<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower_Migration_Tool | Crypto S2S on FTD | ACL configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4163261#M1074513</link>
    <description>&lt;P&gt;Yes, you would build the new VPN topologies, add the SRC (your local networks) and DST (the remote networks) - this defines the interesting traffic to be encrypted over the VPN tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the configuration of your existing VPN Filter on the ASA would need to be re-writing within the ACP applied to the FTD&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 07:28:38 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-10-08T07:28:38Z</dc:date>
    <item>
      <title>Firepower_Migration_Tool | Crypto S2S on FTD | ACL configuration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4162885#M1074497</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question-1&lt;/STRONG&gt;&amp;nbsp;i migrated my 5516-x to FTD: 1140 and I had about 87 S2S tunnels, but none of them migrated by Tools.&lt;BR /&gt;so, please confirm I should follow instructions in cisco and configure Manually right?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question 2&lt;/STRONG&gt;: in the ASA configuration,&lt;STRONG&gt; First&lt;/STRONG&gt;: I have 2 ACL type: 1 under Crypto command like :&lt;BR /&gt;crypto map ipsec_outside 50 match address ipsec_TUNNEL1 ( which is the network I want to protect )&lt;BR /&gt;&lt;STRONG&gt;Second&lt;/STRONG&gt;: I have ACL under Group-Policy ( VPN Filter) Configuration: like :&lt;BR /&gt;group-policy policy_toyota-bank attributes&lt;BR /&gt;VPN-filter value acl_toyota-bank&lt;BR /&gt;(to restrict Port number accessibility from the remote side)&lt;/P&gt;&lt;P&gt;I know that I should write Extended ACLs under Object management&amp;gt; Extended ACL first, and use it for VPN configuration on FMC in Node (B) section.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;but the question is:&lt;/STRONG&gt; how should I use &lt;U&gt;BOTH ACLs&lt;/U&gt; under site-2-site communication? is that possible to combine it? ( we have no command of ''tunnel-group X.X.X.X general-attributes'' to bind ACL like Vpn-Filter in ASA)!&lt;BR /&gt;should I use Flex-config or I can write Extended ACL (a combination of 2 ACLs above) and assign it under Node-B network protection?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Respectfully yours,&lt;BR /&gt;Ashkan&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 14:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4162885#M1074497</guid>
      <dc:creator>najarian</dc:creator>
      <dc:date>2020-10-07T14:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower_Migration_Tool | Crypto S2S on FTD | ACL configuration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4162891#M1074498</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/989127"&gt;@najarian&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct, I don't believe the FMT currently migrates VPN tunnels, so unfortunately you'd have to migrate manually.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On FTD you would configure firewall rules in the ACP (Access Control Policy) to determine which traffic should or should not be permitted over the VPN tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 15:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4162891#M1074498</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-07T15:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower_Migration_Tool | Crypto S2S on FTD | ACL configuration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4163253#M1074511</link>
      <description>&lt;P&gt;Hello Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as i understand, i should just add SRC/DST networks in the NODEs information section in S2S configuration on FMC and i should migrate ''VPN-Filter ACLs on ASA '' in the&amp;nbsp;&lt;SPAN&gt;(Access Control Policy). would you please confirm?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ashkan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 07:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4163253#M1074511</guid>
      <dc:creator>najarian</dc:creator>
      <dc:date>2020-10-08T07:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower_Migration_Tool | Crypto S2S on FTD | ACL configuration</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4163261#M1074513</link>
      <description>&lt;P&gt;Yes, you would build the new VPN topologies, add the SRC (your local networks) and DST (the remote networks) - this defines the interesting traffic to be encrypted over the VPN tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, the configuration of your existing VPN Filter on the ASA would need to be re-writing within the ACP applied to the FTD&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 07:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-crypto-s2s-on-ftd-acl-configuration/m-p/4163261#M1074513</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-08T07:28:38Z</dc:date>
    </item>
  </channel>
</rss>

