Migrating pre-8.3 ASA config to 8.3+

cisco-asa

What are best practices migrating ASA config to 8.3 and forward?

I have manually created a new config file with the following changes:

  • new network objects
  • new NAT statements
  • new access-lists referencing network objects

My next steps would be to upgrade from 8.2 to 8.3 keeping note of any errors. Instead of cleaning up the config would it be easier to re-do it line by line?

Best Answer

Give a short enough config set, reconfiguring by hand should be an acceptable option. You could even take your existing config and try to implement it again via the ASDM to see what the new GUI returns.

If your config is multiple pages or has a large number of objects, it might be best to implement it on a test box to see what comes back as an error message before putting it into production.

Unlike the PIX-to-ASA migration, Cisco never released a sanity check tool.