05-03-2019 10:45 AM - edited 02-21-2020 09:06 AM
Hi All,
I would like to migrate one old ASA cluster from 5520 version 8.2 to ASA 5545 9.x.
I would appreciate if you anyone please help me with the steps to follow.
Many thanks
JP
Solved! Go to Solution.
05-03-2019 01:49 PM
8.2 to 9.X is big change.
How many Rules you have in the FW, if they are Few Hundreds.
i will redo the work by creating new ACL rules in the new ASA (install along with Old FW)
in the maintenance window do the Cut over to new ASA ( leave the old one still on, in case any issue you can role over back to OLD ASA)
Make sense ?
05-03-2019 09:34 PM
05-04-2019 12:45 AM - edited 05-04-2019 12:46 AM
Once of the document attached may help you.
Also this reference :
https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/planning.html
https://www.cisco.com/c/en/us/td/docs/security/asa/asa83/upgrading/migrating.html
05-04-2019 04:37 AM
Cisco does have a tool but I don't believe it's accessible to end users. Your partner should be able to assist you in creating an conversion. Refer them to https://fwm.cisco.com
If you cannot get access to that, consider the free tools at tunnelsup.com. That can help with pre-migration cleanup and NAT rule conversion.
05-03-2019 01:49 PM
8.2 to 9.X is big change.
How many Rules you have in the FW, if they are Few Hundreds.
i will redo the work by creating new ACL rules in the new ASA (install along with Old FW)
in the maintenance window do the Cut over to new ASA ( leave the old one still on, in case any issue you can role over back to OLD ASA)
Make sense ?
05-03-2019 09:34 PM
05-04-2019 12:45 AM - edited 05-04-2019 12:46 AM
Once of the document attached may help you.
Also this reference :
https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/planning.html
https://www.cisco.com/c/en/us/td/docs/security/asa/asa83/upgrading/migrating.html
05-06-2019 09:09 AM
05-06-2019 09:40 AM
no worries and you welcome.
05-04-2019 04:37 AM
Cisco does have a tool but I don't believe it's accessible to end users. Your partner should be able to assist you in creating an conversion. Refer them to https://fwm.cisco.com
If you cannot get access to that, consider the free tools at tunnelsup.com. That can help with pre-migration cleanup and NAT rule conversion.
05-06-2019 09:08 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide