<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD interface reconfiguration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267557#M1077067</link>
    <description>&lt;P&gt;I may be not done, the Migration tool does not give the ability to make complete topology change. this tool simple ACL rule conversation based on exiting to new.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this is not a big rule base I do it manually and now you got a chance to get rid of old rules which redundant moving forward with the new setuo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2021 05:34:32 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-01-06T05:34:32Z</dc:date>
    <item>
      <title>FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4266752#M1077006</link>
      <description>&lt;P&gt;Hi team!&lt;/P&gt;&lt;P&gt;I have ASA5515-x and FTD2100. I'm willing to migrate from ASA to FTD so i used Firepower Migration Tool. ASA has one physical interface for each zone, but on FTD i want to create etherchannel for each zone for redundancy. Is it possible to move configuration from physical interface to port-channel somehow?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 00:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4266752#M1077006</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2021-01-05T00:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4266968#M1077013</link>
      <description>&lt;P&gt;Then you can not use 100% migration tool, you can do offline that changes and required testing also before you make live.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 12:24:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4266968#M1077013</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-05T12:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267447#M1077058</link>
      <description>&lt;P&gt;I've deleted device from FMC and added it again without any configuration. After that manually created Port-Channels and subinterfaces on them. Firepower Migration Tool can see and map ASA interfaces on Port-Channels but not on subinterfaces.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interfaces.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/100962i841EB5C931936523/image-size/large?v=v2&amp;amp;px=999" role="button" title="Interfaces.PNG" alt="Interfaces.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMT.png" style="width: 988px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/100964i85B87DC02C6ADAB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMT.png" alt="FMT.png" /&gt;&lt;/span&gt;Why? What's the limitation for subinterfaces? In documentation&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-CP/CP2FTD-with-FP-Migration-Tool/CP2FTD-with-FP-Migration-Tool_chapter_010.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-CP/CP2FTD-with-FP-Migration-Tool/CP2FTD-with-FP-Migration-Tool_chapter_010.html&lt;/A&gt;&amp;nbsp;there is nothing about it, just - "&lt;SPAN&gt;Subinterfaces are not created by the Firepower Migration Tool. Only interface mapping is allowed between physical interfaces, port channel, or subinterfaces"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also tried to change ASA configuration manually in notepad - move interface configuration to subinterface like that&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;interface GigabitEthernet0/0
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/0.1
 vlan 1
 nameif outside
 security-level 0
 ip address 1.1.1.1 255.255.255.248 standby 1.1.1.2&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;But FMT doesn't see subinterfaces in that file as well&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 23:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267447#M1077058</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2021-01-05T23:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267557#M1077067</link>
      <description>&lt;P&gt;I may be not done, the Migration tool does not give the ability to make complete topology change. this tool simple ACL rule conversation based on exiting to new.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this is not a big rule base I do it manually and now you got a chance to get rid of old rules which redundant moving forward with the new setuo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 05:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267557#M1077067</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-06T05:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267594#M1077069</link>
      <description>&lt;P&gt;That's a current limitation of both the FMT as well as the online migration tool in CDO. I had to go through similar pain in a recent migration. I have since brought it up with the Cisco product team as an unwelcome shortcoming as it can result in a fair amount of unnecessary extra work to change things later. Hopefully future release will incorporate the ability to map to subinterfaces (with or without Etherchannels).&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 07:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4267594#M1077069</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-06T07:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268041#M1077084</link>
      <description>&lt;P&gt;Found the solution - created on both devices (for ASA did it in notepad) Port-Channels with the same numbers, move in notepad ASA config from physical interfaces to Port-Channel subinterfaces and pushed it to Firepower Migration Tool - migration tool created by itself same subinterfaces for FTD&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 20:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268041#M1077084</guid>
      <dc:creator>Sergey Sakharov</dc:creator>
      <dc:date>2021-01-06T20:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268219#M1077090</link>
      <description>&lt;P&gt;Yes that will work as an interim workaround if it is one portchannel subinterface to another portchannel subinterface. In my case I was trying to map multiple source ASA physical interfaces a a single portchannel on FTD with subinterfaces corresponding to the multiple physical interfaces.&amp;nbsp; Maybe I could have gotten it to work if I had more extensively hand-modified the source ASA config to fool the tool into thinking they all started out as subinterfaces on a single interface&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 07:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268219#M1077090</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-07T07:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD interface reconfiguration</title>
      <link>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268321#M1077096</link>
      <description>&lt;P&gt;Good you cracked, since software not know what you done, so you change the config bluff the tool so it can migrate as it is..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;good stufff&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 10:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-interface-reconfiguration/m-p/4268321#M1077096</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-07T10:34:40Z</dc:date>
    </item>
  </channel>
</rss>

