06-09-2011 09:07 AM - edited 03-11-2019 01:43 PM
Has anyone upgraded an ASA5520 from 7.x to 8.4 in one step? Release notes for 8.4 state that you can "...upgrade from any previous release directly to 8.4..." I've read the previous version release notes and see the various changes in NAT etc that 8.3 made.
06-09-2011 09:14 AM
Hi Thammerle,
I would suggest you to follow the upgrade chain:
7.2 ----> 8.0 ------> 8.2 ------> 8.4
This is the best recommended upgarde path.
https://supportforums.cisco.com/docs/DOC-12690
Hope this helps.
Thanks,
Varun
06-09-2011 11:10 AM
What is your logic for this? I can find no such recommendation in cisco documentation for upgrading to 8.4.
06-13-2011 08:12 AM
We upgraded both pairs from 7.2(1) to 8.4(1) pretty much without incident. In one pair two rules failed to migrate which appeared to be related to NAT. Otherwise it was pretty smooth. We had one VPN tunnel setup on one pair, not in active use, and the migration seemed to think we had "NAT exempt" in the config, that failed to migrate associated rules. NAT exempt seems to be a misnomer for 'nat 0' or 'nat 0 access-list' neither of which were in the config. If you've got VPN's configured you probably will have more fun migrating the config manually or trying to re-write it in 8.4 beforehand.
Hardware upgrades went well, the failover nodes saw each other. It was interesting when the 8.4(1) active node coped it's config to the standby 7.4(1) node which didn't recognize alot of it. The standby node remailed inactive. After rebooting the standby node to 8.4(1) it was normal.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide