01-22-2013 08:20 AM - edited 03-11-2019 05:50 PM
Just a quick question that I want to confirm.
Customer has a ASA5540 at their main location and need a new ASA5500 for a DR site.
Can I simply take a config file from an ASA5540 and easily drop it on an ASA5545-X or what ever?
They are going to be using it as a VPN concentrator primarily.
Or are there going to be issues since the 5540 is running 8.4(5) and the 5545-X?
Or if they upgrade to 9,0(1) or higher, then they should be the same?
Thanks.
01-22-2013 05:28 PM
Hello,
The syntax is the same after version 8.3, so 8.4.5 and 8.6 + are compatible.
The interfaces are GE for both ASAs so this won't be an issue.
I would just try to do it by sections so I'll notice if I get an error for any of the lines.
Regards,
Felipe.
01-22-2013 07:19 PM
Richard,
Felipe is correct regarding the syntax compatibility. 5500-X models will most likely be shipped with 8.6. (A couple I unboxed in the last two months had that.) 8.6 releases were specific to -X series (8.5 for ASA services module and 8.4 for classic 5500 series).
Personally I like standardization and would just put them all on 9.0(1) software - even though it's not a requirement for interoperability and configuration compatibility. 9.1 adds no features or bug fixes to the base system - only adds support for CX (with the required SSD also having to be added) - so I've not been loading that.
Remember that if you are exporting VPN configurations that the pre-shared keys (if you're using PSKs on your VPNs) are not included by default. You need to backup using "more system:running-config" (after a "term pager 0") or similar such approach.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide