05-18-2016 08:48 AM - edited 03-12-2019 12:45 AM
Good morning
Currently we have to ASA 5585-X in Fail-over (Acitve-Passive) mode, we have configured 4 interfaces for the DMZ zones, each one at 1 Giga, now we bought the Security Plus License to enable the 10 Giga interfaces.
The question is how I can migrate the configuration from my 4 interfaces at 1 Giga each to my interfaces at 10 Giga in a port-channel against our Nexus switches for our DMZ zones, the new interfaces at 10 Giga will be configured with subinterfaces, so the main idea is to migrate the current configuration from 4 physical interfaces to one port-channel in subinterfaces.
Thanks a lot for all your comments.
Solved! Go to Solution.
05-18-2016 07:33 PM
You need to first copy the current configuration to a file. Separate out any access-lists, NAT rules and other configuration associated with the "nameifs" that you will be migrating. The reason is tthat your will have to remove the interface "nameif" which will delete those bits as well.
Then build the 10 Gbps subinterfaces and assign the desired nameifs on them. Finally reapply the bits you separated out already.
I'd finish up with a diff (I use and recommend the Examdiff tool from Prestosoft) of the before and after configuration to make sure you didn't miss anything.
05-18-2016 07:33 PM
You need to first copy the current configuration to a file. Separate out any access-lists, NAT rules and other configuration associated with the "nameifs" that you will be migrating. The reason is tthat your will have to remove the interface "nameif" which will delete those bits as well.
Then build the 10 Gbps subinterfaces and assign the desired nameifs on them. Finally reapply the bits you separated out already.
I'd finish up with a diff (I use and recommend the Examdiff tool from Prestosoft) of the before and after configuration to make sure you didn't miss anything.
05-20-2016 08:51 AM
Thanks a lot for your answer Marvin
I will try this on my lab and as soon as I have result I'll be back.
06-02-2016 06:00 AM
Good morning Marvin
Thanks a lot for your answer, I test it and it work perfectly. But now I have another question:
Can you explain me the difference between a zone and a port-channel in the ASA, when I can use each one? Are they exclusive? Can I have a port-channel inside a zone or sub interfaces inside the zone? Can I have both working at the same time?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide