Cisco Firewall :: Zero Downtime IOS Upgrade On ASA5520

Jun 5, 2011

We are planning to upgrade IOS on a 5520 pair, from 7.2.4 to 8.2.4, and cause minimum outage. And according to the documentation, we can do the zero downtime IOS upgrade by failing over to the standby ASA and back.
 
[URL]
  
So, can during this process, can we go from 7.2.5 to 8.0.5 (last maintenance release), or do we have to move to 8.0.2 first ?

View 2 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5520 Upgrade 8.0(4) To 8.4.2 / Zero Downtime?

Mar 11, 2012

We are currently on 8.0(4) and planning on upgrading our failover pair to 8.4.2, I read some documents saying that we can perform a zero downtime upgrade.
 
According the below documents Version 8.2 supports mismatch memory failover, [URL]
 
 Upgrade Path:
 
Active Firewall:                         Standby Firewall:
   8.0(4)                                       8.0(4)-->8.2.2
   8.0(4)                                       Upgrade RAM-2G---Reload
   faiover to standby                    8.2.2
   8.0(4)--->8.2.2                          8.2.2

[code]...

Can I perform zero downtime upgrade with the above upgrade path? Will both the firewalls act as a failover pair if one is on 8.2.2 and other is on 8.4.2.
 
"Performing Zero Downtime Upgrades for Failover Pairs
 
The two units in a failover configuration should have the same major  (first number) and minor (second number) software version. However, you  do not need to maintain version parity on the units during the upgrade  process; you can have different versions on the software running on each  unit and still maintain failover support." [URL]

View 4 Replies View Related

Cisco Firewall :: Upgrade ASA 5550 Failover Pair From 8.2 To 8.4 Without Zero-downtime

Jun 28, 2011

Since the "zero-downtime upgrade" is not supported, I would like to validate the process I put together for upgrading a failover pair of asa5550 with the characteristics below. Specifically I am concerned with the role of the standby during the upgrade. This is my setup:
 
.- single context mode
.- active/standby
.- current firmware asa821-k8.bin / asdm-621.bin
.- role: firewall and VPN concentrator for segmented server farm network. Dynamic/static/exemption NAT heavily used.
 
My target is asa842-k8.bin / asdm-645.bin and I am doing a two step upgrade (8.2(1) -> 8.3(1) -> 8.4(2)) to avoid the "unidirectional" attribute and CSCtf89372 bug issues. This is a short version of what I have in mind:
 
.- Verify stability of failover pair and make adequate backups before beginning.
.- plug into the console of active, ssh into active and standby.
.- vpn/act(config)# no failover            ( disable failover from active )

[Code]....

After reboot, point to 8.4(2) and reload again.  Same concern regarding the standby unit.
 
I understand there might be configuration tweaks needed to the NAT configuration. After second reboot test connectivity and if successful, on active "failover", "write standby" and "failover reload-standby". Otherwise "downgrade" and back to the drawing board.

View 6 Replies View Related

Cisco Firewall :: Zero-downtime DRAM Upgrade Of Failover Pair Of 5510 ASAs

Apr 12, 2011

I need to upgrade the active/standby failover pair of 5510 ASA's to have1 Gig DRAM each, and I am trying to plan out the upgrade process. I'm looking for a zero downtime upgrade process.
 
I know that the failover pair has to have the same amount of memory, so how do I perform a zero-downtime upgrade process?Can I power off the standby unit and upgrade it's memory first? Or will it cause a memory mismatch between the active and standby units when it is powered on?

View 2 Replies View Related

Cisco Firewall :: Upgrade 8.2.2 On ASA5520?

Oct 3, 2011

We have 2 x ASA5520 and I upgraded this to 8.2.2 last year, I see 8.2.5 and now 8.4 is out.  If we are having no issues, is it best just to leave it as it is?  I can see a couple of features I may find useful in 8.2.5, but 8.4 seems like a huge jump and a risky one too.

View 1 Replies View Related

Cisco Firewall :: ASA5520 Upgrade 7.2 To 8.4

Jun 8, 2011

Upgraded an ASA5520 from 7.x to 8.4 in one step? Release notes for 8.4 state that you can "...upgrade from any previous release directly to 8.4..."  I've read the previous version release notes and see the various changes in NAT etc that 8.3 made.

View 3 Replies View Related

Cisco Firewall :: ASA5520 Which Is Optimal IOS To For Upgrade

Jun 10, 2013

i need upgrade two ASA5520 in failover. It´s has IOS 8.0(3) and ASDM 6.0(3).How is the correct procedure to upgrade two Firewalls?
 
