cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1709
Views
10
Helpful
7
Replies

ASA software upgrade

vipinrajrc
Level 3
Level 3

Hi

I like to upgrade my ASA 5510  from 7.0.8  to 7.2.5. So how can i test this version will work successfully??? Its a live enviourment.. So could anyone can suggest a best method for the same...???

Thanks&Regards

Vipin

Thanks and Regards, Vipin
1 Accepted Solution

Accepted Solutions

Hi Vipin

i have changed all our asa 55xx (5,10,20)  without a problem you can download the new software on the flash and also the software for asdm (when using)

make a copy of your running config

the onyl thing is the bootvariable must be changed before reolad and also the entry for the asdm:

copy tftp://192.168.0.1/fire/image/asa/asa725-k8.bin flash:

copy tftp://192.168.0.1/fire/image/asa/asdm-525.bin flash:

so the new version is on the flash   controll it with show flash:

then set in config mode

boot system disk0:/asa725-k8.bin

no boot system disk0:/asa703-k8.bin

override with the new asdm version

asdm image disk0:/asdm-525.bin

the config will still exist without problems i have testet it before i do this on production

reload

so for maintenance window on the 5510 you need under 2 minutes for the reload.

when it works you can delete the old software under

delete flash:/asa703-k8.bin

delete flash:/asdm503.bin

hope that will help you

regards

Klaus

View solution in original post

7 Replies 7

You need a tftp server with the desired imags in it. Use the command copy tftp flash and load the new image. change the boot system command to point to the new image stored in flash. A reload will be needed so traffic will get interrupted.

Does that help?

Sent from Cisco Technical Support iPhone App

Hi

Thanks for kind reply.. yes it is helpful... but it is a live environment, so a reload may be a problem...

There is so many ACEs in that ASA.. so if upgrade the current running configuration will be there or not??? Also there is IPSEC VPN configuration... So is ther any probelm when upgrading from current version to newer one.....

Thanks&Regards

Vipin

Thanks and Regards, Vipin

You can upgrade the software all you want but unless you reboot the appliance, the ASA will not load the new IOS you want.

IF it's a live environment and you want to test the new IOS, then it's a question of getting a spare ASA to test or a change window.

Hi

leolaohoo wrote:

You can upgrade the software all you want but unless you reboot the appliance, the ASA will not load the new IOS you want.

IF it's a live environment and you want to test the new IOS, then it's a question of getting a spare ASA to test or a change window.

So the startup configuration will exist ,  right?????? Or we have to enter all the configuration again???? Please make it clear that we need the startup configuration to be unchanged with the new software.............

Thanks&Regards

Vipin

Thanks and Regards, Vipin

Hi the config will still exist, you don't have to enter it all again.

I suggest that you review the release notes for the software that can be found here

http://www.cisco.com/en/US/docs/security/asa/asa72/release/notes/asarn725.html#wp286922

There have been some bug fixes and new features released between your current version and the new version that you are planning to upgrade to.

Before commencing the upgrade make sure that you have a backup of your current config and existing IOS in case you need to rollback your changes.

Hi Vipin

i have changed all our asa 55xx (5,10,20)  without a problem you can download the new software on the flash and also the software for asdm (when using)

make a copy of your running config

the onyl thing is the bootvariable must be changed before reolad and also the entry for the asdm:

copy tftp://192.168.0.1/fire/image/asa/asa725-k8.bin flash:

copy tftp://192.168.0.1/fire/image/asa/asdm-525.bin flash:

so the new version is on the flash   controll it with show flash:

then set in config mode

boot system disk0:/asa725-k8.bin

no boot system disk0:/asa703-k8.bin

override with the new asdm version

asdm image disk0:/asdm-525.bin

the config will still exist without problems i have testet it before i do this on production

reload

so for maintenance window on the 5510 you need under 2 minutes for the reload.

when it works you can delete the old software under

delete flash:/asa703-k8.bin

delete flash:/asdm503.bin

hope that will help you

regards

Klaus

Hi ksimsimon,

Thanks for your kind reply.. thats very helpfull............!!!!!!!!!!!!!!!!!!!

Thanks and Regards, Vipin
Review Cisco Networking for a $25 gift card