10-17-2007 11:30 AM - edited 03-11-2019 04:26 AM
How can I migrate from a pix firewall to a ASA firewall using the same DMZ. doing this so there will be no changes to the ip's in the DMZ. I have tried to NAT the inbound DMZ of the ASA which gives the ASA's IP addres to internal DMZ servers. Works as long as there is not a load balancer which we use. Anything behind the load balancer will send reply https packets to the ASA, but the ASA will drop them.
10-17-2007 03:35 PM
Your question isn't very clear. Are you doing a drop in replacement of a PIX with an ASA? If so that should be pretty simple given that you've duplicated the configuration on the old PIX to the ASA. If you're trying to do something like run both firewalls at the same time, then that's going to get complicated real quick.
10-18-2007 04:44 AM
Yes we are trying to run both at the same time. An easier idea would be to put multiple NICs in the DMZ servers and run two seperate DMZ'z. Not an option as I have walked into the situation. Company wants to test and slowly migrate to the new ASA firewall. Any ideas??
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide