cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
756
Views
0
Helpful
7
Replies

ASA Upgrade

zietgiestt
Level 1
Level 1

Hello,

I have 3 ASAs I need to upgrade from 9.8(1)>9.16.4(57). 
Can anyone tell me if I need to go 9.8(1)>9.16.4>9.16.4(57)?

Or can I just go straight to the (57)?


Thanks,


2 Accepted Solutions

Accepted Solutions

@zietgiestt the output is normal on ASA hardware.

You'd see that other output if using the newer Firepower hardware.

View solution in original post

7 Replies 7

@zietgiestt you can upgrade directly from 9.8 to 9.16 (57) without an interim upgrade.

https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/planning.html#id_58680

 

zietgiestt
Level 1
Level 1

Thanks Rob

zietgiestt
Level 1
Level 1

Rob(or anyone that knows),

1 more quick question...according to Cisco documentation, when I set the new boot system command, I should see this:

ciscoasa(config)# boot system disk0:/cisco-asa-fp1k.9.14.1.SPA

The system is currently installed with security software package 9.13.1, which has:
- The platform version: 2.7.1
- The CSP (asa) version: 9.13.1
Preparing new image for install...
!!!!!!!!!!!!!
Image download complete (Successful unpack the image).
Installation of version 9.14.1 will do the following:
- upgrade to the new platform version 2.8.1
- upgrade to the CSP ASA version 9.14.1
After the installation is complete, reload to apply the new image.
Finalizing image install process...

Install_status: ready...........
Install_status: validating-images.....
Install_status: update-software-pack-completed
ciscoasa(config)#

However, I actually only see this:

ASA-PRI(config)# boot system flash:/asa9-16-4-57-lfbff-k8.SPA
INFO: Converting flash:/asa9-16-4-57-lfbff-k8.SPA to disk0:/asa9-16-4-57-lfbff-k8.SPA
ASA-PRI(config)#

 

Is this normal?


Thanks,

 

 

 

 

@zietgiestt you are using ASA hardware not Firepower hardware?

FYI, in version 9.13 weak crypto was depreciated. If you are using VPNs ensure you are not using weak DH groups, encryption and integrity before upgrading.

asa 5506 

Thanks for the heads up on the vpn tunnels. I'm actually using what will be a deprecated DH group in one of my tunnels

@zietgiestt the output is normal on ASA hardware.

You'd see that other output if using the newer Firepower hardware.

Thanks again Rob...

Review Cisco Networking for a $25 gift card