cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1642
Views
5
Helpful
4
Replies

Migrating Context to another Multiple Mode ASA FW

johnlloyd_13
Level 9
Level 9

hi,

i'll be migrating customer context from one multiple mode ASA FW to another.

can someone confirm the steps below or advice if there's an alternative or easy way to do it?

1.transfer context .cfg file to the new FW

2.pre-configure the subinterface/VLAN under system context in the new FW

3.remove the context in the old FW under 'system' context with 'no context CUST-A'

4.configure the context in the new FW under 'system' context, allocate-interfaces, and point the transferred .cfg file using 'config-url disk0:/CUST-A.cfg'

5.remove the subinterface/VLAN on the old FW under 'system' context

 

i just don't want to shutdown the multiple 'inside' subinterfaces inside the customer context since some context have 'management' interface to ISE/TACACS (for solarwinds polling/config backup) and i remembered or not sure i got locked out last time when i did this.

 

 

4 Replies 4

waldemar.jesus
Level 1
Level 1

Hi johnlloyd_13, 

Had you the opportunity to test this procedure? We have the similar need and we don't find any procedure with this scope.

We'll try to open a Cisco TAC case but before to do this you're response would be appreciate.

Thanks in advance.

yes, my steps worked just fine. i suggest to use ASDM to transfer the .cfg context config files so it's easier.

if you're pre-configuring the new context, i also suggest to 'shutdown' the interfaces. so that during the actual cutover, you can just unshut them and then do a 'no context <context>' under system in the old ASA.

Thanks a lot for your quick answer.

 

I'll share with the community the results of my experience, because i'm very surprised about the littel information about this topic there is.

 

Regards!!

i've cutover context and non-context mode ASA configs quite a lot.

it's just a confirmation in my head that i want to put it out here. unfortunately i didn't get a reply but it's alright as everyone else can find this.

i also advise to open a pro-active TAC case and ask the engineer to standby in case you need help. you get what you've paid for the smartnet

Review Cisco Networking for a $25 gift card