cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
21471
Views
10
Helpful
8
Replies

Wipe out an ASA

johnlloyd_13
Level 9
Level 9

hi all,

just a quick one. what's the 'best' and practical way of resetting an ASA?

this is to help me configure the box from scratch.

is it by using the write erase or config factory-default command?

can elaborate between the two and which is more commonly used?

1 Accepted Solution

Accepted Solutions

Puneesh Chhabra
Cisco Employee
Cisco Employee

Write erase and reload will erase everything on the ASA

Factory-default will leave the ASA with some default ip addresses and dhcp, you can also configure your own ip address to inside interface in the factory-default command.

 

Check this link:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/start.html#wp1053752

 

We mostly use write erase when configuring ASA from the scratch.

 

Regards,

Puneesh

Please do not forget to rate helpful posts

View solution in original post

8 Replies 8

Puneesh Chhabra
Cisco Employee
Cisco Employee

Write erase and reload will erase everything on the ASA

Factory-default will leave the ASA with some default ip addresses and dhcp, you can also configure your own ip address to inside interface in the factory-default command.

 

Check this link:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/start.html#wp1053752

 

We mostly use write erase when configuring ASA from the scratch.

 

Regards,

Puneesh

Please do not forget to rate helpful posts

Hi Punesh,

 

What about the licenses, i want to completely reset my ASA but will see delete the licenses, i have digital certs as well on it.

 

Please advice

Correct, it will include those as well

Please remember to rate useful posts, by clicking on the stars below.

Thanks Dennis, i performed the command and certs are deleted.
License remained.
Many thanks for your help.

Which command did you use?

Hi can you confirm which command you used which didn't delete the licenses? 

What causes the policy-map global_policy with default inspection to be missing from the config file? A write erase and reload is restoring the missing global policy or configure factory default but why it is missing in some cases when as ASA is rebooted. 

I appreciate any feedback. 

Thanks, 

I've seen it happen as a result of a bug on an FTD device. Re-entering the commands (could do it from cli config mode on ASA, have to use Flexconfig in FMC for FTD) restores them.

Review Cisco Networking for a $25 gift card