cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
498
Views
0
Helpful
5
Replies

Pix to asa 5510

mrehman02
Level 1
Level 1

Dears, I am trying to upgrade my pix 515 to ASA 5510 . I have mostly copied the configuration but is stuck on one part where we have  set the IP next hop in the pix. For some reason I cant find the SET IP NEXT HOP command in the asa. What could be the reason? Please advice

1 Accepted Solution

Accepted Solutions

So it seems like you are trying to running PBR (Policy Based Routing). This feature was not available in the ASA code until 9.4:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html

Unfortunately, ASA 5510 is End-of-Life/End-of-Sale and as a result, the latest version that it can run is 9.1. Thus, you should look into replacing that ASA with a next-generation model ASA (X series). This will allow you to run the desired code for PBR and will also give you the option(s) to run some next-generation features (NGIPS, Malware inspection, etc). 

I hope this helps!

Thank you for rating helpful posts!

View solution in original post

5 Replies 5

nspasov
Cisco Employee
Cisco Employee

Hi there, can you post the exact syntax from the PIX?

Thank you for rating helpful posts!

Hi, Please find it below.

route-map NETWORK-1 permit 10
set metric 2
set ip next-hop 10.40.60.5
match ip address 150
route-map NETWORK-1 permit 20
set metric 5
set ip next-hop 10.40.60.8
match ip address 160

So it seems like you are trying to running PBR (Policy Based Routing). This feature was not available in the ASA code until 9.4:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html

Unfortunately, ASA 5510 is End-of-Life/End-of-Sale and as a result, the latest version that it can run is 9.1. Thus, you should look into replacing that ASA with a next-generation model ASA (X series). This will allow you to run the desired code for PBR and will also give you the option(s) to run some next-generation features (NGIPS, Malware inspection, etc). 

I hope this helps!

Thank you for rating helpful posts!

Thank you. That explains!!

No problem. Sorry to bring the bad news :(

Thank you for rating helpful posts!

Review Cisco Networking for a $25 gift card