12-29-2014 12:09 PM - edited 03-11-2019 10:16 PM
I downgraded and
How can I fix this?
Thanks.
12-29-2014 05:03 PM
Some features are named / packaged differently on ASA 8.2. Also, you don't inherit the licenses from the mate in an HA pair.
Which exact licenses are giving you a problem?
12-30-2014 03:40 AM
It with the Annyconnect
I
thanks.
12-30-2014 05:00 AM
Have you tried to reinstall the AnyConnect license? If yes, what were the results (please give the exact error, if any, that you received)
Could you please post the output of the following commands:
dir
show version
--
Please remember to select a correct answer and rate helpful posts
12-31-2014 03:19 AM
Hi all,
I will do a downgrade today again from 8.4 to 8.2 and reinstall the license, but one thing about Marvins comments, from the old version I have the 7.2.2
Thanks.
12-31-2014 05:40 AM
A 7.2(2) configuration file is not designed to work with an 8.2 OS. Much of it may work, but other bits may not.
You would be better off analyzing the 8.4 configuration and re-entering "by hand" it with manually modified syntax changes (i.e. NAT rules and access-lists referring to NAT addresses vs. real IP addresses) onto the 8.2 appliance.
All begging the question of why one would want to do so in the first place....
12-31-2014 10:14 AM
12-31-2014 12:36 PM
Hello Marius
Here is the output you requested.
Cisco Adaptive Security Appliance Software Version 8.4
Compiled on Tue 18-Jan-11 01:33 by builders
Config file at boot was "startup-config"
ASA5510 up 1 day 0 hours
Hardware: ASA5510, 1024 MB RAM, CPU Pentium 4 Celeron 1600 MHz
Internal ATA Compact Flash, 64MB
BIOS Flash AT49LW080 @ 0xfff00000, 1024KB
Licensed features for this platform:
Maximum Physical Interfaces
Maximum VLANs
Inside Hosts
Failover
VPN-DES
VPN-3DES-AES
Security Contexts
GTP/GPRS
Other VPN Peers
Total VPN Peers
Shared License
Advanced Endpoint Assessment
UC
Total UC Proxy Sessions
Botnet Traffic Filter
Directory of disk0
97 -rwx 15390720 01:18:40 Jan 01 2003 asa825-k8.bin
99 -rwx 8312832 09:36:52 Mar 12 2007 asa722-k8.bin
100 -rwx 5623108 09:38:12 Mar 12 2007 asdm-522.bin
101 -rwx 24938496 02:31:58 Jan 01 2003 asa840-128-k8.bin
3
6
86 -
14
102 -
103 -
104 -
106 -
12-31-2014 01:15 PM
You will most likely, as Marvin has hinted on, take a manual backup of your current running config and then manually adjust the configuration to suite the 8.2 version. another option would be to take the running config of one of the other 8.2 ASAs and amend that to the needs of the new ASA (IP addresses, ACLs, NAT, VPN pools...etc.)
--
Please remember to select a correct answer and rate helpful posts
01-01-2015 06:37 AM
Marius,
In this firewall I have no configuration is blank, when you mean
Directory of disk0
75
80
176 -rwx 7598456 19:02:14 Mar 17 2009 asdm-615.bin
177 -rwx 8570880 18:27:50 Dec 15 2011 asa725-k8.bin
178 -
179 -rwx 15390720 18:31:38 Dec 15 2011 asa825-k8.bin
180 -
181 -
182 -rwx 13934592 19:52:04 Dec 16 2011 asa805-k8.bin
183
184 -
185 -
186 -
187 -
188 -
189 -
190 -rwx 11491880 11:34:58 Mar 31 2010 asdm-623.bin
Thanks!!
01-01-2015 06:37 AM
On the firewall with default configuration here is how I would do it:
1. Upload the desired image and set the boot variable to that image.
2. Save and reload.
3. Verify your running version and that the activation key still shows the desired licenses using "show version".
4. Open "7_2_2_0_startup_cfg.sav" in a text editor and enter the lines into the firewall in config mode.
5. Investigate and remedy any lines that present invalid syntax due to 7.x - 8.x differences.
6. Save and reload once more. Double check disk0: for a file "startup_errors" (exact name will vary) to see if any lines didn't parse correctly.
7 Test proper operations in the production environment during an approved change window.
12-30-2014 11:35 AM
The downgrade in itself should not remove the license. I would (as Marius suggested) see what "show ver" reports.
Also the configuration backup you specified seems to be from a very old version - 7.2(2). There may be commands (or lack of commands) in that to prevent the AnyConnect Premium from working.
Depending on what features you were using you may also need to verify copies of dap.xml and clientless portal configuration etc.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide