We have a pair of 5520's running 8.2(5) in Active/Standby mode and we want to upgrade to version 8.4(7). Due to the number and complexity of the NAT statements we have elected to re-construct the NAT statements by hand.
With the Primary unit active we removed the NAT statements from the Secondary (standby) unit, adjusted the boot parameter to boot to 8.4(7) and reloaded.
When the Secondary (standby) ASA powered on it pulled the old config from the Primary (active) and proceeded to perform the upgrade conversion. At that point we rolled back to the 8.2(5) release and config.
It is my understanding that the ASA would not form a failover pair if the firmware versions are different but it did nonetheless.
What is the proper procedure for upgrading the ASA's 8.4 with manual modification to the config? Do we need to break the HA pair and perform the work on one and then the other? Should we convert the Primary first while the Standby is active and then convert the Standby?
This is a 24x7 shop so downtime has to be minimized.
Thanks.