Cisco ASA 5510 Firewall Logo
Posted on Jan 29, 2010
Answered by a Fixya Expert

Trustworthy Expert Solutions

At Fixya.com, our trusted experts are meticulously vetted and possess extensive experience in their respective fields. Backed by a community of knowledgeable professionals, our platform ensures that the solutions provided are thoroughly researched and validated.

View Our Top Experts

Replacing a PIX 515E with an ASA 5510

On the PIX, I have E0=inside E1=outside E2=dmz. I have already ordered the ASA. Actually two of them for redundancy. My question to day is, can you guys help me with the config transfer and a plan of attack?


Thanks

2 Answers

Anonymous

Level 1:

An expert who has achieved level 1.

New Friend:

An expert that has 1 follower.

Mayor:

An expert whose answer got voted for 2 times.

  • Contributor 3 Answers
  • Posted on Feb 15, 2010
Anonymous
Contributor
Level 1:

An expert who has achieved level 1.

New Friend:

An expert that has 1 follower.

Mayor:

An expert whose answer got voted for 2 times.

Joined: Feb 15, 2010
Answers
3
Questions
0
Helped
8382
Points
5

Best way to migrate is to take the configuration of the old PIX and TFTP it to a PC or other server for safe keeping.

Then boot up the ASA in a lab environment and TFTP the configuration to the new unit and reboot. There will be some commands that don't translate correctly, but you can compare the configurations to each other to make sure all the access lists and NAT statements get transferred across.

Keep in mind that the PIX and the ASA name their interfaces differently, so there may be errors when you transfer the configuration. You can edit the configuration offline with something like Notepad and change the names of the interfaces to have it work.

Good luck!

Beerm0nster

Level 2:

An expert who has achieved level 2 by getting 100 points

MVP:

An expert that got 5 achievements.

Sniper:

An expert who has posted more than 50 answers, of which 90% or more were rated as helpful.

Governor:

An expert whose answer got voted for 20 times.

  • Expert 82 Answers
  • Posted on Jan 29, 2010
Beerm0nster
Expert
Level 2:

An expert who has achieved level 2 by getting 100 points

MVP:

An expert that got 5 achievements.

Sniper:

An expert who has posted more than 50 answers, of which 90% or more were rated as helpful.

Governor:

An expert whose answer got voted for 20 times.

Joined: Jan 17, 2010
Answers
82
Questions
0
Helped
81452
Points
230

Hi,

The ASA config guide is here http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/config.html

Generally the config can be moved across fairly easily. I would suggest that you get your ASA powered up in the lab / on a desk and apply a modified version of the original PIX one. This will allow you to check out functionality without putting your live traffic at risk. When you feel confident that the ASA now replicates the PIX functionality then you can schedule an out of hours change window to bring the ASA into service

If this helps please leave feedback, if not let me know and I will try to help some more!

Ad

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

0helpful
1answer

RF365PXKW shows error code F5E1

Whirlpool-KitchenAid-Roper Appliances: Oven Fault Codes:
>>Exception Note:<<
Chart below does not apply to Whirlpool Models using the "Y" line in the products model numbers. Applies to models using 4 digit displays only.

F0-E0 Analog to Digital failure
Disconnect panel for 30 seconds
Should the above error re-appear, replacement of the control is required.
F1-E1 Defective ERC Replace ERC
F2-E0 Shorted Keypad Replace Keypad
F3-E0 Sensor or Sensor Fuse Open Replace Sensor or Fuse
F3-E1 Shorted wire or Sensor locate short and correct it or replace Sensor
F3-E2 Oven over heat Replace Sensor
F3-E3 Cleaning Temp over heat Replace Sensor
F5-E0 Door Error Check Door
F5-E1 Door Latch Check Latch
F5-E2 Door Switch Check Switch
0helpful
2answers

Kitchen aid wall oven Model YKEBS2780B1 SHOWS

Hello,4 Digit Failure Code F0 - E0 Analog to Digital Failure Disconnect for 30 seconds - if display re-appears - replace control F1 - E1 Safety flip flop Replace Electronic Range Control/Clock(ERC) F2 - E0 Shorted keypad Replace Electronic Range Control/Clock(ERC) F3 - E0 Oven temperature sensor or oven temperature sensor fuse opened Replace oven temperature sensor or fuse F3 - E1 Oven temperature sensor shorted Replace oven temperature sensor F3 - E2 Oven too hot Replace oven temperature sensor F3 - E3 Clean temp too hot Replace oven temperature sensor F5 - E0 F5 - E1 and E2 Check door/latch switch Replace component 2 Digit Failure Code F0 or F1 or F5 Failed transistor Replace Electronic Range Control/Clock(ERC) F2 - E0 Oven temp too high 1. Test operation of door lock on self-clean models
2. Test relay contact operation
3. High resistance in oven temperature sensor F3

Thanks
May 26, 2010 • Ovens
0helpful
1answer

How to configure MAC access list at PIX 515

The PIX is a layer 3 device, I cant say that I have ever tried to filter a mac address. I'm pretty sure you cant
2helpful
1answer

I want to block an outside IP-address and some sites on PIX 515E

Assuming you are running the latest version.
Short answer:
# access-list acl-outside line 1 deny ip IPYOUWANTTOBLOCK 255.255.255.255 any # write memory
The link below contains a longer helpful explanation: http://www.velocityreviews.com/forums/t35733-how-to-block-external-ip-address-on-pix-515e.html
I hope this helps.
0helpful
1answer

Cisco pix 515 workstations cant get outside pix can

You have to create a route statement to allow workstations to get online.

Below is the command:
route interface_name ip_address netmask gateway_ip

Example:
route outside 0.0.0.0 0.0.0.0 200.200.200.1
or
route outside 0 0 200.200.200.1

When there is already a route statement but still cannot get online, check the DNS settings.
0helpful
3answers

New cisco asa 5510 setup

connect your laptop to the asa5510 using a cross over cable
0helpful
1answer

Cisco ASA 5505 Firewall

1. Change your PCs default gateway to your firewalls' internal IP

2. configure the nameservers on your ASA

Then internet will work fine.
0helpful
1answer

Pix 515E inside to outside translation problem

Dear Kiran,

What is the name assigned for isp 1 as well as isp2.

for your reference kindly find the sample configuration......
ISP 1:
interface ethernet 0 100 full
nameif outside security-lvl 0
ip address outside 203.193.129.132 255.255.255.240.
nat (inisde) 1 (local network)
global (outside) 1 203.193.129.133
route outside 0 0 203.193.129.129.1.

regards,
mani.S

0helpful
1answer

ASA 5510 sec - bun k9

Basic Commands pixfirewall(config)#hostname PIX !--- Naming the PIX is optional. PIX(config)#nameif ethernet2 fo security20 !--- Naming the interface is optional. It is recommended that you !--- hardcode the speed/duplex. PIX(config)#interface ethernet2 100full !--- Bring up the interface. PIX(config)#ip address fo 192.168.1.1 255.255.255.0 !--- Assign an IP address. Failover Commands PIX(config)#failover ip address fo 192.168.1.2 !--- IP address for the failover link. PIX(config)#failover lan unit primary !--- This unit is primary . PIX(config)#failover lan interface fo !--- The 'fo' interface is used for LAN failover. PIX(config)#failover lan key cisco !--- The Pre-shared key. PIX(config)#failover lan enable !--- Enables failover. PIX(config)#failover !--- Start the failover process. This message appears on the console:
LAN-based Failover: trying to contact peer failover_01.gifLAN-based Failover: Send hello msg and start failover monitoring
0helpful
2answers

Whirlpool RF196LX Smooth Top Range

4 Digit Failure Code F1 - E1 Safety flip flop Replace board F2 - E0 Shorted keypad Replace keypad F3 - E0 Oven temperature sensor opened Replace oven temperature sensor F3 - E1 Oven temperature sensor shorted Replace oven temperature sensor F3 - E2 Oven too hot Replace oven temperature sensor F3 - E3 Clean temp too hot Replace oven temperature sensor F5 - E0 F5 - E1 and E2 Check door/latch switch Replace switch if defective
Not finding what you are looking for?

541 views

Ask a Question

Usually answered in minutes!

Top Cisco Computers & Internet Experts

Brad Brown

Level 3 Expert

19187 Answers

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

Sean Wright
Sean Wright

Level 3 Expert

2045 Answers

Are you a Cisco Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...