This document describes the best practices regarding deployment, migration, and configuration from hardware ESA/SMA to Virtual ESA/SMA.
It is recommended to have a virtual Secure Email Gateway (ESA)/Security Management Appliance (SMA) running on the same AsyncOS version as the hardware before you can migrate the configuration. You can choose the AsyncOS release closest to the version running on your appliance and upgrade it after that, if required, or download the latest version of AsyncOS.
Deployments on these platforms are supported – Microsoft Hyper-V, Keyboard/Video/Mouse (KVM), and VMWare ESXi. Check the installation guide for more details: Cisco Secure Email Virtual Gateway and Secure Email and Web Manager Virtual Appliance Installation Guide.
You can download the virtual image from the link: Software Download.
In order to be able to upgrade the virtual ESA/SMA, first you must install its licenses – you can share the existing licenses from your hardware with the new virtual ESA (both ESAs can run together).
For Traditional licenses, once the physical license has been successfully shared for the vESA/vSMA, and you received your license, open up the .XML file you received with NotePad++ or WordPad. Select all, and then copy/paste via the vESA/vSMA CLI using the loadlicense command. Refer to the link for more details: Obtain and Apply Virtual Licenses for vESA, vWSA, and vSMA.
For Smart licenses, add the new vESA/vSMA in the smart account, once the token is generated, register the devices as per the process mentioned in the article: Activate Smart Licensing and Troubleshoot on ESA/SMA/WSA.
The hardware and virtual appliance must be on the same version prior to the migration. You can check the compatibility matrix for the SMA and ESA on the link mentioned in order to upgrade the ESA to the proper version: Compatibility Matrix for Cisco Secure Email and Web Manager.
The virtual ESA/SMA can be configured in these ways:
Note: Once the virtual ESA/SMA obtains the current configuration, you can choose to disconnect the devices from the cluster or keep them as-is based on requirement. The hardware device can be removed from the cluster configuration and decommissioned.
The virtual and hardware ESA/SMA use different upgrade servers and after migrating the configuration, the server changes. In order to be able to further upgrade your vESA/vSMA, you can correct the server via the vESA/vSMA CLI with these steps:
updateconfig, and then the subcommand dynamichost.update−manifests.sco.cisco.com:443.For additional FAQs regarding migration, refer to the link: ESA/SMA Virtual Deployment FAQ.
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
05-Jun-2026
|
Updated SEO and Formatting. |
1.0 |
16-Feb-2024
|
Initial Release |