The ASA 5500-X Series was redesigned to address higher performance requirements and increase flexibility when adding new services while maintaining the compact 1-RU form factor. Customers migrating from ASA 5500 Series platforms need to consider these changes at the time of migration to the newer hardware. In this article it describes the best practices to follow while migrating to the new ASA 5500-X Series midrange appliances.

Migrating from Cisco ASA 5500 to ASA 5500-X Series

The Cisco ASA 5500 Series midrange appliance portfolio comprises four security appliances (ASA 5510, ASA 5520, ASA 5540, and ASA 5550). In March 2012, Cisco added five new midrange appliances to the ASA family. The new appliances carry the `-X’ suffix to distinguish them and are named as follows: ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, ASA 5555-X. Cisco ASA 5500-X Series delivers next-generation security services.

The Cisco ASA 5500-X Series is designed to support next-generation security services while meeting the higher performance requirements of today’s networks. It is based on a multicore, 64-bit architecture and uses separate dedicated multicore chipsets for crypto and pattern matching operations. Hardware and software changes have been introduced without sacrificing the compact form factor.

Cisco ASA 5500-X Series Hardware Migration Path

The Cisco ASA 5500 Series portfolio comprises four platforms that are based on a single-CPU, 32-bit architecture. Due to architectural limitations, they are not capable of supporting next-generation security services. The table lists the suggested hardware migration path to the ASA 5500-X Series. Suggested sizing approach is a conservative estimate.

Hardware Migration Path from ASA 5500 Series to ASA 5500-X Series

ASA 5500 Series Appliance

Equivalent ASA 5500-X Series Appliance
ASA 5510 ASA 5512-X
ASA 5510 with SecPlus License ASA 5515-X or ASA 5512-X with SecPlus License
ASA 5520 ASA 5525-X
ASA 5540 ASA 5545-X
ASA 5550 ASA 5555-X

Cisco ASA 5500-X Series Software Migration Path

Software support for the Cisco ASA 5500-X Series is available in ASA Software Release 8.6 and later. Earlier ASA Software releases will fail to load on the new appliances.

Planning for a Successful Migration

To ease the migration process, the following pre-migration checks should be performed to meet the minimum hardware and software requirements.

• Licenses do not migrate automatically. All required licenses should be acquired and applied to the new appliance before starting the migration process.

ASA 5500-X Series appliances requires ASA Software Release 8.6 or later. They do not support earlier software versions. The new appliance should be loaded with the latest ASA Software release available on Cisco.com.

• Upgrade ASA Software on existing 5500 Series appliances to ASA Software Release 8.4. With this upgrade, configuration will be updated to reflect licensing, NAT, and real IP address migration of ACL enhancements introduced in ASA Software Release 8.3.If ASA 5500 is running a pre-8.4 release, the preferred way is to upgrade iteratively over major revisions e.g., if the appliance is running ASA Software Release 7.2, then do following transitions: 7.2 to 7.4 to 8.0 to 8.2 to 8.4. With this approach, deprecated features are taken care of automatically during upgrades.

• Back up the configuration from the existing ASA 5500 Series appliance on a remote machine. This can be done using the CLI `copy’ command or using Cisco Adaptive Security Device Manager (ASDM).

• If the IPS Security Services Module (SSM) is present, back up the IPS configuration using IDM/IME or the CLI.

• During configuration backup, make sure to export certificates and keys from the old platform for reuse.

Feature License Migration

Cisco ASA feature licenses are linked to the hardware serial number. License information is not included in the configuration; as a result, licenses do not migrate when a configuration is moved from an older appliance to a newer one. All requisite licenses currently in use on an older ASA 5500 Series appliance should be acquired for the new ASA 5500-X Series appliance before proceeding with the migration process.

Cisco ASA Software Requirements for Migration

All new midrange ASA 5500-X Series appliances require ASA Software Release 8.6 or later. Earlier versions (ASA 5500 Series: 5510, 5520, 5540, and 5550) are unsupported and will not load on the new platforms.

Minimum Software Requirements for Migration from ASA 5500 to ASA 5500-X Appliances

ASA Appliance Minimum Software Version Notes
ASA 5500 Series (5510, 5520, 5540, and 5550) ASA Software Release 8.4.2 Release 8.6 is not supported on these platforms.
ASA 5500-X Series (5512-X, 5515-X, 5525-X, 5545-X, and 5555-X) ASA Software Release 8.6  

ASA 5500 Series appliances should be upgraded to ASA Software Release 8.4.2 before attempting migration to the ASA 5500-X Series. Upgrade steps are explained in detail at http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html.

Offline upgrade of ASA 5500 Series appliances to ASA Software Release 8.4 is possible using an internal migration tool hosted at http://gypsy.cisco.com/migration.html. More information on this tool is provided in the next section.

More info of migrating from Cisco ASA 5500 Series to ASA 5500-X Series Midrange Appliances

You can visit: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5709/ps6120/guide_c07-727453.html