Which is the optimal IOS to for upgrade and i not need make changes in config of ASA?

View 3 Replies View Related

Cisco Firewall :: Flash Upgrade ASA5520

Jan 11, 2012

I am needing to upgrade the Flash card on our current ASA from 64mb to a 1GB card to make way from upgrading from 8.0 to 8.4.  When i copy all the contents from the 64MB card through a card reader i am not getting the startup-config file copied over.  I checked to make sure that all hidden files are shown, but i am not seeing it.  I backed up the startup-config from the old 64mb card to a tftp server before switching the cards out.    Is their something that i am missing?

View 4 Replies View Related

Cisco Switching/Routing :: Zero Downtime 3750 Stack Upgrade?

Jun 10, 2011

Zero downtime 3750 stack upgrade?

View 1 Replies View Related

Cisco Switching/Routing :: Zero Downtime 3750 Stack Upgrade

Feb 3, 2009

Zero downtime 3750 stack upgrade 

View 3 Replies View Related

Cisco Switching/Routing :: Upgrade C3750-stack Without Downtime?

Sep 30, 2009

Is it possible to upgrade a c3750-stack one member at a time to avoid downtime? I need to keep L3-functionality up.
 
If I have one etherchannel from access-switch (2 channel-ports in 3750, in different stack-members), my 3750-stack as a distribution layer switch, and another etherchannel (also spread over multiple stack members) to core, can I upgrade the entire stack without traffic interruption?

View 5 Replies View Related

Cisco Firewall :: ASA5520 Configured NAT / ACL With Real IP In Existing Configuration After Upgrade

Mar 7, 2011

I am forced to upgrade my ASA 5520 software from 7.1 - 8.2 or higher, as I am not familiar with ASA I need expert opinions.I have following concerns regarding the upgrade.
 
1-Do I need to worry about the software licensing when I download 8.2

2-I read about the few difference in commands (ACL and NAT) in 8.2 what exactly I have to do here should I change the configured NAT and ACL with real IP in the existing configuration after the upgrade ?

View 5 Replies View Related

Cisco Firewall :: ASA5520 To ASA5520 Via L2L Tunnel

May 31, 2011

Our firewall expert has gone off on long term illness leave and I am trying to pick up the pieces :-(
 
We have an ASA 5520 (local office) talking to another ASA (remote office) via a VPN Tunnel.
 
My 1st problem is that I cannot ping from my inside network (local) to the outside interface of my remote ASA.
 
My 2nd is that I have debug enabled on my rules but am not logging anything.

View 1 Replies View Related

Cisco Firewall :: ASA5520 Bypass All Network Through Firewall

Dec 22, 2011

With regarding to the firewall ASA5520, i'm using it in my network, all the confiuration are properly configured and working but with the use of proxy address in internet explorer(e.:206.53.155.129/3128) all the blocked contents as easily accessible simply it bypass all the network through firewall.so will u guide me to block the proxy servers.

View 1 Replies View Related

Cisco Firewall :: Keep ASA5520 Firewall In Sync

Aug 22, 2011

I have two asa 5520 firewalls. one at my primary data center connected to our production Internet feed, and one at my fail over data center connected to a backup internet feed. I was wondering if there was an easy way to keep the firewall rules in sync between the two firewalls. We have failover with our isp that will move our public facing address block from our primary site to our dr site in the event of a disaster so the ip addresses will not change if we were to have to fail over to the DR site. currently i just have to do any changes that i make on the fail over server but would like a way to at least simi-automat this if not fully automat this so that i can eliminate the possibility of human error of a change happening at primary but never getting don at DR.

View 1 Replies View Related

Cisco Firewall :: Only One Internet IP Can Be Used In Asa5520?

Sep 25, 2011

I have a asa5520 with five Internet IP.One for the internet interface and the others are static maped to dmz hosts. It runs rightly until yesterday.Now it will lose the connection to the gateway many times everyday and the dmz hosts can not connect to internet any time. configuration(simplified):
 
!
interface GigabitEthernet0/0
nameif internet
security-level 0

[Code]....

I called ISP to check,when ISP clear their router's ARP, the asa will lose the connection at the same time and then the ISP's router couldn't learn the ASA's MAC. After I 'clear arp' manually,The ISP's router can learn the ASA's MAC and the connection recovered,but the DMZ's cann't access internet still (of course,There is no problem between DMZ and ASA ,I ping the internet gateway from DMZ host and can not get any reply.).

