cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
328
Views
0
Helpful
1
Replies

Upgrade FWSM 4.0 to ASASM 9.1

DOUG DAVIDSON
Level 5
Level 5

We are getting ready to upgrade from a FWSM running 4.0x to an ASASM 9.1.5. I have run the migration tool and uploaded the config to startup and let it boot. I have seen several references to having the change access-lists to use the real IP not the NAT IP.

 

Do I have to update all of my ACLS to bring the ASASM live?

 

Would I be better off to boot the ASASM up to 8.5 and then upgrade to 9.1.5?

 

Thanks,

Doug

1 Reply 1

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

Regarding the change of the IP address in the ACL ,  it is only required on the Inbound Interface where the Static NAT's are configured.

Other ACL's are not required to be changes.

I think there would not be any major changes to the NAT configuration between the code 8.5 and 9.1.

The only major change will be with the access-list integration for IPv4 and IPv6.

You can check the release notes for all the changes:-

http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/release/notes/asarn85.html

http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/release/notes/asarn90.html

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking products for a $25 gift card