<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate from ASASM to FMC/FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726994#M1095299</link>
    <description>&lt;P&gt;What version is your ASASM running? If it's 8.4+ then the suggestion by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320"&gt;@Milos_Jovanovic&lt;/a&gt; is how I'd suggest proceeding. That method should get you a clean migration using FMT.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Nov 2022 04:24:23 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2022-11-24T04:24:23Z</dc:date>
    <item>
      <title>Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726768#M1095292</link>
      <description>&lt;P&gt;I am working on migrating from an ASASM to FMC/FTD.&amp;nbsp; I know that the ASASM isn't fully supported by the firepower migration tool, but the policy and objects are pretty long so we are doing what we can with it and the TAC said that it would not migrate interfaces and static routes.&amp;nbsp; However, I have tested the migration several times and the policy does come over but the post migration report show that not all of the objects and policy were migrated over (lines from the config were ignored). I did manually create the interfaces on the FTD before doing the migration.&lt;/P&gt;
&lt;P&gt;I'll probably end up opening a new TAC case but I figured I'd ask here first. Has anyone done this kind of migration and is there a way to get all of the ACLs and objects successfully migrated over without having to do it all manually?&amp;nbsp; At the moment I'm thinking we'll run the migration tool and then have to go through the post migration report to manually add all the configuration that was ignored. It's going to be very time consuming so I'm hoping to find some ways to speed things up. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726768#M1095292</guid>
      <dc:creator>ben.levin1</dc:creator>
      <dc:date>2022-11-23T17:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726777#M1095293</link>
      <description>&lt;P&gt;Sometime Migration toolk no 100% does what you expected due to some odd config issue around to be honest.&lt;/P&gt;
&lt;P&gt;since you have TAC case, they are the better SME for your case and they review your config, since we do not have your config visibility what worked and what failed here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726777#M1095293</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-23T17:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726782#M1095294</link>
      <description>&lt;P&gt;Thank you for your response. &amp;nbsp;We had a TAC case over the summer but it was closed since the project was delayed. I will open a new TAC case to see if they can help us.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726782#M1095294</guid>
      <dc:creator>ben.levin1</dc:creator>
      <dc:date>2022-11-23T17:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726821#M1095295</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/890309"&gt;@ben.levin1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you have or can get standard ASA (like ASAv or any of the 5500-X models, with newer SW like 9.8+), you could try to manually copy over ASASM config to ASAv. While copying config, if you spot any issues, you can fix them right then and there. Once that is done, you can try again with FMT, and see what are the results.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 19:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726821#M1095295</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T19:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726994#M1095299</link>
      <description>&lt;P&gt;What version is your ASASM running? If it's 8.4+ then the suggestion by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320"&gt;@Milos_Jovanovic&lt;/a&gt; is how I'd suggest proceeding. That method should get you a clean migration using FMT.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 04:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4726994#M1095299</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-24T04:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727278#M1095301</link>
      <description>&lt;P&gt;we have tried FWSM to ASAv and then FTD, the results are not as expected. i am sure you need to do manual task many many lines.&lt;/P&gt;
&lt;P&gt;if the config is simple and I would take the opportunity to clean up many rules and not the required information (which we don't remove and rules not hit also gone increasing organically).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 08:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727278#M1095301</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-24T08:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727571#M1095325</link>
      <description>&lt;P&gt;If I remember correctly, FWSM is using pre ASA v8.3 syntax, so it falls down to migration of pre 8.3 to post 8.3, which is complication of its own, and I fully agree - existing automated tools are not providing best results in such case.&lt;/P&gt;
&lt;P&gt;What I was suggesting is same as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; explained better, with more details - if ASASM is post 8.3 syntax, then manual input of config, without too much config to ASAv (which is always post 8.3) can be used.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 13:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727571#M1095325</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-24T13:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from ASASM to FMC/FTD</title>
      <link>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727581#M1095327</link>
      <description>&lt;P&gt;If I recall correctly ASASM (not FWSM) was an 8.6+ device.&lt;/P&gt;
&lt;P&gt;Since the VLAN groups don't have any real analogue in ASA (or FTD) then doing as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320"&gt;@Milos_Jovanovic&lt;/a&gt; suggests would be the best bet. That should get the ACLs and NAT rules transferred with associated objects. That comprises the bulk of the configuration by number of lines. Routing and interface configurations would need to be done manually.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 13:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrate-from-asasm-to-fmc-ftd/m-p/4727581#M1095327</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-24T13:45:00Z</dc:date>
    </item>
  </channel>
</rss>

