<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD migration tool and destination zone in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824126#M1099989</link>
    <description>&lt;P&gt;Is there any text file in CLI i could edit and just replace all ANY to the zone we want?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 12:10:32 GMT</pubDate>
    <dc:creator>lanab</dc:creator>
    <dc:date>2023-04-28T12:10:32Z</dc:date>
    <item>
      <title>FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4823983#M1099982</link>
      <description>&lt;P&gt;I am using the latest FTD migration tool to move contexts from our old ASA5585 to FMC without FTD.&lt;/P&gt;&lt;P&gt;There is a major problem when doing this conversion as their is no way the tool can apply the destination zone i want and configured it to, it sets it to ANY with no other choice.&lt;/P&gt;&lt;P&gt;This is a problem as we have thousands of ACLs that needs the correct destination zone.&lt;/P&gt;&lt;P&gt;How can we solve this problem, how do we change the destination zone from ANY to XYC for all ACLs?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 10:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4823983#M1099982</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-04-28T10:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824095#M1099986</link>
      <description>&lt;P&gt;Generally the target zones will be configured and associated with interfaces / interfaces groups on a target FTD managed by the FMC. Is it that you don't have a target FTD available yet?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 11:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824095#M1099986</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-04-28T11:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824098#M1099988</link>
      <description>&lt;P&gt;We have no target FTD now as we have like 50 contexts we are migrating from, we want to create the in FMC first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 11:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824098#M1099988</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-04-28T11:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824126#M1099989</link>
      <description>&lt;P&gt;Is there any text file in CLI i could edit and just replace all ANY to the zone we want?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 12:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824126#M1099989</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-04-28T12:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824311#M1100005</link>
      <description>&lt;P&gt;There's no cli source file option that I'm aware of being able to use.&lt;/P&gt;
&lt;P&gt;We have to migrate to a target device to get zones because anything associated with interfaces is not migrated/populated when we choose to "proceed without FTD" as a target device.&lt;/P&gt;
&lt;P&gt;I wonder if you could just spin up a single FTDv and use it (over and over) for the various contexts?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824311#M1100005</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-04-28T16:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824325#M1100006</link>
      <description>&lt;P&gt;I full get your request&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Map ftd interface will use asa to zone in ftd' but ANY is not interface in ASA and you want way to map it to ftd zone&lt;/P&gt;
&lt;P&gt;Am I correct?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824325#M1100006</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-28T16:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824339#M1100009</link>
      <description>&lt;P&gt;I check the asa to ftd migrate will add zone &lt;STRONG&gt;any&lt;/STRONG&gt; for any subnet (source or destination) that is list as any in acl of asa.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 17:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824339#M1100009</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-28T17:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824515#M1100014</link>
      <description>&lt;P&gt;I tried to spin up an FTDv in the lab but then arise another problem as FTDv does not support portchannels so the migration tool will block and not continue.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 08:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824515#M1100014</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-04-29T08:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824521#M1100015</link>
      <description>&lt;P&gt;I have created source and destination zone as wanted in the migration tool but after the conversion is done the tool only populated the source zone correctly and destination zone as ANY.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 08:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824521#M1100015</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-04-29T08:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824559#M1100017</link>
      <description>&lt;H2 class="topictitle2"&gt;I think you hit migration limits here&lt;/H2&gt;
&lt;H2 class="topictitle2"&gt;Migration Limitations&lt;/H2&gt;
&lt;SECTION&gt;
&lt;P&gt;When migrating your ASA configuration, be aware of the following limitations:&lt;/P&gt;
&lt;DL&gt;
&lt;DT class="dlterm"&gt;ASA Configuration Only&lt;/DT&gt;
&lt;DD&gt;The migration tool converts only ASA configurations. It does not convert existing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ASA FirePOWER&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;configurations. You must manually convert an existing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ASA FirePOWER&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;configuration to a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Firepower Threat Defense&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;configuration.&lt;/DD&gt;
