.255.0 DMZnet 255.255.255.0 &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;WARNING: MIGRATION: Failed to create acl element to track during migration&lt;/P&gt;&lt;P&gt;*** Output from config line 1298, "access-group XXXXX..."&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 6&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 7&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 9&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Problem with interface 11&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;*** Output from config line 1797, "service-policy global-po..."&lt;/P&gt;&lt;P&gt;NAT migration logs:&lt;/P&gt;&lt;P&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'dmz' and was not migrated.&lt;/P&gt;&lt;P&gt;nat (inside) 1 access-list inside_nat_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WARNING: The following identity NAT was not migrated. If required, an appropriate bypass NAT rule needs to be added.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (outside) 10 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 logserver 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;WARNING: The following identity NAT was not migrated. If required, an appropriate bypass NAT rule needs to be added.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 logserver 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'dmz' and was not migrated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 1 icnetwork 255.255.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: MIGRATION: No memory to create migrated service-policy element&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The following 'nat' command didn't have a matching 'global' rule on interface 'TAV' and was not migrated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz) 1 access-list dmz_nat_outbound&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INFO: NAT migration completed.&lt;/P&gt;&lt;P&gt;ERROR: an object-group with the same name (egitim) exist. &lt;/P&gt;&lt;P&gt;WARNING: Failed to create an object for name 'egitim' in the following ACL:&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 9.1.1.90 object-group egitim any &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-migration-problems/m-p/1907192#M458428</guid>
      <dc:creator>hellishglare</dc:creator>
      <dc:date>2019-03-11T22:39:02Z</dc:date>
    </item>
  </channel>
</rss>

