<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need to migrate a virtual Firepower Management Center to a physical Firepower Management Center in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3834138#M133536</link>
    <description>&lt;P&gt;You gonna have some downtime. Event with import export features it is difficult to have 0 downtime migration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you start importing the policies to the new FMC, you need to associate the zones from you ACP rules with interfaces. This means you need to connect your FTDs before policy import. If you have identity policy, than you should do the integration before the policy import because ACP rules are using identities from external sources.&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT and routing are features without export functions. It is expected (but not pleasant) behavior.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since Firepower 6.3 FTD could be backuped. My suggestion is to create backup of the sensors with all the policies they have(routing, NAT, interface conf, flexconfig, etc), and then revert the backup from the new FMC. You cannot revert a backup of FMCv to FMC hardware, but FTD backup is just for the FTD, whatever is the FMC managing it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose Edgar did this long time ago, but I am sharing my thought for the rest interested.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And call TAC only you are facing an issue. If you need assistance for migration, than advanced services is the team you need. Or third party Firepower experts like me &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2019 11:30:18 GMT</pubDate>
    <dc:creator>ivanradevradev_</dc:creator>
    <dc:date>2019-04-08T11:30:18Z</dc:date>
    <item>
      <title>I need to migrate a virtual Firepower Management Center to a physical Firepower Management Center</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3086012#M133534</link>
      <description>&lt;DIV&gt;I&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt; need to migrate a virtual Firepower Management Center to a physical Firepower Management Center (Version 6.2.0-362 /&amp;nbsp;&lt;A href="http://patch-6.2.0.1-59.sh/" target="_blank" data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://patch-6.2.0.1-59.sh/&amp;amp;source=gmail&amp;amp;ust=1501874585510000&amp;amp;usg=AFQjCNH2iW_5rRuu_9Gx0iDa6SFqR9KXkw"&gt;Patch-6.2.0.1-59.sh&lt;/A&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;Per documentation the backup/restore procedure is not recommended.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/backup_and_restore.html#ID-2200-00000297" target="_blank" data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/backup_and_restore.html%23ID-2200-00000297&amp;amp;source=gmail&amp;amp;ust=1501874585510000&amp;amp;usg=AFQjCNFqTGJibmnGiDy9BZiwXdymYgxiAA"&gt;http://www.cisco.com/c/en/us/t&lt;WBR /&gt;d/docs/security/firepower/610/&lt;WBR /&gt;configuration/guide/fpmc-confi&lt;WBR /&gt;g-guide-v61/backup_and_restore&lt;WBR /&gt;.html#ID-2200-00000297&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;"Do not restore backups created on virtual Firepower Management Centers to physical Firepower Management Centers — this may stress system resources."&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;So, do we need to follow the export/import procedure?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;We've tried this procedure in a lab environment:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Update physical FMC to the same Patch than Virtual&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Export configuration on virtual FMC&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Import configuration on physical FMC&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Disabled the HA on virtual FMC&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Desassociate both FTDs from virtual FMC&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;- Associate both FTDs on physical FMC&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;We noticed that the static routes and NATs are not imported in export/import procedure, both configuration disappears from FTD after associate on physical FMC.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&amp;nbsp;The customer doesn't want downtime, is this the right procedure? Is there any way to keep static routes and NAT?&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:46:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3086012#M133534</guid>
      <dc:creator>Edgar Machado</dc:creator>
      <dc:date>2019-03-12T09:46:24Z</dc:date>
    </item>
    <item>
      <title>I'd recommend opening a TAC</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3086013#M133535</link>
      <description>&lt;P&gt;I'd recommend opening a TAC case on this one.&lt;/P&gt;
&lt;P&gt;The static routes and NATs not transferring sounds like a bug.&lt;/P&gt;
&lt;P&gt;Even with that resolved, I'm pretty sure there is going to be downtime involved.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 02:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3086013#M133535</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-04T02:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: I need to migrate a virtual Firepower Management Center to a physical Firepower Management Center</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3834138#M133536</link>
      <description>&lt;P&gt;You gonna have some downtime. Event with import export features it is difficult to have 0 downtime migration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you start importing the policies to the new FMC, you need to associate the zones from you ACP rules with interfaces. This means you need to connect your FTDs before policy import. If you have identity policy, than you should do the integration before the policy import because ACP rules are using identities from external sources.&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT and routing are features without export functions. It is expected (but not pleasant) behavior.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since Firepower 6.3 FTD could be backuped. My suggestion is to create backup of the sensors with all the policies they have(routing, NAT, interface conf, flexconfig, etc), and then revert the backup from the new FMC. You cannot revert a backup of FMCv to FMC hardware, but FTD backup is just for the FTD, whatever is the FMC managing it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose Edgar did this long time ago, but I am sharing my thought for the rest interested.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And call TAC only you are facing an issue. If you need assistance for migration, than advanced services is the team you need. Or third party Firepower experts like me &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 11:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/3834138#M133536</guid>
      <dc:creator>ivanradevradev_</dc:creator>
      <dc:date>2019-04-08T11:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: I'd recommend opening a TAC</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/5156413#M1114897</link>
      <description>&lt;P&gt;Hi Marvin you know if you can&amp;nbsp;use a backup file of physical FMC on a virtual FMC?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 11:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-migrate-a-virtual-firepower-management-center-to-a/m-p/5156413#M1114897</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2024-08-06T11:31:40Z</dc:date>
    </item>
  </channel>
</rss>

