<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC conflicts and overlaps in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302304#M1121450</link>
    <description>&lt;P&gt;Yes, those conflict errors can still happen even on a blank FMC. Here's why:&lt;/P&gt;&lt;H3&gt;Why You’re Seeing Conflicts&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The ACP you're importing likely has objects (like network, service, or zone objects) that are &lt;STRONG&gt;referencing things that don't exist&lt;/STRONG&gt; yet on the new FMC.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Some objects might have &lt;STRONG&gt;duplicate names&lt;/STRONG&gt; or &lt;STRONG&gt;missing dependencies&lt;/STRONG&gt; from the export.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Even though the FMC is clean, the ACP still depends on certain settings or objects it used before.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;What You Should Do&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Check the conflict details&lt;/STRONG&gt; on the FMC. It should tell you what objects are causing the problem.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the object is unused, delete it.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If it’s needed, check if:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The name is already in use&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;It’s missing a reference&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;It can be renamed&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Try resolving the conflict by either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Renaming the object&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Creating the missing item manually&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Make sure you can deploy the policy on the test FMCv without errors &lt;STRONG&gt;before exporting it to the production FMC.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;Final Tip&lt;/H3&gt;&lt;P&gt;If you’re unsure, try importing the same ACP into another test FMCv running the same version as production. That way you can catch errors before pushing it live.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jun 2025 09:34:51 GMT</pubDate>
    <dc:creator>rovianjaxiel</dc:creator>
    <dc:date>2025-06-25T09:34:51Z</dc:date>
    <item>
      <title>FMC conflicts and overlaps</title>
      <link>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302259#M1121447</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have exported an ACP from on FMC 2500 onto a blank new FMCv. I have then upgraded the FMCv and plan on migrating that ACP to a newer FMC already in production and migrating two firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My issue is when I imported the ACP onto the blank FMCv I have conflict errors. I am unsure what these are and how to resolve them or if they need resolving before exporting and importing again onto the final destination FMC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these naming conflicts or something else? As it is a blank FMC i wouldn't of thought that was the case.&lt;/P&gt;&lt;P&gt;How do I resolve?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 05:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302259#M1121447</guid>
      <dc:creator>NetworkMonkey101</dc:creator>
      <dc:date>2025-07-24T05:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: FMC conflicts and overlaps</title>
      <link>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302286#M1121448</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1495947"&gt;@NetworkMonkey101&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;FYI :&lt;/EM&gt;&lt;/FONT&gt;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwp29808" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwp29808&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 08:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302286#M1121448</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-06-25T08:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC conflicts and overlaps</title>
      <link>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302295#M1121449</link>
      <description>&lt;P&gt;The policy analysis conflicts are just highlighting that some of your objects and/or rules have overlaps and are thus not entirely internally consistent. You have the opportunity to analyze them and potentially combine some unless you prefer to keep them as separately defined names for reasons external to the firewall (e.g., to better follow the business logic from a human-readable point of view).&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 09:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302295#M1121449</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-25T09:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC conflicts and overlaps</title>
      <link>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302304#M1121450</link>
      <description>&lt;P&gt;Yes, those conflict errors can still happen even on a blank FMC. Here's why:&lt;/P&gt;&lt;H3&gt;Why You’re Seeing Conflicts&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The ACP you're importing likely has objects (like network, service, or zone objects) that are &lt;STRONG&gt;referencing things that don't exist&lt;/STRONG&gt; yet on the new FMC.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Some objects might have &lt;STRONG&gt;duplicate names&lt;/STRONG&gt; or &lt;STRONG&gt;missing dependencies&lt;/STRONG&gt; from the export.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Even though the FMC is clean, the ACP still depends on certain settings or objects it used before.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;What You Should Do&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Check the conflict details&lt;/STRONG&gt; on the FMC. It should tell you what objects are causing the problem.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the object is unused, delete it.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If it’s needed, check if:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The name is already in use&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;It’s missing a reference&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;It can be renamed&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Try resolving the conflict by either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Renaming the object&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Creating the missing item manually&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Make sure you can deploy the policy on the test FMCv without errors &lt;STRONG&gt;before exporting it to the production FMC.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;Final Tip&lt;/H3&gt;&lt;P&gt;If you’re unsure, try importing the same ACP into another test FMCv running the same version as production. That way you can catch errors before pushing it live.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 09:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-conflicts-and-overlaps/m-p/5302304#M1121450</guid>
      <dc:creator>rovianjaxiel</dc:creator>
      <dc:date>2025-06-25T09:34:51Z</dc:date>
    </item>
  </channel>
</rss>

