<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520-  ISP change  proceedure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772463#M494449</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did change the external IPs few months back on Active/stanby cluster. Please refer to below thread. If you still have queries, please post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3325539#3325539"&gt;https://supportforums.cisco.com/message/3325539#3325539&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Oct 2011 19:10:08 GMT</pubDate>
    <dc:creator>mvsheik123</dc:creator>
    <dc:date>2011-10-31T19:10:08Z</dc:date>
    <item>
      <title>ASA 5520-  ISP change  proceedure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772462#M494446</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our company is going to change its´ ISP.&lt;/P&gt;&lt;P&gt;The External Ips are going to obviously change too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an Active/Standby Firewall and we would like to make the change with at least connectivity downfall as possible.&lt;/P&gt;&lt;P&gt;In our configuration we have nearly all features configured as in a normal Productive Firwall such as , NAT, Site-toSite VPN, Remote Access&lt;/P&gt;&lt;P&gt;Webvpn, ACLs and also routing.&amp;nbsp; I have looked up some information in this community and still I am not sure about the steps to be&lt;/P&gt;&lt;P&gt; made so to reach our goal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read that chaging only the "names" from the old IP Range to the new Ip range would not really make the change.&lt;/P&gt;&lt;P&gt;The old Ip range will still be configured in the features using the external Ip adress. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore we have to first delete all the information (in the runing config) connected to these Variables and then re insert them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My biggest worry is that this could be a little bit tricky during the implementation, if some config lines or objects could be left out &lt;/P&gt;&lt;P&gt;during the deleting and inserting procedure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have someone any idea how we could make this change with a low percentage of "copy and paste failures"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking about in changing the "names" to their new Ips and then afterwards reload the ASA. Will this workout?&lt;/P&gt;&lt;P&gt;Primary ASA will be changed first with the secondary shutdown. ASA Firmware 8.2.2 (12)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ray &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772462#M494446</guid>
      <dc:creator>rayborg</dc:creator>
      <dc:date>2019-03-11T21:44:30Z</dc:date>
    </item>
    <item>
      <title>ASA 5520-  ISP change  proceedure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772463#M494449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did change the external IPs few months back on Active/stanby cluster. Please refer to below thread. If you still have queries, please post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3325539#3325539"&gt;https://supportforums.cisco.com/message/3325539#3325539&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 19:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772463#M494449</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-10-31T19:10:08Z</dc:date>
    </item>
    <item>
      <title>ASA 5520-  ISP change  proceedure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772464#M494455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your prompt answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your proposal was very interesting to read maybe i&amp;nbsp; can try it out this week. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still I have got some questions regarding the doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried implementing the change on our Lab ASA using two different methods.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the&amp;nbsp; first method I have made a copy off the "more system:running config"&amp;nbsp; and edited the &lt;/P&gt;&lt;P&gt;copied version with the new ISP Address Range.&amp;nbsp; Than I TFTPed it back to the ASA on the Startup and reloaded. &lt;/P&gt;&lt;P&gt;The results seemed o.k. but as I said this is our LAb ASA.&amp;nbsp; One issue could be the Pre-shared key for the IPsec&lt;/P&gt;&lt;P&gt;configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My second method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have edited&amp;nbsp; the Objects involved over ASDM and applied the changes. &lt;/P&gt;&lt;P&gt;This methode seemed also to away to reach our goal. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any hidden issues if I have to implement any one from my methods?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said I would like to hear some feedback from persons whom have had already experienced such a measure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again &lt;STRONG&gt;mvsheik123&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate it if we could discuss more about&amp;nbsp; this issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 13:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772464#M494455</guid>
      <dc:creator>rayborg</dc:creator>
      <dc:date>2011-11-02T13:11:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5520-  ISP change  proceedure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772465#M494458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ray,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are not changing the Firewalls here there is no need to use any uploads. But as precautionary, keep tftp copy of current working running config from fw handy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now as far as the names, yes.. just changing names will not work. My preferred method (although not the best), I copy the config to text file and edit (with new IPs) wherever necessary. I keep (names, static, route, tunnel etc) old config lines with &lt;STRONG&gt;'no'&lt;/STRONG&gt; key word form and new config lines as well so that I copy/pastethe config during the maintenance window. That saves lot of time incase of any unforeseen issues and needs time to t-shoot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, Within the maintenanace window I did it phase by phase. (1. Internet 2. DMZ access 3.VPN changes etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you clear the arp tables on external switches and Xlates on ASAs after changing the IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 14:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772465#M494458</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-11-03T14:46:48Z</dc:date>
    </item>
    <item>
      <title>ASA 5520-  ISP change  proceedure</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772466#M494464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this is already marked as "Answered", but i just wanted to air my method.&lt;/P&gt;&lt;P&gt;I'm not sure it the most optimal, and there sure are plenty of room for copy-paste errors. Also, the "Remote Access" part can get a bit tricky i guess, if taking too long.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, i did this a couple of times on a couple of remote ASAs. They weren't paired though, but i can't imagine the procedure being much different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I "simply" added another "outside" interface and duplicated access-lists, NATs and statics, VPN tunnel-groups and so on.&lt;/P&gt;&lt;P&gt;In these particular cases, all i had to switch was outside management, a couple of statics and the VPN tunnels terminated on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my own pace, i could move one tunnel at a time, by just adding a static route to my VPN peer out through the new outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the VPN tunnels were done, new VPN profiles distributed and users notified of the changes, i changed the default route too, making the change complete.&lt;/P&gt;&lt;P&gt;All left to do is a lot of cleanup, but that can be done without disturbing the users too. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, both ISPs have to be active at the same time to accomplish this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;/P&gt;&lt;P&gt;/Sune T.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 22:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-isp-change-proceedure/m-p/1772466#M494464</guid>
      <dc:creator>stt</dc:creator>
      <dc:date>2011-11-07T22:30:15Z</dc:date>
    </item>
  </channel>
</rss>

