11-20-2019 05:27 AM - edited 02-21-2020 09:42 AM
HI Everyone,
We want to do a downgrade for our ASA, they are working on Failover A/S mode. I am not sure about this operation.
What should I do? Is there a detailed step? Does the implementation of this downgrade process require a transition to an intermediate version?
In addition, is there any need to pay attention to such a downgrade?
Thanks
11-20-2019 05:54 AM
why you want to downgrade to 8.2 from 8.4. the new NAT were introduced in 8.4 and they are called unified nat. going back to 8.2 your nat rules might not work and you need a properly understand how the old nat syntax work. also to mention the 8.2 is not supported any more and it gone end of life.
11-20-2019 06:30 AM
11-20-2019 06:33 AM
11-20-2019 06:50 AM
there is side effect on the downgrade, not sure what is the reason for downgrade? (i am more interested to know)
here is the downgrade procedure ( read "Important Notes")
https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/release/notes/asarn84.html
11-20-2019 07:04 AM
11-20-2019 07:33 AM
I can understand ( we need to educate the Business what is the security risk here - being FW, we expect to protect the network, not tigive hand over our network to hackers - by installing the outdated version which has security holes.)
Make sure to take the backup of the config. in case something really goes bad while degrading.
Maintenance window - Boot with Old Version and test it.
11-20-2019 04:32 PM
11-21-2019 12:49 AM
in this case, I suggest breaking the HA and downgrade both, and join them back.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide