cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
651
Views
0
Helpful
3
Replies

ASA Upgrade from 8.0(3) to 8.4(transparent - Active/Active)

juno_q_beat
Level 1
Level 1

Hi all

I have a question with regards to upgrade software on ASA 5550 8.0(3) to 8.4(transparent - Active/Active)

We have 2x Failover pars of ASA 5550 (4Gb Ram 256MB of Flash)

As far as I know there are some restrictions with regards to upgrade to 8.4 directly. I am wondering if this is true and what would be the best approach in terms of update with no downtime

Your suggestions are very much appreciated

Show version :

Hardware:   ASA5550, 4096 MB RAM, CPU Pentium 4 3000 MHz

Internal ATA Compact Flash, 256MB

BIOS Flash M50FW080 @ 0xffe00000, 1024KB

Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)

                             Boot microcode   : CN1000-MC-BOOT-2.00

                             SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.01

                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.04

0: Ext: GigabitEthernet0/0  : address is 001e.f760.93f2, irq 9

1: Ext: GigabitEthernet0/1  : address is 001e.f760.93f3, irq 9

2: Ext: GigabitEthernet0/2  : address is 001e.f760.93f4, irq 9

3: Ext: GigabitEthernet0/3  : address is 001e.f760.93f5, irq 9

4: Ext: Management0/0       : address is 001e.f760.93f6, irq 11

5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11

6: Int: Not used            : irq 5

7: Ext: GigabitEthernet1/0  : address is 001e.7a81.92c3, irq 255

8: Ext: GigabitEthernet1/1  : address is 001e.7a81.92c4, irq 255

9: Ext: GigabitEthernet1/2  : address is 001e.7a81.92c5, irq 255

10: Ext: GigabitEthernet1/3  : address is 001e.7a81.92c6, irq 255

11: Int: Internal-Data1/0    : address is 0000.0003.0002, irq 255

Licensed features for this platform:

Maximum Physical Interfaces  : Unlimited

Maximum VLANs                : 250      

Inside Hosts                 : Unlimited

Failover                     : Active/Active

VPN-DES                      : Enabled  

VPN-3DES-AES                 : Enabled  

Security Contexts            : 10       

GTP/GPRS                     : Disabled 

VPN Peers                    : 5000     

WebVPN Peers                 : 2        

AnyConnect for Mobile        : Disabled 

AnyConnect for Linksys phone : Disabled 

Advanced Endpoint Assessment : Disabled 

3 Replies 3

lcambron
Level 3
Level 3

Hello,

You can upgrade directly to 8.4:

http://www.cisco.com/en/US/docs/security/asa/asa84/release/notes/asarn84.html#wp628310

However since this is a mayor upgrade, no downtime is not supported, it is better to have a window in case you have any issue.

Regards,

Felipe.

Do you know what will be a best/stable 8.2 version that I can use in case if I will not go with 8.4

Hello,

We do not usually recommend releases since it depends on the features you need (possible bug fixes needed), etc.

I would just go with the latest on 8.2 (8.2.5) which is an stable version.

Regards,

Felipe.

Review Cisco Networking products for a $25 gift card