cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
12
Helpful
6
Replies

Migration: Pix 515 to ASA 5520

rcoote5902_2
Level 2
Level 2

We've had some issues using the pix migration tool to get our current config over to our new ASA. Are there any general recommendations out there for doing a conversion from a PIX to an ASA?

Thanks!

6 Replies 6

eddie.mitchell
Level 3
Level 3

There is plenty of great documentation on this process. Have you read through all of the following information?

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808554ed.shtml

What specific issues are you having with the migration tool?

Thanks for the link I believe we had referenced that somewhat but I'll dig into it more thoroughly.

We had our configs matched up as far as we could tell but when we tried to cutover we had no outside access. Same port, same address, same cable even...able to ping inside from the ASA management port, but couldn't get any outside addresses.

Did you bother to reboot your outside gateway I.E. upstream router?

Your mac address changed when you went to the ASA from the PIX and you have the same ip....

Bet that works.

-C

Yes, we actually brought all of our equipment offline for the cutover and restarted everything in stages.

I've found the pix to asa conversion tool does some wierd things with the config, particularly in the order of commands. It placed all of my nat entries before the actual nat command, so they all return as invalid. I'm massaging the output now so it's in the correct order and will see what happens.

I'm doing this all through the CLI as I have read mixed reviewes of the ASDM - which is better?

I actually really like ASDM especially newer versions like 6.x..

Only issue I ever run into is sometimes the log freezes but I am a huge fan.

If you want you can share the config and I can take a peek at it..

Really pix to ASA should be almost as simple as cut and paste depending on the features you are using on the PIX.. Obviously if your using an old version conduits and outbounds don't work but ACL's should eb fine..

-C

Much appreciated. I'm still 'massaging' the output from the OCC and migration tool. I'm not sure when we'll have a chance to test again, since downtime here is a rare commodity.

If this run doesn't work I'll definitely post some configs for some further input.

Review Cisco Networking for a $25 gift card