10-18-2010 07:02 AM - edited 03-11-2019 11:55 AM
Wanted to upgrade the ASA to version 8.2. Current ASA version is 7.0(8) - see below
Currently running AS 5520
Cisco Adaptive Security Appliance Software Version 7.0(8)
Device Manager Version 5.0(8)
to
Leased a ASA 5520
Cisco Adaptive Security Appliance Software Version 8.2(3)
Device Manager Version 6.3(4)
Leased a Cisco ASA 5520 with version 8.2 (3)
I basically copied the configuration from the current ASA to the new one. I placed the new ASA in place & started having external DNS problems, internal websites no problems.
All workstation point to several internal Windows 2003 DNS servers.
Placed a call with TAC, TAC looked at the ASA & could not come up with a solution. I place the old ASA back into place any everything works OK !
Any Ideas !!
10-18-2010 07:09 AM
Hi,
Could you provide reference to the TAC SR number and also provide the config of your device if possible?
10-18-2010 08:26 AM
I sent you the SR case # & the configuration, thanks
10-18-2010 11:33 PM
Hey,
Mike here, would you mind posting the SR number so I can check it really quick?
Cheers
Mike
10-19-2010 04:00 AM
SR: 615746171
10-19-2010 05:48 AM
Hello,
I see the problem now. Would you be able to put the asa 5520 back and try to do queries from the DNS server?
Let me know.
Mike
10-19-2010 05:58 AM
Unfortunately I can't place the updated AS
A until Sunday morning, can you tell me what you think the problem is, thanks.
10-19-2010 06:13 AM
Hey.
Between my thoughts is that either there is something different on the configuration, or any of the codes that you have may be running into a bug. Can you tell me the following?
What is the model of the old device?
What is the version of the old device and the version from the new device?
Cna you send me both configurations?
Something that I dont know if you tried was to try to do DNS lookups from your internal DNS server itself.
Will be waiting for your inputs.
Mike
10-19-2010 06:44 AM
I sent you the infomation, thanks
10-19-2010 11:31 AM
Hello,
If you post the santized information here it may help to get you an answer faster since there will be more available eyes to look at the problem.
As Mike mentioned above, you'll want to confirm that there were no unintended configuration changes when the ASAs were swapped. Also, you should verify the ARP tables on the clients, DNS server, and network devices that share a layer 2 broadcast domain with the ASA to make sure that they were successfully updated for the new hardware's MAC address.
Hope that helps.
-Mike
10-19-2010 11:43 AM
I took another approach to this problem. I placed the same ASA version 7.08 & configuration on the new ASA. I then updated from 7.08 to 7.1 to 7.2 then to 8.2 (3). I will be placing this in production on Friday morning. I will post my results late Friday morning.
Thanks
10-22-2010 02:36 PM
Hello
Today is the day when you were going to put the firewall in production, please let me know if that worked for you, if not, I think it would be better to reopen the TAC case.
Cheers
Mike
10-25-2010 12:17 PM
Sorry for the delayed reply, yes that work, DNS problems resolverd !
10-25-2010 12:20 PM
Excellent, I am glad to hear that, would you please mark this issue as resolved so other people can take it as a reference?
Cheers
Mike
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide