<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA to FTD migration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125801#M561931</link>
    <description>&lt;P&gt;if that does not add an inspection policy just like any other ACP (in aka ACL).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is traffic flow ( in case if you did not come across)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80202i443859AB94608AF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jul 2020 23:03:22 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-07-26T23:03:22Z</dc:date>
    <item>
      <title>ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4121448#M561789</link>
      <description>&lt;P&gt;I want to convert ASA configuration to Firepower as prefilter rules instead of ACEs. I do not see any option in the migration tool to do so.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 00:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4121448#M561789</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2020-07-20T00:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4121618#M561794</link>
      <description>&lt;P&gt;I do not believe you have that option, you need to make some of the requirement manually and test it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since its only feature available ASA to FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 07:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4121618#M561794</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-20T07:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125779#M561929</link>
      <description>i think there was an option in older versions of FMT. btw, what kind of traffic should be in prefilter ? i understand that is traffic that do not need further inspection. e.g I have a few hundred rules that are from ANY source to VIPs of loadbalancer which hosts various services/appications. Where would you put that traffic ?</description>
      <pubDate>Sun, 26 Jul 2020 20:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125779#M561929</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2020-07-26T20:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125801#M561931</link>
      <description>&lt;P&gt;if that does not add an inspection policy just like any other ACP (in aka ACL).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is traffic flow ( in case if you did not come across)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80202i443859AB94608AF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2020 23:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125801#M561931</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-26T23:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125841#M561933</link>
      <description>&lt;P&gt;I believe the old tool which required using an intermediate FMC instance had the option to select a prefilter policy. The current FMT does not.&lt;/P&gt;
&lt;P&gt;Generally we use prefilter for traffic which is either a. explicitly trusted or b. does not lend itself to IPS inspection (e.g. encrypted traffic flowing through the appliance that does not require even the basic Security Intelligence (SI) scrub). I tend to put only things in the first category in prefilter since the SI action adds value even if you aren't able to inspect the unencrypted traffic.&lt;/P&gt;
&lt;P&gt;FYI 6.7 will allow us to copy (or cut and paste) rules from an ACP into a prefilter policy.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 02:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4125841#M561933</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-27T02:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4131297#M562146</link>
      <description>&lt;P&gt;I have migrated the rules manually now. Have some more basic questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. In ASA lower security level traffic is automatically denied to higher security level and higher to lower is allowed. How can i replicate this after migrating to firepower ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. All my access policies are migrated with source zone and without any destination zone. Is destination zone necessary or optional? what happen to traffic without a destination zone ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Have we any dates for&amp;nbsp;&lt;SPAN&gt;6.7 ? There are many rules&amp;nbsp; that can reside in prefilter policy. If i set them as "&lt;/SPAN&gt;&lt;SPAN&gt;trust" instead of allow will it help ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. How can i estimate that would there be any performance issued with the number of rules i have configured ? running FTD 4115 in HA with 6.6. Five contexts were migrated from ASA with total approx 3000 rules.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 08:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4131297#M562146</guid>
      <dc:creator>mateens</dc:creator>
      <dc:date>2020-08-06T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to FTD migration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4131324#M562148</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Q1. You can't replicate that in FTD. All interfaces have the same security&lt;BR /&gt;level which can't be changed. The concept of FTD is to use zones and&lt;BR /&gt;explicit rules to allow/deny. All interfaces within the same zone are&lt;BR /&gt;implicitly allowed to communicate. For different zones, the default action&lt;BR /&gt;is as per you ACP.&lt;BR /&gt;&lt;BR /&gt;Q2. The need of the destination zone is subject to your policy. Just check&lt;BR /&gt;the use case if it's needed or not.&lt;BR /&gt;&lt;BR /&gt;Q3. No idea about dates you can check that with your cisco AM. Trust and&lt;BR /&gt;allow are different. In prefilter trust will be processed by LINA (ASA&lt;BR /&gt;engine) without snort. Allow will pass the traffic to be examined against&lt;BR /&gt;ACP, snort, SI, etc.&lt;BR /&gt;&lt;BR /&gt;Q4. 3000 rules are very low. I have used FPR1140 with 52k rules without&lt;BR /&gt;issues. The number of rules impacts the memory and can be verified using *show&lt;BR /&gt;memory detail*. Check the system free memory from the 1st section. The cpu&lt;BR /&gt;can be verified from *show cpu* and is impacted by connection per second.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Aug 2020 09:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-to-ftd-migration/m-p/4131324#M562148</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-08-06T09:31:05Z</dc:date>
    </item>
  </channel>
</rss>