View 2 Replies View Related

Cisco :: Firewall ASA5520 Is Very Slow

May 8, 2011

I have one firewall ASA5520, are very slow

View 3 Replies View Related

Cisco Firewall :: Cannot Ping ASA5520 From LAN

Mar 7, 2011

I am trying to introduce an ASA5520 to my network based on the following diagram: ISP Internet ------> ASA5520 ------- > Cisco Router ------> LAN. The problem is I cannot ping the ASA from the LAN. I can ping it from  inside the router.  I already allow ICMP within ASA. If i remove the  cisco router and replace it by a swich, I can ping the ASA with NO problem.

View 5 Replies View Related

Cisco Firewall :: ASA5520 With Different CPU Type?

May 16, 2011

We want to use ASA5520 but both Firewall have different CPU. One has CPU Pentium 4 2400 MHz and another has Pentium 4 Celeron 2000 MHz. Can it be configured for replica / failover?

View 5 Replies View Related

Cisco Firewall :: LAN To LAN Between ASA5520 Version 8.3 And PIX?

Apr 19, 2011

We have 2 firewalls on PIX facing the Internet and connected to interface e1 (behind it) an ASA version 8.3 Both the PIX (Firewall facing) and the ASA are on the same subnet.
 
By using Routing statements and statics I have been able to reroute specific traffic to the ASA5520 version 8.3 Now I need to inverse the 2 devices. The ASA5520 will be facing the Internet and the PIX will be behind it.Unfortunately the ASA5520 is refusing to route the traffic to the PIX. The access-lists are open accordingly and a NAT on the ASA has been created.

View 2 Replies View Related

Cisco Firewall :: Client Uses ISP DNS Under ASA5520?

May 31, 2013

i have my router connected to ISP then my router directly connected to my ASA5520....i use also ASA5520 as my DHCP Server and i was wondering with the DHCP Server function of ASA 5520 because if i use the ASA 5520 LAN ip ...all workstation will not be able to browse anything from the internet unless i use my ISP DNS IP which they gave me?

View 3 Replies View Related

Cisco Firewall :: Using CSC SSM 6.6.1125.0 With ASA5520 8.4(4)1?

Sep 4, 2012

Get the following log message on secondary ASA console output when turning on the ASA failover function?
 
"Mate's service module (CSC SSM 6.6.1125.0) on slot 1 is different from mine (CSC SSM 6.6.1125.0)"
 
After that the secondary cannot join as a failover unit and shows in disabled status.We have the same model ASA & CSC module and each pair of them are in same firmware (CSC 6.6.1125.0 with ASA5520 8.4(4)1), when I shutdown both the csc modules, the ASA failover works fine.

View 8 Replies View Related

Cisco Firewall :: ASA5520 To Act As Web Proxy

Dec 15, 2012

I am using a squid proxy behind an ASA5520 firewall to collect the users to the internet. Squid is just necessary to log what is going on in order to find a quick solution when the internet slows down.
 
Considering that I have unlimited licenses and I would like to get rid of squid, I wonder if the ASA has some functionalities to track which websites are being used and how much traffic is generated. If there is not, I would like to know if Cisco offers a good product to replace Squid.

View 2 Replies View Related

Cisco :: ASA5520 / Two Firewall Are Unknown On LMS 4.0.1

Jul 5, 2011

My customer had 2 asa5520 version:8.0(5)20 and LMS 4.0.1.Two Firewall are "unknow" on LMS, why ?Normally, LMS manages ASA with version 7 min.

View 1 Replies View Related

Cisco Firewall :: ASA5520 VPN Support Over DSL

Jan 5, 2012

Any limits on the number of IPSec sessions an ASA5520 can support over a DSL connection?
 
Currently, as we increase the number of IPSec VPN tunnels, our LAN switches connected to the DSL/ASA start seeing CRC/input errors.   Tried different LAN ports for both DSL/ASA connections - same reults (CRCs and errors).   Swapped ASA for PC running 1 IPSEC w/HD video and no issues.
 
VPN connection bandwidth demand 50% of DSL capacity, so not exceeding DSL bandwidth.    Errors get so bad that all VPN sessions drop - sometimes VPN sessions re-establish while other instances a DSL modem reboot is required.
   
cause of LAN switch connections seeing errors with 4+ VPN sessions established on ASA across a DSL Internet circuit?

