<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower Migration Tool - AMA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4138871#M1073177</link>
    <description>&lt;DIV&gt;&lt;STRONG&gt;This topic is a chance to clarify your questions about &lt;/STRONG&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;Firepower Migration Tool and its capabilities. Cisco Firepower Migration Tool is a free software image used for migration from Adaptive Security Appliance (ASA) 8.4 or later, Check Point (r75-r77.30 &amp;amp; r80 and later), and Palo alto Network (6.1+) to Cisco Firepower Threat Defense (FTD)&lt;/SPAN&gt;.&lt;/DIV&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;To participate in this event, please use the&lt;/STRONG&gt; &lt;IMG src="https://community.cisco.com/legacyfs/online/media/reply-button.png" alt="Join the Discussion : Cisco Ask the Expert" width="75" height="27" border="0" /&gt;button below&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;to ask your questions&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-align: center;"&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#00CCFF"&gt;Ask questions from Thursday, August 20 to Friday, August 28 2020 &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;F&lt;/STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;eatured&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;STRONG style="font-family: inherit;"&gt;&lt;STRONG style="font-family: inherit;"&gt;Expert&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;STRONG&gt;s&lt;/STRONG&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Shrinad" style="width: 90px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81517i69C27076547D0F07/image-dimensions/90x135?v=v2" width="90" height="135" role="button" title="shrinad.jpg" alt="shrinad.jpg" /&gt;&lt;/span&gt;Shrinad Trivedi&lt;/STRONG&gt; is a Consulting Engineer with Cisco’s Security team in Bangalore, India. He works with Cisco in the Network Security domain with Firewall and VPN products. He has delivered multiple trainings on handling third party migrations and firewall migration capabilities using Firepower Migration Tool. Shrinad holds a bachelor’s degree in information technology and a CCIE certification in Security (#45631).&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Aditya" style="width: 90px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81516iEAD17A92C505F60E/image-dimensions/90x135?v=v2" width="90" height="135" role="button" title="adganjoo.jpg" alt="adganjoo.jpg" /&gt;&lt;/span&gt;Aditya Ganjoo&lt;/STRONG&gt; is a Technical Marketing Engineer in Bangalore, India. He has been working with Cisco for the past nine years in security domains such as Firewall, VPN, and Authentication, Authorization, and Accounting (AAA). Aditya has delivered trainings on ASA and VPN technologies. He holds a bachelor’s degree in information technology and a CCIE certification in Security (CCIE#58938). He has been a consistent contributor on Cisco Community and has delivered multiple sessions at Cisco Live.&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;For more information, visit the &lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_self"&gt;Network Security&lt;/A&gt; category.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;Find&amp;nbsp;further events on &lt;A href="https://community.cisco.com/t5/custom/page/page-id/Events?categoryId=technology-support" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/custom/page/page-id/Events?categoryId=technology-support&lt;/A&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;Do you know you &amp;nbsp;can get answers before opening a TAC case by visiting the Cisco Community. &amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;FONT color="#FFCC00"&gt;&lt;SPAN&gt;&lt;STRONG&gt;**Helpful votes Encourage Participation! **&lt;BR /&gt;Please be sure to rate the Answers to Questions&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 20 Aug 2020 15:43:00 GMT</pubDate>
    <dc:creator>ciscomoderator</dc:creator>
    <dc:date>2020-08-20T15:43:00Z</dc:date>
    <item>
      <title>Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4138871#M1073177</link>
      <description>&lt;DIV&gt;&lt;STRONG&gt;This topic is a chance to clarify your questions about &lt;/STRONG&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, Arial, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;Firepower Migration Tool and its capabilities. Cisco Firepower Migration Tool is a free software image used for migration from Adaptive Security Appliance (ASA) 8.4 or later, Check Point (r75-r77.30 &amp;amp; r80 and later), and Palo alto Network (6.1+) to Cisco Firepower Threat Defense (FTD)&lt;/SPAN&gt;.&lt;/DIV&gt;
&lt;P style="text-align: center;"&gt;&lt;STRONG&gt;To participate in this event, please use the&lt;/STRONG&gt; &lt;IMG src="https://community.cisco.com/legacyfs/online/media/reply-button.png" alt="Join the Discussion : Cisco Ask the Expert" width="75" height="27" border="0" /&gt;button below&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;to ask your questions&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-align: center;"&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;FONT color="#00CCFF"&gt;Ask questions from Thursday, August 20 to Friday, August 28 2020 &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;STRONG&gt;F&lt;/STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;eatured&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;STRONG style="font-family: inherit;"&gt;&lt;STRONG style="font-family: inherit;"&gt;Expert&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;STRONG&gt;s&lt;/STRONG&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Shrinad" style="width: 90px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81517i69C27076547D0F07/image-dimensions/90x135?v=v2" width="90" height="135" role="button" title="shrinad.jpg" alt="shrinad.jpg" /&gt;&lt;/span&gt;Shrinad Trivedi&lt;/STRONG&gt; is a Consulting Engineer with Cisco’s Security team in Bangalore, India. He works with Cisco in the Network Security domain with Firewall and VPN products. He has delivered multiple trainings on handling third party migrations and firewall migration capabilities using Firepower Migration Tool. Shrinad holds a bachelor’s degree in information technology and a CCIE certification in Security (#45631).