&lt;DT class="dlterm"&gt;ACL and ACE Limits&lt;/DT&gt;
&lt;DD&gt;The migration tool can support an ASA configuration file containing up to 2000000&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;total&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;access rule elements. If the converted configuration file exceeds this limit, the migration fails.&lt;/DD&gt;
&lt;DD class="ddexpand"&gt;You must consider the sum of all access rules elements in the ASA configuration file, rather than the element count for a single ACL. To view elements for a single ACL, use the ASA CLI command,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SAMP class="codeph"&gt;show access-list | i elements&lt;/SAMP&gt;.&lt;/DD&gt;
&lt;DT class="dlterm"&gt;Applied Rules and Objects Only&lt;/DT&gt;
&lt;DD&gt;The migration tool only converts ACLs that are applied to an interface; that is, the ASA configuration file must contain paired&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;access-group&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;commands.&lt;/DD&gt;
&lt;DD class="ddexpand"&gt;The migration tool only converts objects if they are associated with either actively-applied ACLs or NAT rules; that is, the ASA configuration file must contain appropriately associated&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;object&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;access-list&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;access-group&lt;/SPAN&gt;, and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cmdname"&gt;nat&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;commands. You cannot migrate network and service objects alone.&lt;/DD&gt;
&lt;DT class="dlterm"&gt;Unsupported ACL and NAT Configurations&lt;/DT&gt;
&lt;DD&gt;
&lt;P&gt;The migration tool supports most ACL and NAT configurations, with certain exceptions. It handles unsupported ACL and NAT configurations as follows:&lt;/P&gt;
&lt;P&gt;Converts but Disables—The migration tool cannot fully convert ACEs that use:&lt;/P&gt;
&lt;A name="id_28394__ul_ofp_25d_lw" target="_blank"&gt;&lt;/A&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Time range objects&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Fully-qualified domain names (FQDN)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Local users or user groups&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Security group (SGT) objects&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Nested service groups for both source and destination ports&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It cannot convert certain elements of these rules because there is no Firepower equivalent functionality for the unsupported elements. In these cases, the tool converts rule elements that have Firepower equivalents (for example, source network), excludes rule elements that do not have Firepower equivalents (for example, time range), and disables the rule in the new access control or prefilter policy it creates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For each disabled rule, the system also appends&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SAMP class="codeph"&gt;(unsupported)&lt;/SAMP&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the rule name and adds a comment to the rule indicating why the system disabled the rule during migration. After importing the disabled rules on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;your&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt;, you can manually edit or replace the rules for successful deployment in the Firepower System.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DD&gt;
&lt;/DL&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Sat, 29 Apr 2023 11:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4824559#M1100017</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-29T11:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4825846#M1100066</link>
      <description>&lt;P&gt;This is by far the worst product i ever worked with, it's full of bugs.&lt;/P&gt;&lt;P&gt;I had to export the ACP and then manually edit the show-tech file for all interfaces that are portchannels to ordinary ethernet interfaces, then i ran the migration tool it continued fine, but still not working as it should.&lt;/P&gt;&lt;P&gt;Some rules gets a -no lookup after the ACL name which means it sets destination zone to ANY which means i still have to manually change all those ACLs from ANY to the right destination zone i want.&lt;/P&gt;&lt;P&gt;And editing just one ACL takes ages because the slow FMC GUI is not the fastest to work with.&lt;/P&gt;&lt;P&gt;So Cisco does not have any solution to this crap? your answer is to edit several hundreds of ACLs? we don't have that time.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 19:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/4825846#M1100066</guid>
      <dc:creator>lanab</dc:creator>
      <dc:date>2023-05-01T19:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD migration tool and destination zone</title>
      <link>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/5166527#M1115412</link>
      <description>&lt;P&gt;Did you ever resolve this issue I have the same problem? I do not want to have to edit 900 individual policies within FMC to use the correct zone instead of the migrated "any" zone.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 13:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-migration-tool-and-destination-zone/m-p/5166527#M1115412</guid>
      <dc:creator>NetworkMonkey101</dc:creator>
      <dc:date>2024-08-27T13:29:29Z</dc:date>
    </item>
  </channel>
</rss>

