cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
404
Views
0
Helpful
1
Replies

Changing ISP, how would I go about updating the public IP's on ASA

Andrew White
Level 2
Level 2

Hello,

We have 2 x ASA 5520s in active/standby and we have a block of 30 public IP's that NAT to many servers etc and we use it for our Corp VPN.  We are changing ISPs soon and we will be getting a new block of public IPs   where do I even start to plan the migration and how?  Can I overlap somehow and do a slow migration or must I do it in one big swoop?

Thanks

1 Reply 1

Azubuike Obiora
Level 1
Level 1

Hi Andrew,

Ok I haven't hard the priviledge to be in your shoes, but I think from what I know with the Active/Standby, all you need to do is change the IP address on the Active firewall, which replicates on the Standby remember that's why you have the Failover link, to replicate Configuration to the Standby firewall. Also you'll need to contact those you are having your VPN tunnel with to give them your new IP to update their  tunnel-group xxx.xxx.xxx.xxx type ipsec-l2l, tunnel-group xxx.xxx.xxx.xxx ipsec-attributes.   But please backup your previous configs just before you start doing the change! It's always go to err on the side of caution.

I hope this helps anyway.

BRGS

Teddy

Review Cisco Networking for a $25 gift card