cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2751
Views
15
Helpful
7
Replies

ASA migration from 5520 8.2 to ASA 5545 9.x

Hi All,

I would like to migrate one old ASA cluster from 5520 version 8.2 to ASA 5545 9.x.

 

I would appreciate if you anyone please help me with the steps to follow. 

 

 

Many thanks

JP

4 Accepted Solutions

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

8.2 to 9.X  is big change.

 

How many Rules you have in the FW, if they are Few Hundreds.

 

i will redo the work by creating new ACL rules in the new ASA (install along with Old FW)

in the maintenance window  do the  Cut over to new ASA ( leave the old one still on, in case any issue you can role over back to OLD ASA)

 

Make sense ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Thank you, BB for your quick response on this. What about NAT rules and object groups. As I have more than 200 object groups and 200 NAT/ACLs. So do I need to create all of the manually on new ASA?

my old ASA has too many ACLs and NATs. So I am a bit worried about creating them all manually. Does Cisco have a tool for the conversion to 8.3 or later version?

View solution in original post

Cisco does have a tool but I don't believe it's accessible to end users. Your partner should be able to assist you in creating an conversion. Refer them to https://fwm.cisco.com

 

FWM.PNG

 

If you cannot get access to that, consider the free tools at tunnelsup.com. That can help with pre-migration cleanup and NAT rule conversion.

View solution in original post

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

8.2 to 9.X  is big change.

 

How many Rules you have in the FW, if they are Few Hundreds.

 

i will redo the work by creating new ACL rules in the new ASA (install along with Old FW)

in the maintenance window  do the  Cut over to new ASA ( leave the old one still on, in case any issue you can role over back to OLD ASA)

 

Make sense ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you, BB for your quick response on this. What about NAT rules and object groups. As I have more than 200 object groups and 200 NAT/ACLs. So do I need to create all of the manually on new ASA?

my old ASA has too many ACLs and NATs. So I am a bit worried about creating them all manually. Does Cisco have a tool for the conversion to 8.3 or later version?

Thank you so much, BB. I appreciate your help.

no worries and you welcome.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Cisco does have a tool but I don't believe it's accessible to end users. Your partner should be able to assist you in creating an conversion. Refer them to https://fwm.cisco.com

 

FWM.PNG

 

If you cannot get access to that, consider the free tools at tunnelsup.com. That can help with pre-migration cleanup and NAT rule conversion.

Thank you so much for letting me know about this hidden tool :). I appreciate your time and help.

I will contact Cisco in case they can help me.
Review Cisco Networking for a $25 gift card