<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664338#M528883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have CISCO 5510 firewall running with IOS ASA821-k8.bin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My company has purchased another ASA5510 with IOS ASA843-k8.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to run both firewalls in Active/Standby mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I upgrade the IOS of old firewall to ASA843-k8.bin the the running&amp;nbsp; configurations does not work properly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not pick the network objects and NAT rules as they are configured&amp;nbsp; with OLD IOS and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or if I restore the configurations of old firewall at New ASA the result is&amp;nbsp; worst. Even firewall with new IOS does not show any Access Rule and NAT rule and&amp;nbsp; does not supprt network objects&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help to solve this issue that how can I upgrade from 8.2 to 8.4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2012 09:14:13 GMT</pubDate>
    <dc:creator>mehmoodch</dc:creator>
    <dc:date>2012-08-16T09:14:13Z</dc:date>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664333#M528878</link>
      <description>&lt;P&gt;Since the "zero-downtime upgrade" is not supported, I would like to validate the process I put together for upgrading a failover pair of asa5550 with the characteristics below. Specifically I am concerned with the role of the standby during the upgrade. This is my setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.- single context mode&lt;/P&gt;&lt;P&gt;.- active/standby&lt;/P&gt;&lt;P&gt;.- current firmware asa821-k8.bin / asdm-621.bin&lt;/P&gt;&lt;P&gt;.- role: firewall and VPN concentrator for segmented server farm network. Dynamic/static/exemption NAT heavily used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My target is asa842-k8.bin / asdm-645.bin and I am doing a two step upgrade (8.2(1) -&amp;gt; 8.3(1) -&amp;gt; 8.4(2)) to avoid the "unidirectional" attribute and CSCtf89372 bug issues. This is a short version of what I have in mind:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- Verify stability of failover pair and make adequate backups before beginning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- plug into the console of active, ssh into active and standby.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# no failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ( disable failover from active )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# asdm image disk0:/asdm-645.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# clear config boot system&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# boot system disk0:/asa831-k8.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# sh bootvar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# write mem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act(config)# end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THIS NEXT STEP IS WHAT I AM CONCERNED WITH. IS THERE A RISK THE STANDBY CAN BECOME ACTIVE? SHOULD I SHUTDOWN OR CUTOFF THE STANDBY FROM THE NETWORK BEFORE DOING THIS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; .- vpn/act# reload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After reboot, point to 8.4(2) and reload again.&amp;nbsp; Same concern regarding the standby unit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand there might be configuration tweaks needed to the NAT configuration. After second reboot test connectivity and if successful, on active "failover", "write standby" and "failover reload-standby". Otherwise "downgrade" and back to the drawing board.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664333#M528878</guid>
      <dc:creator>javier_streb</dc:creator>
      <dc:date>2019-03-11T20:52:46Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664334#M528879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Javier,&lt;/P&gt;&lt;P&gt;The zero-downtime upgrade should work fine, as users have commented at the end of this document:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12690"&gt;https://supportforums.cisco.com/docs/DOC-12690&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- You don't want to disable failover. Doing this won't cause the standby to go active immediately, but it could cause problems with the rest of the upgrade&lt;/P&gt;&lt;P&gt;- You don't want to reload the active unit, make it standby first before you reload. That ensures an instant switchover (instead of reloading the active firewall and waiting for the unit holdtime to expire before the failover occurs).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 19:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664334#M528879</guid>
      <dc:creator>Jay Johnston</dc:creator>
      <dc:date>2011-06-29T19:14:34Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664335#M528880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The doc (&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/admin_swconfig.html#wp1240251"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/admin_swconfig.html#wp1240251&lt;/A&gt;) says :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"You can upgrade from a minor release to the next minor release. You cannot skip a minor release. &lt;/P&gt;&lt;P&gt;&lt;A name="wp1240276"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For example, you can upgrade from 7.0(1) to 7.1(1). Upgrading from 7.0(1) directly to 7.2(1) is not supported for zero-downtime upgrades; you must first upgrade to 7.1(1). "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it mean that we can't update a failover pair from 8.2 to 8.4 with zero-downtime ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Armand&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 08:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664335#M528880</guid>
