1 Apr 2010

Steps for migrating from PIX to ASA

You should be running v7.x on your PIX so that your configuration can be converted properly. Two ways of going about this:

* Tool-Assisted Conversion (Link)
* Manual Conversion

I'll covert the manual method here.
Upgrading your PIX to v7.x

1. Get copies of your config and version/license info
# show running
# write net
# show version


2a. If BIOS is earlier than 4.2, use Monitor Mode instead of copy tftp flash

Reboot and press BREAK or ESC during boot to enter Monitor Mode
monitor>interface
monitor>address
monitor>server
monitor>gateway
monitor>ping
monitor>file
monitor>tftp


PIX will automatically boot, but the software upgrade is only done in Memory, you MUST you go through the steps below to complete the upgrade!

2b. Upgrade System software

#enable
#copy tftp: flash:
Address or name of remote host []? 10.1.6.44
Source filename []? pix701.bin
Destination filename [pix701.bin]?


3. Now you have upgraded your software and your config was auto converted to v7.x
You should go through and check the changes made, which could be very different from your older pix config.

4. Use this config in your ASA appliance. Do this either with the Copy/Paste method, or via a tftp/ftp config file transfer.



Ref: Migration from PIX 500 Series Security Appliances to ASA 5500 Series Adaptive Security Appliances

No comments:

Post a Comment