cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2137
Views
3
Helpful
3
Replies

ASA 8.3 real ip address automatic migration

jmprats
Level 4
Level 4

Hi, in the ASA Migration Guide for Version 8.3 says about real ip address: "All of the access-list
commands used for these features are automatically migrated unless otherwise noted"

But my ACL's have not been migrated to real ip address. In my migration log:

INFO: NAT migration completed.
Real IP migration logs:
     No ACL was changed as part of Real-ip migration


Why?
So, do I have to migrate them manually?

Thanks

1 Accepted Solution

Accepted Solutions

Yes, there is bug with the outside ACL does not get converted correctly during the migration unfortunately due to NAT exemption ACL configured.

Here is the bugID for your reference: CSCtf57830

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtf57830

The issue is resolved if you were to upgrade from 8.2 to 8.3.2.

Yes, you would need to manually change it at this stage.

View solution in original post

3 Replies 3

Jennifer Halim
Cisco Employee
Cisco Employee

ASA version 8.3 does not use ACL anymore for any of the NAT statements, hence it's saying that there is no change to the ACL.

It will automatically convert that to the same on version 8.3.

But, what I'm saying is that my outside ACL after migration is still using public ip (natted), not real ip address.

so, do i have to migrate outside ACL manually?

Why not be migrated autmotically?

Thanks

Yes, there is bug with the outside ACL does not get converted correctly during the migration unfortunately due to NAT exemption ACL configured.

Here is the bugID for your reference: CSCtf57830

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtf57830

The issue is resolved if you were to upgrade from 8.2 to 8.3.2.

Yes, you would need to manually change it at this stage.

Review Cisco Networking for a $25 gift card