      <dc:creator>Kooopobol</dc:creator>
      <dc:date>2011-11-18T08:11:25Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664336#M528881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Armand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Short answer, you CAN upgrade from v 8.2 to v 8.4 with out going through v 8.3. following the zero-downtime procedure on a failover pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Granted, you will have to carefully review the resulting NAT configuration and probably do some cleanup after the fact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case we had to skip v8.3 due to a timeout in&amp;nbsp; the NAT migration process that would cause the active unit to force a&amp;nbsp; re-synchronization of the recently upgrade standby back to the previous&amp;nbsp; configuration.&amp;nbsp; I migrated from asa821-k8.bin to asa842-9-k8.bin, note&amp;nbsp; this an interim firmware provided by Cisco support for open cases, not a&amp;nbsp; published binary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bugs that I ran into are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCti36048&amp;nbsp;&amp;nbsp; (3 ASA upgrade to 8.3(2) adds unidirectional keyword to manual nat lines)&lt;/P&gt;&lt;P&gt;CSCtj20724&amp;nbsp;&amp;nbsp; (ASA hitless upgrade from 8.2 to 8.3: upgraded unit reload upon conf sync.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that little support is being&amp;nbsp; put into v8.3 and fixes done on v8.4 are not necessarily being back&amp;nbsp; ported to v8.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;J.S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 14:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664336#M528881</guid>
      <dc:creator>javier_streb</dc:creator>
      <dc:date>2011-11-18T14:15:26Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664337#M528882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco procedure (&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/admin_swconfig.html#wp1240294"&gt;here&lt;/A&gt;) concerning the 8.2 to 8.4 upgrade of an active-standby configuration didn’t run successfully.&lt;BR /&gt;We had to connect on both of them locally to reload the ASAs and restore the failover status&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Armand&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Nov 2011 08:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664337#M528882</guid>
      <dc:creator>Kooopobol</dc:creator>
      <dc:date>2011-11-24T08:02:35Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664338#M528883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have CISCO 5510 firewall running with IOS ASA821-k8.bin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My company has purchased another ASA5510 with IOS ASA843-k8.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to run both firewalls in Active/Standby mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I upgrade the IOS of old firewall to ASA843-k8.bin the the running&amp;nbsp; configurations does not work properly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not pick the network objects and NAT rules as they are configured&amp;nbsp; with OLD IOS and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or if I restore the configurations of old firewall at New ASA the result is&amp;nbsp; worst. Even firewall with new IOS does not show any Access Rule and NAT rule and&amp;nbsp; does not supprt network objects&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help to solve this issue that how can I upgrade from 8.2 to 8.4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 09:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664338#M528883</guid>
      <dc:creator>mehmoodch</dc:creator>
      <dc:date>2012-08-16T09:14:13Z</dc:date>
    </item>
    <item>
      <title>Upgrade asa failover pair from 8.2 to 8.4 w/o zero-downtime</title>
      <link>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664339#M528884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahmood,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My experience is that the NAT reconfiguration will introduce addicional definitions to the ones you had but will still do a valid conversion of what is in place.&amp;nbsp; You might find more network object definitions, access-list entries and NAT definitions but the configuration should still work.&amp;nbsp; Other than rewriting the NAT, access-lists and object-groups should remain plus new addtions.&amp;nbsp; What error messages does the upgrade give you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect that loading a pre version 8.3 configuration on a box running v 8.4 to fail, which is what you are experiencing it seems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;J.S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 15:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrade-asa-failover-pair-from-8-2-to-8-4-w-o-zero-downtime/m-p/1664339#M528884</guid>
      <dc:creator>javier_streb</dc:creator>
      <dc:date>2012-08-16T15:34:15Z</dc:date>
    </item>
  </channel>
</rss>

