05-31-2018 09:09 AM - edited 02-21-2020 07:49 AM
Hi All
Are there any ASA migration tools or checkers you can use when say moving from a 5520 to 5545?
cheers
05-31-2018 12:48 PM
For my migrations, I never used any tools as I typically don‘t like what they produce. I would look at two different scenarios:
1) the old ASA is running a version < 8.3: then I would first update to 8.4, but dump all the NAT-config and rewrite that from scratch. Then update to 9.1, take that config to the new platform and update to the desired version (I would typically go for 9.8x at the moment).
2) If you are already on 8.3 or newer, update to 9.1 and then move to the new platform, same as above.
05-31-2018 02:34 PM
05-31-2018 11:06 PM
Karsten has a good point, but I have had good results migrating the NAT configuration using the free tool at tunnelsup.com. They also have a config cleanup tool to identify unused objects and ACLs.
Cisco does have a tool (fwmig) available to partners that works ok for larger migrations. If you're working with a partner SE they should be able to help you with that as an option.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide