Monday, September 23, 2019

Cisco ASA upgrades for the uninitiated

Hey r/networking, I’m more traditionally a systems guy, so forgive me if this is a basic question.

I have a 5508-x running on 9.6(4)-34. I recently upgraded it from an older release of 9.6(4) due to a dos bug (not the 213 days one).

Anyway, to play it safe I stuck in the 9.6(4) family and just updated to the latest. However, in the interest of not letting the system get too far behind, I thought it might be time to research going to one of the latest builds, 9.8? 9.9? However, trying to read through Cisco’s website is kind of a pain for the uninitiated, I was wondering:

  1. Is there a quick and easy place to find change notes for the mere mortals? (Example of something for SQL Server: https://sqlserverbuilds.blogspot.com/?m=1)

  2. Anyone have any advice, should I go straight to the latest? We’re not doing much, we have a handful of IPsec tunnels, Remote access, normal firewall inspection, and only one open port for an external facing service. The only thing I could find that stood out to me was the addition of VTIs in one of the releases. 95% of my tunnels are IKEv1, but I’ve got one up to Azure that is ikev2.

  3. What’s the general relationship with ASDM, AnyConnect and the ASA version? I see in the matrix that my particular version has shows to be compatible with ASDM 7.9+, does that really mean on up (to 7.12, etc), or just within the 7.9 family? Same with AnyConnect, have there been strict requirements that the version match the ASA software?



No comments:

Post a Comment