<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration using FMT with different FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350823#M1123669</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1473936"&gt;@dimdim12&lt;/a&gt;&amp;nbsp;-&amp;nbsp;Definitely follow the advice and guidance that&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1804395"&gt;@sakathik&lt;/a&gt;&amp;nbsp;provided.&lt;/P&gt;
&lt;P&gt;I have found in the couple of dozen migrations I have done for customers that most old ASAs with Firepower service modules have minimal configurations on them. Thus not a lot is lost by handling those policies separately outside the tool workflow.&lt;/P&gt;</description>
    <pubDate>Sat, 29 Nov 2025 07:55:57 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-11-29T07:55:57Z</dc:date>
    <item>
      <title>Migration using FMT with different FMC</title>
      <link>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350679#M1123662</link>
      <description>&lt;P data-start="227" data-end="242"&gt;Hello everyone,&lt;/P&gt;
&lt;P data-start="244" data-end="490"&gt;I’m currently performing a migration from &lt;STRONG data-start="286" data-end="335"&gt;Cisco ASA with FirePOWER Services (ASA + SFR)&lt;/STRONG&gt; to &lt;STRONG data-start="339" data-end="352"&gt;Cisco FTD&lt;/STRONG&gt; using the &lt;STRONG data-start="363" data-end="416"&gt;Secure Firewall Migration Tool (version 7.7.10.4)&lt;/STRONG&gt;, and I’ve run into a limitation that I’m not sure how to properly handle.&lt;/P&gt;
&lt;H3 data-start="492" data-end="511"&gt;&lt;STRONG data-start="496" data-end="511"&gt;Environment&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL data-start="512" data-end="822"&gt;
&lt;LI data-start="512" data-end="560"&gt;
&lt;P data-start="514" data-end="560"&gt;Source Firewall: ASA with FirePOWER Services&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="512" data-end="560"&gt;
&lt;P data-start="514" data-end="560"&gt;Source FMC (managing the SFR module): &lt;STRONG data-start="601" data-end="620"&gt;FMC version 7.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="621" data-end="677"&gt;
&lt;P data-start="623" data-end="677"&gt;Target Firewall: FTD (already deployed and registered)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="678" data-end="711"&gt;
&lt;P data-start="680" data-end="711"&gt;Target FMC: &lt;STRONG data-start="692" data-end="711"&gt;FMC version 7.6&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="712" data-end="822"&gt;
&lt;P data-start="714" data-end="736"&gt;ASA currently handles:&lt;/P&gt;
&lt;UL data-start="739" data-end="822"&gt;
&lt;LI data-start="739" data-end="765"&gt;
&lt;P data-start="741" data-end="765"&gt;Site-to-Site IPSec VPN&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="768" data-end="790"&gt;
&lt;P data-start="770" data-end="790"&gt;Gateway interfaces&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="793" data-end="804"&gt;
&lt;P data-start="795" data-end="804"&gt;Routing&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="807" data-end="822"&gt;
&lt;P data-start="809" data-end="822"&gt;DHCP server&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 data-start="824" data-end="837"&gt;&lt;STRONG data-start="828" data-end="837"&gt;Issue&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P data-start="838" data-end="921"&gt;When selecting the FMC during the migration process, the tool displays the message:&lt;/P&gt;
&lt;BLOCKQUOTE data-start="923" data-end="989"&gt;
&lt;P data-start="925" data-end="989"&gt;&lt;STRONG data-start="925" data-end="989"&gt;“The Source and the Target FMC has to be the same FMC unit.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dimdim12_0-1764322719190.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/255943iDA8461E41DBBA2AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dimdim12_0-1764322719190.jpeg" alt="dimdim12_0-1764322719190.jpeg" /&gt;&lt;/span&gt;&lt;/BLOCKQUOTE&gt;
&lt;P data-start="991" data-end="1246"&gt;This means I cannot select the new FMC (7.6) where my FTD is currently registered.&lt;BR data-start="1073" data-end="1076" /&gt;If I choose &lt;STRONG data-start="1088" data-end="1113"&gt;“Proceed without FTD”&lt;/STRONG&gt;, the tool warns that &lt;STRONG data-start="1135" data-end="1193"&gt;interfaces, routing, and S2S VPNs will not be migrated&lt;/STRONG&gt;, which is a critical requirement for my environment.&lt;/P&gt;
&lt;H3 data-start="1248" data-end="1265"&gt;&lt;STRONG data-start="1252" data-end="1265"&gt;Questions&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL data-start="1266" data-end="1793"&gt;
&lt;LI data-start="1266" data-end="1417"&gt;
&lt;P data-start="1269" data-end="1417"&gt;Is it &lt;STRONG data-start="1275" data-end="1288"&gt;supported&lt;/STRONG&gt; to temporarily unregister the FTD from &lt;STRONG data-start="1328" data-end="1339"&gt;FMC 7.6&lt;/STRONG&gt; and register it to &lt;STRONG data-start="1359" data-end="1370"&gt;FMC 7.2&lt;/STRONG&gt; only for the purpose of running the migration?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1418" data-end="1594"&gt;
&lt;P data-start="1421" data-end="1594"&gt;After the migration and deployment are completed, can I safely unregister the FTD from FMC 7.2 and register it back to &lt;STRONG data-start="1540" data-end="1551"&gt;FMC 7.6&lt;/STRONG&gt; without losing the migrated configuration?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1595" data-end="1665"&gt;
&lt;P data-start="1598" data-end="1665"&gt;Is there any official Cisco documentation confirming this workflow?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1666" data-end="1793"&gt;
&lt;P data-start="1669" data-end="1793"&gt;Is there a recommended or alternative best practice for this scenario when the source and target FMC versions are different?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="1795" data-end="1886"&gt;Any guidance or best practices from the community would be highly appreciated.&lt;BR data-start="1873" data-end="1876" /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 09:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350679#M1123662</guid>
      <dc:creator>dimdim12</dc:creator>
      <dc:date>2025-11-28T09:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Migration using FMT with different FMC</title>
      <link>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350730#M1123665</link>
      <description>&lt;P data-start="60" data-end="158"&gt;This is the default behavior of FMT, where the source and target FMC must be the same device.&lt;/P&gt;
&lt;P data-start="160" data-end="433"&gt;Please refer to the ASA with FPS migration workflow guide:&lt;BR data-start="218" data-end="221" /&gt;&lt;A class="decorated-link" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-fps/fmt-migration-guide-asa-fps/asawithfps2ftd-with-fp-migration-tool/b_Migration_Guide_ASA2FTD_chapter_0111.html#id_68145" target="_new" rel="noopener" data-start="221" data-end="431"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide-fps/fmt-migration-guide-asa-fps/asawithfps2ftd-with-fp-migration-tool/b_Migration_Guide_ASA2FTD_chapter_0111.html#id_68145&lt;/A&gt;&lt;/P&gt;
&lt;P data-start="435" data-end="727"&gt;It is not recommended—and generally not supported—to temporarily unregister an FTD from FMC 7.6 and register it to an older FMC version (such as FMC 7.2), even for migration or FPS-policy mapping. Doing so may cause registration failures, version incompatibilities, or unsupported behavior.&lt;/P&gt;
&lt;P data-start="729" data-end="864"&gt;As a workaround, please migrate the ASA configuration to the target FMC/FTD and then manually configure the FPS rules on the FMC/FTD.&lt;/P&gt;
&lt;P data-start="866" data-end="1010"&gt;Note that device-level configurations (Interfaces, Routes, S2S VPN, DHCP, and SNMP) will not be migrated if the ‘without FTD’ option is used.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 14:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350730#M1123665</guid>
      <dc:creator>sakathik</dc:creator>
      <dc:date>2025-11-28T14:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Migration using FMT with different FMC</title>
      <link>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350823#M1123669</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1473936"&gt;@dimdim12&lt;/a&gt;&amp;nbsp;-&amp;nbsp;Definitely follow the advice and guidance that&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1804395"&gt;@sakathik&lt;/a&gt;&amp;nbsp;provided.&lt;/P&gt;
&lt;P&gt;I have found in the couple of dozen migrations I have done for customers that most old ASAs with Firepower service modules have minimal configurations on them. Thus not a lot is lost by handling those policies separately outside the tool workflow.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 07:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-using-fmt-with-different-fmc/m-p/5350823#M1123669</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-11-29T07:55:57Z</dc:date>
    </item>
  </channel>
</rss>

