<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD impact of migrating FMC from VMWare to AWS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5281695#M1120618</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We have a production FMC running in VMWare that needs migrating to AWS. Having looked through a bunch of docos and peoples posts on this community and Reddit, it seems migrating FMC is just as painful as the actual product itself. As far as I could find I have three option:&lt;BR /&gt;1) Import and export - Not suitable as doesn't export objects, certificates, remote access config and much more.&lt;BR /&gt;2) Backup restore - apparently only to be used for disaster recovery and doesn't work cross model (VMWare and AWS are different models)&lt;BR /&gt;3) Model migration script - Doesn't support migrating from VMWare to AWS&lt;BR /&gt;&lt;BR /&gt;As none of the above seemed suitable for our use case, I searched the web and seen that people said tricking an FMC to think its a different model allows to restore from backup so I didnt he following:&lt;BR /&gt;&lt;BR /&gt;1) Deployed FMC on AWS&lt;BR /&gt;2) Blocked it from talking to the FTDs on the management port as to avoid any issues with having 2 FMCs online&lt;BR /&gt;3) Ran the '&lt;SPAN&gt;/var/sf/etc/model-info/configure-model.sh' script and tricked the AWS model to think its VMWare model.&lt;BR /&gt;4) Backed up the production VMWare FMC&lt;BR /&gt;5) Uploaded the WMware FMC backup to the AWS FMC which thinks its VMWare&lt;BR /&gt;6) Restored AWS FMC from backup&lt;BR /&gt;7) Changed the AWS FMC back to AWS model by running the script again&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;Changed the AWS FMC back to its AWS allocated IP address instead of the one restored from backup&lt;BR /&gt;&lt;BR /&gt;I don't have much experience with FTD and FMC so I'm not sure what happens when I allow the AWS FMC to talk to the FTDs and shut down the VMWare one. It's technically been restored from backup but obviously I messed around with the models and on top of that the FMC has a different IP address (unfortunately it has to). I'm wondering if anybody has done a similar thing and noticed if they need to reregister the firewall or whether there was any downtime observed.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Our FMC version is 7.2.5&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help would be hugely appriciated!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 20:21:10 GMT</pubDate>
    <dc:creator>szymonsikorski</dc:creator>
    <dc:date>2025-04-15T20:21:10Z</dc:date>
    <item>
      <title>FTD impact of migrating FMC from VMWare to AWS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5281695#M1120618</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We have a production FMC running in VMWare that needs migrating to AWS. Having looked through a bunch of docos and peoples posts on this community and Reddit, it seems migrating FMC is just as painful as the actual product itself. As far as I could find I have three option:&lt;BR /&gt;1) Import and export - Not suitable as doesn't export objects, certificates, remote access config and much more.&lt;BR /&gt;2) Backup restore - apparently only to be used for disaster recovery and doesn't work cross model (VMWare and AWS are different models)&lt;BR /&gt;3) Model migration script - Doesn't support migrating from VMWare to AWS&lt;BR /&gt;&lt;BR /&gt;As none of the above seemed suitable for our use case, I searched the web and seen that people said tricking an FMC to think its a different model allows to restore from backup so I didnt he following:&lt;BR /&gt;&lt;BR /&gt;1) Deployed FMC on AWS&lt;BR /&gt;2) Blocked it from talking to the FTDs on the management port as to avoid any issues with having 2 FMCs online&lt;BR /&gt;3) Ran the '&lt;SPAN&gt;/var/sf/etc/model-info/configure-model.sh' script and tricked the AWS model to think its VMWare model.&lt;BR /&gt;4) Backed up the production VMWare FMC&lt;BR /&gt;5) Uploaded the WMware FMC backup to the AWS FMC which thinks its VMWare&lt;BR /&gt;6) Restored AWS FMC from backup&lt;BR /&gt;7) Changed the AWS FMC back to AWS model by running the script again&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;Changed the AWS FMC back to its AWS allocated IP address instead of the one restored from backup&lt;BR /&gt;&lt;BR /&gt;I don't have much experience with FTD and FMC so I'm not sure what happens when I allow the AWS FMC to talk to the FTDs and shut down the VMWare one. It's technically been restored from backup but obviously I messed around with the models and on top of that the FMC has a different IP address (unfortunately it has to). I'm wondering if anybody has done a similar thing and noticed if they need to reregister the firewall or whether there was any downtime observed.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Our FMC version is 7.2.5&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help would be hugely appriciated!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 20:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5281695#M1120618</guid>
      <dc:creator>szymonsikorski</dc:creator>
      <dc:date>2025-04-15T20:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD impact of migrating FMC from VMWare to AWS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5281971#M1120623</link>
      <description>&lt;P&gt;Why 7.2 and not 7.4 or 7.6? Also yes, there are ways to "hack" the migration scripts. Just note they have no support from Cisco.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 13:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5281971#M1120623</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-04-16T13:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD impact of migrating FMC from VMWare to AWS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5283410#M1120667</link>
      <description>&lt;P&gt;I did this about 2 years ago when moving from an op-premise FMC 4500 to an AWS FMCv300. In my case we removed the device from the on-prem FMC and registered it anew on the AWS instance and restored a device backup. It may have been a bit more than necessary, but we wanted to make doubly sure that nothing was missed as we were moving over about 50 production firewalls.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 15:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5283410#M1120667</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-04-21T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD impact of migrating FMC from VMWare to AWS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5283473#M1120674</link>
      <description>&lt;P&gt;Please consider following the advice of &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;. He has assisted many, including myself, with the migration of the FMC100 and brings valuable expertise to this community.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-impact-of-migrating-fmc-from-vmware-to-aws/m-p/5283473#M1120674</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-04-21T18:15:45Z</dc:date>
    </item>
  </channel>
</rss>

