01-06-2012 07:23 AM - edited 03-11-2019 03:11 PM
Hello,
We're planning the upgrade from 8.2 to 8.4, which I understand has NAT and ACL changes. I've read the migration guide at http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.pdf
My understanding is that the upgrade procedure will convert the NATs, and place real IPs in the ACLs instead of the translated IPs.
But in looking through my 8.2 configs it appears the real IPs are already being used in my access lists. For example x.x.x.x is my public IP, and y.y.y.y is my internal IP. This is my current config:
static (inside,outside) x.x.x.x y.y.y.y netmask 255.255.255.255
access-list acl_out extended permit tcp any host x.x.x.x eq ssh
So it seems that the 8.4 upgrade won't need to change anything. Is that correct?
Thanks
Bill
Solved! Go to Solution.
01-06-2012 12:43 PM
Thanks. What would be the upgrade plan for an HA active/standby pair?
Does that sound right?
01-06-2012 12:52 PM
Nope, the best would be to make the primary active and upgrdae the secondary (standby) first to the image that you would like to finally go to, failover and make secondary active and and then upgrade the primary box to the right image, this way you would not lose any traffic and would be up all the time.
Thanks,
Varun
01-06-2012 12:54 PM
That makes a lot more sense, I like that. But for some reason that's not what another engineer recommended (SR
620272873)
Tom
01-06-2012 01:05 PM
Hey Thomas, I just went through it and there are two things in here:
Number one - going by the book (which is wat the engineer recommends you)
Number two - my own personal experience, because there have been situations where in some TAC's I did a lab repro for the upgrdae as other customers were apprehensive about doing it on their production device, I did the way I told you, no issues.
So what he must have told, would definitely have a good reason for it or some experience that he can share, I would say, you can definitely talk to the engineer and he would definitely explain you his reason behind it. Just make sure you have your memory requirements spot on.
I hope I was able to clear it out.
Thanks,
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide