09-25-2013 08:20 AM - edited 03-11-2019 07:43 PM
Hi there ,
What would be best way to migrate a Context from FWSM to ASA (non SM) with minimal down time & effort .
I am thinking of these steps :
1) Preconfigure the new ASA with the same IP-Address as FWSM for the interfaces (keep the ASA subinterfaces in shut state ) , configure Access rules .
( Want to retain same ip for the interfaces , since there are many hosts behind the FWSM with this gateway IP configured )
2) Shut the context specific interfaces on FWSM & bring up the Context specific interfaces on the ASA.
( Also a query - If I introduce ASA into the Network with the same IP as of FWSM , though the interfaces would be in shut state , should i expect any IP Conflicts )
Thanks
Solved! Go to Solution.
09-27-2013 08:28 AM
I'd suggest opening a TAC case for assistance. Let us know what you find out.
09-25-2013 11:03 AM
That sounds like a good plan.
You should not see any IP conflicts as long as both the FWSM context interfaces and corresponding ASA subinterfaces are not up simultaneously.
You may need to flush arp caches on the hosts since I do not believe the ASA will send a gratuitous ARP announcing it owns the interface addresses once they are brought out of shutdown.
09-25-2013 11:15 PM
ok , gratuitous ARP behavior post migration could cause issues then , as we have around 300 - 400 virtual servers behind this ASA context , so flushing ARP on all these boxes may not be possible ; do we have any other recommendations , as our ASA5585X will be running on 9.0.1 code.
Thanks
09-25-2013 11:33 PM
Hi,
Well you probably have the option to configure the old FWSMs interface MAC address to the ASAs corresponding interface manually, this way there will be no change in the ARP from the perspective of the server/host.
I guess depending on if you have a single firewall or failover firewall the command is a bit different as you define either 1 or 2 MAC addresses.
I think this was the command to modify the MAC address
http://www.cisco.com/en/US/docs/security/asa/command-reference/m1.html#wp2111205
- Jouni
09-27-2013 07:06 AM
Thanks Jouni, however we are planning to migrate some 20 contexts with 6 - 8 subinterfaces in each of them ; is their any other way to tweak this gratuitous ARP problem , without having to flush the ARP cache on hosts or replicating mac address from FWSM to ASA.
09-27-2013 08:28 AM
I'd suggest opening a TAC case for assistance. Let us know what you find out.
09-27-2013 08:33 AM
ok thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide