<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.3 Migration - Expanded Access list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712426#M557186</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is expected behavior in the configuration conversion process.&lt;/P&gt;&lt;P&gt;Unfortunately, there is no way of automatically getting back the previous config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could edit the access-list part of your 8.2 config, to allow traffic to real ip, instead of translated ip, and add that configuration into the cli.&lt;/P&gt;&lt;P&gt;However, this will involve some downtime, as you would have to delete the existing access-lists before doing that. You might also need to add/edit the object groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest making a backup of the current 8.3 config before doing this as well, just in case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark this question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Apr 2011 13:00:32 GMT</pubDate>
    <dc:creator>Shrikant Sundaresh</dc:creator>
    <dc:date>2011-04-25T13:00:32Z</dc:date>
    <item>
      <title>ASA 8.3 Migration - Expanded Access list</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712425#M557185</link>
      <description>&lt;P id="[object]"&gt;I have just upgraded a ASA5510 from 8.2 to 8.3 using migration tool.&lt;/P&gt;&lt;P id="[object]"&gt;All seemed to go well, still double checking the config as this is a bench test of upgrade prior to filed upgrades.&lt;/P&gt;&lt;P id="[object]"&gt;&lt;/P&gt;&lt;P id="[object]"&gt;Anyway one thing that is slightly frustrating is that the migration has expanded all of my access-lists, so we maybe had 10 lines of config relating to access-lists based on access-groups, now we have hundreds of lines.&lt;/P&gt;&lt;P id="[object]"&gt;On ASDM this is bad enough but on CLI with show run its a bit of a bind.&lt;/P&gt;&lt;P id="[object]"&gt;&lt;/P&gt;&lt;P id="[object]"&gt;Is there any way to un-expand the access list or do I simply delete and start again using my access groups.&lt;/P&gt;&lt;P id="[object]"&gt;&lt;/P&gt;&lt;P id="[object]"&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Any thoughts appreciated&lt;/SPAN&gt;&lt;/P&gt;&lt;P id="[object]"&gt;&lt;/P&gt;&lt;P id="[object]"&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712425#M557185</guid>
      <dc:creator>shaucall46</dc:creator>
      <dc:date>2019-03-11T20:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Migration - Expanded Access list</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712426#M557186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is expected behavior in the configuration conversion process.&lt;/P&gt;&lt;P&gt;Unfortunately, there is no way of automatically getting back the previous config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could edit the access-list part of your 8.2 config, to allow traffic to real ip, instead of translated ip, and add that configuration into the cli.&lt;/P&gt;&lt;P&gt;However, this will involve some downtime, as you would have to delete the existing access-lists before doing that. You might also need to add/edit the object groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest making a backup of the current 8.3 config before doing this as well, just in case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark this question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Apr 2011 13:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712426#M557186</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-25T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.3 Migration - Expanded Access list</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712427#M557187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P id="[object]"&gt;&lt;/P&gt;&lt;P id="[object]"&gt;As this was a test bed for future upgrades to 8.3, I think I would much rather re-write to config on 8.3 than run through the migration tools and have unknowns.&lt;/P&gt;&lt;P id="[object]"&gt;Basically what I did here was rolled back my config to 8.2 and re-did the config as suggested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 13:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-3-migration-expanded-access-list/m-p/1712427#M557187</guid>
      <dc:creator>shaucall46</dc:creator>
      <dc:date>2011-05-09T13:52:45Z</dc:date>
    </item>
  </channel>
</rss>

