cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
208
Views
1
Helpful
3
Replies

upgrading ASA5506 from 9.8 to 9.16

I'd like to know if you have experience with upgrading an ASA5506 from 9.8 to 9.16.

I have an s2s IPsec IKEv2 configuration with group 14 and 19. What impact will this have on IPsec?

Could you please share your experiences? 

Thank you!

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You should be OK. Only DH groups 2, 5 and 24 were deprecated (as of ASA 9.13). Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/release/notes/asarn913.html#reference_yw3_ngz_vhb

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You should be OK. Only DH groups 2, 5 and 24 were deprecated (as of ASA 9.13). Reference: https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/release/notes/asarn913.html#reference_yw3_ngz_vhb

balaji.bandi
Hall of Fame
Hall of Fame

before upgrading - make sure check other end can support same DH methods, some legacy system still need DH 5, this what i have encountered the issue.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you for your answer.

The other thing that worries me is that Cisco recommends generating higher-security keys as soon as possible using the crypto key generate {eddsa | ecdsa} command.

Review Cisco Networking for a $25 gift card