Monday 28 November 2016

replacing an ASA steps

Before switching to get an idea of numbers you should see after switching, get a screenshot of the following:
sh conn count
sh xlate count
sh crypto map sa
Identify important VPNs
Get VPN PSKs with more system:running-config
Check for any certificates installed on ASA (they cannot be copied, must be added again)
Do full backup in ASDM make sure you have your configs.


Switch over cables
First thing make sure you have internet access
Make sure interfaces have been "no shut"
Often you have to unplug and re-plug cables on ISP devices to resolve arp cache issues
Ping out all interfaces to ensure all VLANs etc are working
Once we have that look at VPNs make sure they are up
You might need to generate some traffic to bring it up.
Check anyconnect from outside is working
Check ASDM / anyconnect image
Re-install certificates


No comments:

Post a Comment