View 1 Replies View Related

Cisco Switching/Routing :: 6509 / HSRP Migration To VSS With 0 Downtime?

Mar 13, 2012

I have to migrate two Cat6K series switches in a Data center to the new Cisco 6509 Series switches with no downtime. i know there are few threads on the same topic but none of them discuss about the downtime.The two Old Cat6K series switches are working in HSRP redundant mode. All access/Dist switches are dual homed to these two switches in downlink direction. In the uplink direction a router is dual homed to both Switches. Now my requirement is to completely migrate the configuration from the old switches to the new one in VSS mode without any downtime. Already VTP server is running on of the old switches so VLAN migration is not an issue. I will update the network diagram in few hours .As per now i am going to follow these steps:
 
1. Remove active links from switch 1 and shut it down
2. Monitor network and traffic impact on switch 2
3. Install the new 6509 switch along with switch 2 (VSS config already done in Staging)
4. Config HSRP and make it standby
5. Connect all removed links back to new switch
6. Remove old switch 2 and monitor network
7. Connect new switch with VSS config
8. Connect the two new switches together in VSS and move virtual IP to SVI.
 
During last step i think i will face some minor packet drops.

View 2 Replies View Related

Cisco WAN :: 2800 - Interface Downtime In Order To Initiate DHCP

Feb 26, 2012

I'm trying to find out what is the minimum downtime for a Cisco 2800 series LAN interface configured as DHCP client, in order to initiate a new DHCP discover. How much time does it need to take for the Cisco to "sense" the phy disconnection ?

View 4 Replies View Related

Cisco Firewall :: Cut-Through Proxy Not Working With ASA5520

Jan 16, 2012

I'm trying to configure an ASA 5520 with cut-through proxy feature. The user is required to be authenticated when trying to access an outside resource from the inside. This is a test lab before it is implemented in production. [code]

View 15 Replies View Related

Cisco Firewall :: How To Enable Not Used Interfaces On ASA5520

May 12, 2011

I have a pair of brand new 5520s I am in the middle of commission.  After carving out all the DMZs etc I needed I realized that I really neede another physical NIC, not just another VLAN off a configured nic. [code]I am running 8.3(2).  How can I turn these "Not used" interfaces into useable ones?

View 2 Replies View Related

Cisco Firewall :: ASA5520 Cannot Ping Outside World

May 22, 2013

I have Cisco ASA5520 with  a 8.4 code in GNS3.  I have a problem pinging to the internet.  On the ASA console, I can ping  to outside world, but on vpc  I cannot ping the outside world.  But I can ping the ASA Inside interface and other VLANs, no problem. [code]

View 3 Replies View Related

Cisco Firewall :: Access-list On ASA5520

Feb 23, 2011

I have a question about access-lists on ASA: (5520 running 8.4)Often I want to permit all traffic from networks behind an interface (let's say DMZ in this example) to Internet, but NOT to internal networks. Then I  first configure a Deny from DMZ to all internal network and then a Permit to ANY. If I forget the first Deny I will allow all traffic also to my internal networks. Is it possible to configure an access-list that permit all traffic from a network to all networks that are reachable via a given interface? In this example: Permit all traffic from DMZ to all networks that are reachable via the Outside-interface? This should permit traffic to Internet and deny traffic to internal networks in one statement.If I specify the outside-interface as the destination only traffic to the interface itself will be allowed.

View 1 Replies View Related

Cisco Firewall :: ASA5520 Not Allowing Traceroute

Oct 31, 2011

I've got an annoying problem with my ASA 5520.I have traffic going from the inside interface (security level 100) to the outside interface (security level 0) with a global PAT applied to the outside interface address for all inside traffic - and I can't seem to traceroute through the firewall.The ruleset is simple - basically, allow any IP from inside to outside. The NAT is simple - PAT all traffic unless exempted to the IP address of the outside interface.If I do the trace from my internet edge router it works fine - so I know it's not soemthing my uplinks are filtering - but if I do it through the firewall, I get perfect responses until the hop where it hits the firewall interface - then nothing.Is there something I am missing that I need to do to allow traceroute to just work with all the rest of the traffic?

View 2 Replies View Related

Cisco Firewall :: How To Verify If CG-NMS Is Enabled On ASA5520

Apr 11, 2013

how do I verify if CG-NMS is enabled on ASA5520. I just need to know if it's enable/install to be enabled and used?Cisco Adaptive Security Appliance Software Version 8.0(5)28..Device Manager Version 6.1(5)51

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved