<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 4100 to 4200 migration in FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5309972#M1121851</link>
    <description>&lt;P&gt;for reference, I need the migration tool to migrate from 4120 to 4125.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jul 2025 08:21:11 GMT</pubDate>
    <dc:creator>m-webster</dc:creator>
    <dc:date>2025-07-16T08:21:11Z</dc:date>
    <item>
      <title>FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5296220#M1121230</link>
      <description>&lt;P&gt;Hi all. I'm trying to migrate an FMC-managed FTD 4125 HA pair to a pair of FTD 4215s. &amp;nbsp;FMC and all of the FTDs are running 7.4.2.1.&lt;/P&gt;
&lt;P&gt;Is there any way to migrate the FTD interfaces, routing, etc over to the 4215s? &amp;nbsp;I talked to the TAC and they told me to use the migration wizard in FMC. However, this only seems to support 1100s and 2100s to 3100s, and when we run the wizard, the 4125s don't show up. &amp;nbsp;I was also going to try to use the push config option but that gives me an error that the models and interfaces don't match.&lt;/P&gt;
&lt;P&gt;If there's no way to do this, we're going to have to do it manually, which would be time consuming.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 14:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5296220#M1121230</guid>
      <dc:creator>ben.levin1</dc:creator>
      <dc:date>2025-06-03T14:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5296251#M1121234</link>
      <description>&lt;P&gt;4100 series model migration will be introduced in the next major release of FMC this fall (target ca. September-October).&lt;/P&gt;
&lt;P&gt;For now, the device configuration would need to be manually configured. ACP, NAT, VPN etc. can just be added to the new devices once that first part is done.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 16:54:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5296251#M1121234</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-03T16:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5297000#M1121260</link>
      <description>&lt;P&gt;Thanks for the info!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 18:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5297000#M1121260</guid>
      <dc:creator>ben.levin1</dc:creator>
      <dc:date>2025-06-05T18:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5309962#M1121850</link>
      <description>&lt;P&gt;Marvin, is this release still coming in September / October? If you could post any links about this release here, that would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 07:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5309962#M1121850</guid>
      <dc:creator>m-webster</dc:creator>
      <dc:date>2025-07-16T07:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5309972#M1121851</link>
      <description>&lt;P&gt;for reference, I need the migration tool to migrate from 4120 to 4125.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 08:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5309972#M1121851</guid>
      <dc:creator>m-webster</dc:creator>
      <dc:date>2025-07-16T08:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310231#M1121863</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1898283"&gt;@m-webster&lt;/a&gt;&amp;nbsp;4120 to 4125 will not be a natively supported migration path. You would have to build the device configuration fresh for the 4125 and then assign the ACP, NAT, platform policies to the new 4125. Any VPN (S2S and RA) would likewise need to be reconfigured in FMC to point to the new firewall.&lt;/P&gt;
&lt;P&gt;More details will be posted when the new release comes out - currently still projected for September / October 2025 but subject to change by Cisco.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 17:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310231#M1121863</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-07-16T17:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310449#M1121870</link>
      <description>&lt;P&gt;Another Q that has come up, can you build the new FTD config on FMC without de registering the old kit? It has come to light that FMC may not like 2 devices (not a HA pair) having the same interface IPs.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mitch.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 06:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310449#M1121870</guid>
      <dc:creator>m-webster</dc:creator>
      <dc:date>2025-07-17T06:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310451#M1121871</link>
      <description>&lt;P&gt;As long as you are using the management interface for registration and have unique IPs there, you can build the new FTD(s) using the exact same config as the old one(s).&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 07:01:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310451#M1121871</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-07-17T07:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310452#M1121872</link>
      <description>&lt;P&gt;Thanks Marvin&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 07:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5310452#M1121872</guid>
      <dc:creator>m-webster</dc:creator>
      <dc:date>2025-07-17T07:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5328638#M1122647</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/migration/threat-defense/b_secure-firewall-threat-defense-model-migration-761.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/migration/threat-defense/b_secure-firewall-threat-defense-model-migration-761.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 21:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5328638#M1122647</guid>
      <dc:creator>wimorton</dc:creator>
      <dc:date>2025-09-09T21:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5337745#M1123140</link>
      <description>&lt;P class=""&gt;&lt;SPAN class=""&gt;I am attempting to migrate from an existing FTD 4120 (running version 7.2.10) to a new FTD 4215 (running version 7.4.2).&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;My primary method for this migration is using the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;"Migrate Threat Defense Devices"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;feature within Cisco Secure Firewall Management Center (FMC 7.6.2).&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;However, each attempt to perform the migration results in the following error message:&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;"Threat Defense Model Migration Migration from PL-HQ-FTD-HA cannot proceed because of an internal error. Contact Cisco TAC."&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;I have already opened a case with Cisco TAC regarding this "internal error," but I'm looking for community insights or similar experiences while awaiting their definitive solution.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Migration Tool Failure:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The core issue is the persistent "internal error" when using the official migration tool.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;CLI Restrictions on 7.4.2:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Due to increased CLI restrictions in FTD 7.4.2, manually configuring interfaces, routes, and other network settings on the new 4215 directly via the command line is significantly hindered compared to previous versions. This makes a manual configuration approach very difficult.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; system support diagnostic-cli&lt;BR /&gt;&amp;gt; enable&lt;BR /&gt;Password:&lt;BR /&gt;# conf terminal&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 16:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5337745#M1123140</guid>
      <dc:creator>AhmadAmro</dc:creator>
      <dc:date>2025-10-11T16:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5338007#M1123149</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1901781"&gt;@AhmadAmro&lt;/a&gt;&amp;nbsp;is your FMC at 7.6.2? It was only with FMC 7.6 that 4100 series was added as a source device type (and 4200 series as a target). Is your 4215 a native or multi-instance type configuration? H ave you considered running it with the current suggested release (7.6.2.1)?&lt;/P&gt;
&lt;P&gt;The cli restrictions regarding manual configuration have been present with all versions of FTD ever, whether locally-managed or FMC-managed.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 13:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5338007#M1123149</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-10-13T13:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5343954#M1123357</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your FMC at 7.6.2? &lt;SPAN&gt;FMC version 7.6.2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is your 4215 a native or multi-instance type configuration? Native&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you considered running it with the current suggested release (7.6.2.1)? no current version&amp;nbsp;7.6.2&lt;/P&gt;&lt;P&gt;The cli restrictions regarding manual configuration have been present with all versions of FTD ever, whether locally-managed or FMC-managed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Nov 2025 22:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5343954#M1123357</guid>
      <dc:creator>AhmadAmro</dc:creator>
      <dc:date>2025-11-02T22:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344084#M1123360</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1901781"&gt;@AhmadAmro&lt;/a&gt;&amp;nbsp;I notice your source appears to be an HA pair. Is your target also already configured as HA?&lt;/P&gt;
&lt;P&gt;Assuming you have met all the other prerequisites (link below), then you are best off working with your TAC engineer to resolve the issue. Do please let us know the eventual resolution.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/migration/threat-defense/b_secure-firewall-threat-defense-model-migration-761.html#limitations-for-secure-firewall-threat-defense-model-migration" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/migration/threat-defense/b_secure-firewall-threat-defense-model-migration-761.html#limitations-for-secure-firewall-threat-defense-model-migration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 13:53:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344084#M1123360</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-11-03T13:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344113#M1123365</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;I’ve completed the upgrade to version 7.6.2.1, but unfortunately, I’m still encountering the same error.&lt;/P&gt;&lt;P&gt;Regarding the prerequisites:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I don’t have a multi-instance setup.&lt;/LI&gt;&lt;LI&gt;The source is configured as HA.&lt;/LI&gt;&lt;LI&gt;I had reviewed the prerequisites beforehand and didn’t find any additional steps required in this scenario.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It also seems that TAC support is not very familiar with the migration process—they appear to be troubleshooting it the same way I am&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 15:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344113#M1123365</guid>
      <dc:creator>AhmadAmro</dc:creator>
      <dc:date>2025-11-03T15:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344566#M1123394</link>
      <description>&lt;P&gt;Sorry to hear that TAC is struggling to support your resolution. At this point, I can only suggest that you request escalation of your case with them.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 04:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5344566#M1123394</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-11-05T04:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 4100 to 4200 migration in FMC</title>
      <link>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5362100#M1124153</link>
      <description>&lt;DIV&gt;&lt;P&gt;I wanted to update you regarding the migration. Cisco has shared several important points related to the issue we faced, and I’m sharing them here as they may help others encountering similar migration problems.&lt;/P&gt;&lt;P&gt;During their analysis, Cisco found a discrepancy in the &lt;STRONG&gt;HA_EXTN_DATA&lt;/STRONG&gt; table on the FMC side. This inconsistency caused the &lt;STRONG&gt;static route configuration&lt;/STRONG&gt; to fail during migration, which led to the model migration errors we observed. In their lab testing, Cisco identified a workaround: using &lt;STRONG&gt;“Refresh Node Status”&lt;/STRONG&gt; on the HA pair before reattempting the model migration. This resolved the internal errors they previously saw.&lt;/P&gt;&lt;P&gt;Additionally, Cisco highlighted another issue that can cause migration validation failures. On our FTD-HA, interfaces &lt;STRONG&gt;Eth1/1&lt;/STRONG&gt; and &lt;STRONG&gt;Eth1/2&lt;/STRONG&gt; were showing an &lt;STRONG&gt;MTU value of “0”&lt;/STRONG&gt;, which is invalid. MTU values must be between &lt;STRONG&gt;64 and 9184&lt;/STRONG&gt;. This will also need to be corrected to avoid migration errors.&lt;/P&gt;&lt;P&gt;It’s worth mentioning that I performed the same migration on other devices with the &lt;STRONG&gt;same version and platform series&lt;/STRONG&gt; without any issues, which suggests the Cisco TAC findings are accurate for this specific case.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Action Plan from Cisco:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Perform &lt;STRONG&gt;Force Refresh Node Status&lt;/STRONG&gt; on the HA pair&lt;/LI&gt;&lt;LI&gt;Correct the MTU values on &lt;STRONG&gt;Eth1/1&lt;/STRONG&gt; and &lt;STRONG&gt;Eth1/2&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Re-attempt the model migration&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 16 Jan 2026 11:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-4100-to-4200-migration-in-fmc/m-p/5362100#M1124153</guid>
      <dc:creator>AhmadAmro</dc:creator>
      <dc:date>2026-01-16T11:43:25Z</dc:date>
    </item>
  </channel>
</rss>

