cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

593
Views
0
Helpful
2
Replies
Highlighted
Beginner

Replacing a ASA 55x0 with another 55x0

I am about to replace a ASA 5510 with a ASA 5520.

This ASA is configured for a variety of functions between firewall and SSL VPN.

Am I able to simply to do a show start on the original and save that off and then paste that back into the replacement ASA?

I do not have any PSKs to my knowledge on the ASA.

I am concerned that configuration and especially certificates would be lost.

Cheers

2 REPLIES 2
Highlighted
Cisco Employee

If you don't have pre-share keys, then yes, or even better if you have pre-share key, you can grab the output of "more system:running" and it will show you the actual pre-share key instead of *

But certificate, definitely can't be just copy and paste from old to new ASA.

Are you using self signed certificate or third party certificate?

Highlighted

Hi,

Both units support the same configuration so you can copy/paste the configuration from 5510 into 5520.

There are some things you need to check for example the ASA 5510 supports either a basic or security plus license which enables the use of Gigabit interfaces on the appliance (instead of 10/100 interfaces with base license).

When you copy/paste the config, you might need to convert FastEthernet to GigaEthernet interfaces (depending on the license).

Both units are basically the same with the difference of capacity for handling connections, VPN tunnels, throughout, etc.

Sensitive things like certificates might be another issue or passwords that will not show under the configuration because the ASA encrypts that information (if you do have that information is just a matter of re-adding the correct values to the new ASA).

Hope it helps.


Federico.

Content for Community-Ad