&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Aditya" style="width: 90px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81516iEAD17A92C505F60E/image-dimensions/90x135?v=v2" width="90" height="135" role="button" title="adganjoo.jpg" alt="adganjoo.jpg" /&gt;&lt;/span&gt;Aditya Ganjoo&lt;/STRONG&gt; is a Technical Marketing Engineer in Bangalore, India. He has been working with Cisco for the past nine years in security domains such as Firewall, VPN, and Authentication, Authorization, and Accounting (AAA). Aditya has delivered trainings on ASA and VPN technologies. He holds a bachelor’s degree in information technology and a CCIE certification in Security (CCIE#58938). He has been a consistent contributor on Cisco Community and has delivered multiple sessions at Cisco Live.&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;For more information, visit the &lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_self"&gt;Network Security&lt;/A&gt; category.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;Find&amp;nbsp;further events on &lt;A href="https://community.cisco.com/t5/custom/page/page-id/Events?categoryId=technology-support" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/custom/page/page-id/Events?categoryId=technology-support&lt;/A&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;Do you know you &amp;nbsp;can get answers before opening a TAC case by visiting the Cisco Community. &amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&lt;FONT color="#FFCC00"&gt;&lt;SPAN&gt;&lt;STRONG&gt;**Helpful votes Encourage Participation! **&lt;BR /&gt;Please be sure to rate the Answers to Questions&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 20 Aug 2020 15:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4138871#M1073177</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2020-08-20T15:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4141009#M1073314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have recently migrated from ASA to FTD(9300 SM56) and we use FMC 4600.&lt;/P&gt;&lt;P&gt;After the migration, we are now facing rule-base capacity related issues. We just have 18K odd rules. The system does not allow adding more rules. We did not have this problem while we were on ASA. The error is&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;Rule validation failed due to insufficient resources causing deployment failure. Please consider reducing the rule set...&lt;/EM&gt;" In the troubleshooting details, it shows that the process stops at "FWRuleChecker validation..." with an error "&lt;EM&gt;Failed to parse identity rules file - 153&lt;/EM&gt;".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please through some light on this? We did not have any issues during or immediately after migration but this issue cropped up after a while. Sorry, my question may not be exactly on the migration tool but related to ASA-FTD migration and hope, you'll help me in giving some direction. Where can I find the capacity limits for FTD platform and FMC appliance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks much in advance!&lt;BR /&gt;- Krishna&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 13:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4141009#M1073314</guid>
      <dc:creator>krishna.yadavalli</dc:creator>
      <dc:date>2020-08-25T13:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4141845#M1073372</link>
      <description>Hi Krishna, &lt;BR /&gt;&lt;BR /&gt;Thanks for reaching out on the Community Page. Can you please follow the steps below :&lt;BR /&gt;&lt;BR /&gt;1. Login to the FTD via the SSH session, in your case 9300 FTD device and share the output of below command. &lt;BR /&gt;2. Can you share the output of &amp;gt; show access-list | include elements&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Shrinad &lt;BR /&gt;</description>
      <pubDate>Wed, 26 Aug 2020 17:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4141845#M1073372</guid>
      <dc:creator>shritriv</dc:creator>
      <dc:date>2020-08-26T17:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142514#M1073406</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1021071"&gt;@shritriv&lt;/a&gt;&amp;nbsp;Hi Shrinad,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for my delayed response. Here is the output that you asked for:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;access-list CSM_FW_ACL_; 683042 elements; name hash: 0x4a69e3f3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So, the count of 683K should be much lesser than the 6M limit that this platform can handle?&lt;/P&gt;&lt;P&gt;What else can we check with this, please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your attention!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 15:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142514#M1073406</guid>
      <dc:creator>krishna.yadavalli</dc:creator>
      <dc:date>2020-08-27T15:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142803#M1073439</link>
      <description>&lt;P&gt;Hi Krishan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The number of ACE's on both FTD and ASA are definitely less than the supported number on this platform.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue can be due to other factors like available memory on the device etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest to open a TAC case and get this troubleshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 06:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142803#M1073439</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2020-08-28T06:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Migration Tool - AMA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142818#M1073440</link>
      <description>&lt;P&gt;Thanks Aditya. The TAC case was already there and it is not helping much. It's not going in the right direction.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The push from TAC is still to optimize the rules. While that can be done, it should not prevent new rules being added.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nevertheless, thanks for your confirmation!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 07:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-ama/m-p/4142818#M1073440</guid>
      <dc:creator>krishna.yadavalli</dc:creator>
      <dc:date>2020-08-28T07:24:16Z</dc:date>
    </item>
  </channel>
</rss>

