01-12-2017 11:09 AM - edited 03-05-2019 07:49 AM
I'm trying to backup config from ASA 5505 that is currently connected to the network and restore it on a backup ASA 5505 which is not connected to the network yet.
Is there a way to backup the entire configuration including Access and NAT rules, policies, etc and restore it on the backup ASA 5505? Or do I have to just manually update the rules?
01-12-2017 12:16 PM
It depends on your configuration ...
The easiest way is to backup the full ASA from Tools -> Backup in ASDM and restore it on the other ASA.
01-12-2017 12:29 PM
I tried that. But unfortunately, the Access rules and NAT rules don't show up.
01-12-2017 12:34 PM
It really should work that way. How do you restore and is there a failure or success messages after restore?
01-12-2017 12:36 PM
Success messages:
-----------------
Running-configuration available
Translation-table configuration available
Customization configuration available
Failure messages:
-----------------
No plug-in entries / configurations available
No url-list entries / configurations available
No webcontent entries / configurations available
No DAP entries / configurations available
No CSD image entries / configurations available
No SVC entries / configurations available
No APCF entries / configurations available
No certificates available
No Proxy PAC entries / configurations available
No CSD config entries / configurations available
01-12-2017 12:41 PM
Sorry, these are the messages I get when I backup.
01-12-2017 12:48 PM
Hello,
on a side note, 'copy run tftp' would back the config up to a TFTP server. Is that an option ?
Or 'write net', although that is an older command as far as I remember...
01-12-2017 02:14 PM
Would it be possible for you to provide more information regarding the copy run tftp process? I downloaded a solarwinds tftp server. But need some directions after that.
01-12-2017 02:24 PM
Hello,
basically, you specify the IP address of the TFTP server, e.g.:
ciscoasa#copy run tftp:
Source filename [running-config]?
Address or name of remote host []?
I am not if 'write net' still works, but the syntax is the same. Check this document for an example:
http://www.petenetlive.com/KB/Article/0000076
01-12-2017 02:29 PM
Is the IP address of tftp server the same as the IP of the PC that I'm using to connect to the router via console?
01-12-2017 02:34 PM
Hello,
the TFTP server needs to be a device that you can reach by its IP address. I don't think you can ping the PC from the ASA through the console port, so connect it to one of the Ethernet ports.
01-12-2017 02:51 PM
Thanks. I was able to back up configuration using tftp as a config.cfg file.
How do I restore this file on to the new asa 5505?
01-12-2017 03:06 PM
You pretty much do the reverse, e.g.:
ciscoasa#copy tftp start
Address or name of remote host []? 192.168.1.1
Source filename []? config.cfg
01-12-2017 03:23 PM
Tried that. Everything went successfully but still access and nat rules are missing on the new asa 5505 :(
01-13-2017 01:02 AM
Hello,
weird indeed. There are also ways to do this via HTTP/HTTPS/SCP:
https://supportforums.cisco.com/document/97966/asa-how-download-images-using-tftp-ftp-http-https-and-scp
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide