<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you Marvin. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931105#M149686</link>
    <description>&lt;P&gt;Thank you Marvin.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2016 14:13:56 GMT</pubDate>
    <dc:creator>talkapple4</dc:creator>
    <dc:date>2016-10-03T14:13:56Z</dc:date>
    <item>
      <title>FWSM v4.1 to ASA v9.6.1 on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931100#M149673</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As you can see in the title, I have to migrate a (huge) configuration from FWSM OS v4.1 to ASA OS v9.6.1 on Firepower 4100.&lt;/P&gt;
&lt;P&gt;I found the FWSM to ASA-SM migration tool - which translates the configuration to ASA-SM OS v8.5 - here:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/migration/fwsm/fwsm2asasm.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/migration/fwsm/fwsm2asasm.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I also know the officially recommended upgrade path from here:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/release/notes/asarn96.html#ID-2152-0000000a" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/release/notes/asarn96.html#ID-2152-0000000a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There are two problems:&lt;/P&gt;
&lt;P&gt;1. I can't boot in place with one of the new ASA images, because I am migrating *both hardware &amp;amp; software version* at the same time.&lt;/P&gt;
&lt;P&gt;2. I can't figure out&amp;nbsp; where the resulting ASA-SM v8.5 configuration from the first link would fit in the table from the second one.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Supposing I can find and will use an old ASA 5550, I still can't figure out with which software version I would have to start the migration with.&lt;/P&gt;
&lt;P&gt;Version 8.5 seems to be an odd one, I can't find it here:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/portal/pub/download/portal/select.html?&amp;amp;mdfid=280563817&amp;amp;flowid=4376&amp;amp;softwareid=280775065" target="_blank"&gt;https://software.cisco.com/portal/pub/download/portal/select.html?&amp;amp;mdfid=280563817&amp;amp;flowid=4376&amp;amp;softwareid=280775065&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Has anyone successfully done this, and if yes, how did you go about it ?&lt;/P&gt;
&lt;P&gt;Thank you !&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931100#M149673</guid>
      <dc:creator>theomarinescu</dc:creator>
      <dc:date>2019-03-12T08:19:32Z</dc:date>
    </item>
    <item>
      <title>Are you a partner? If so,</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931101#M149674</link>
      <description>&lt;P&gt;Are you a partner? If so, there is an available tool that support FWSM configuration file conversion to ASA 55xx.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;https://fwm.cisco.com&lt;/P&gt;
&lt;P&gt;While it doesn't specifically support FirePOWER 4100 as the target, you would choose say a 5555-X only need to modify interfaces to accommodate that platform. The target ASA software is only 9.2(1) but that would not make a difference for your purposes. Of course you assign interfaces on a FirePOWER 4100 via the FX-OS Chassis Manager so that would be a manual process.&lt;/P&gt;
&lt;P&gt;I have used the FWM tool successfully on several larger migrations to 5585-X. I also run the configuration through some cleanup first and double check the NAT conversions using the tools available at tunnelsup.com&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931101#M149674</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-26T14:50:03Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931102#M149681</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The tool you pointed out worked very well and brought me to v9.2(1).&lt;/P&gt;
&lt;P&gt;I was trying to do it myself in Perl - had trouble with a lot of corner cases, and the scripts kept growing.&lt;/P&gt;
&lt;P&gt;Indeed, the interfaces assignation (and bundling into port-channels) are done from the chassis.&lt;/P&gt;
&lt;P&gt;Fixing the subinterface names &amp;amp; cleanup was trivial.&lt;/P&gt;
&lt;P&gt;I will also look up the tools at tunnelsup.&lt;/P&gt;
&lt;P&gt;Thank you very much for your help !!!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 09:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931102#M149681</guid>
      <dc:creator>theomarinescu</dc:creator>
      <dc:date>2016-09-29T09:26:19Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931103#M149684</link>
      <description>&lt;P&gt;Hello Marvin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Migration from FWSM &amp;nbsp;to &amp;nbsp;Firepower 9300 FTD 6.1.&lt;/P&gt;
&lt;P&gt;I have a very big configuration file any advice or thoughts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2016 21:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931103#M149684</guid>
      <dc:creator>talkapple4</dc:creator>
      <dc:date>2016-10-02T21:25:30Z</dc:date>
    </item>
    <item>
      <title>Yes, that can be done also. I</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931104#M149685</link>
      <description>&lt;P&gt;Yes, that can be done also. I'd recommend the following:&lt;/P&gt;
&lt;P&gt;1. Work with your Cisco SE or a partner (if you aren't already one) to run things through FWM tool. Scrub things with tunnelsup and an experienced eye to review it all.&lt;/P&gt;
&lt;P&gt;2. There is another brand new partner / internal tool for migration from ASA to FTD.&lt;/P&gt;
&lt;P&gt;If it's part of a large deal you may even be able to convince Cisco to give you a loaner 5585-X to vet the ASA migration prior to moving it onto FTD.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 00:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931104#M149685</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-10-03T00:21:29Z</dc:date>
    </item>
    <item>
      <title>Thank you Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931105#M149686</link>
      <description>&lt;P&gt;Thank you Marvin.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 14:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/2931105#M149686</guid>
      <dc:creator>talkapple4</dc:creator>
      <dc:date>2016-10-03T14:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, that can be done also. I</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3302730#M149687</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;I have FWSM module on 6500 switch. I need to upgrade FWSM to firepower 4140. please I need your recommendation on this .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;much appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Haitham Jneid&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 10:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3302730#M149687</guid>
      <dc:creator>haitham.jneid</dc:creator>
      <dc:date>2017-12-27T10:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Are you a partner? If so,</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3338187#M149688</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are planning to migrate from&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;=======================================================================&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.1(5)1&lt;/P&gt;
&lt;P&gt;Device Manager Version 7.4(2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Compiled on Fri 04-Apr-14 16:15 PDT by builders&lt;/P&gt;
&lt;P&gt;System image file is "disk0:/asa915-1-smp-k8.bin"&lt;/P&gt;
&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hqasasmfw01 up 51 days 15 hours&lt;/P&gt;
&lt;P&gt;failover cluster up 51 days 15 hours&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; WS-SVC-ASA-SM1, 24576 MB RAM, CPU Xeon 5600 series 2000 MHz, 2 CPUs (24 cores)&lt;/P&gt;
&lt;P&gt;Internal ATA Compact Flash, 8192MB&lt;/P&gt;
&lt;P&gt;BIOS Flash M25P32 @ 0x0, 64KB&lt;/P&gt;
&lt;P&gt;====================================================================================&lt;/P&gt;
&lt;TABLE width="390"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Model&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Cisco Firepower Management Center 3500 (66)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Model Cisco Firepower Management Center 3500 (66)&lt;/P&gt;
&lt;P&gt;To Firepower 6.0.1.1-1023&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide some guidance on what is the best way to approach this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Geoffrey Zakayo&lt;/P&gt;
&lt;P&gt;Sr. Cloud &amp;amp; Data Center Engineer&lt;/P&gt;
&lt;P&gt;Kelly Services&lt;/P&gt;
&lt;P&gt;Cell: 425.753.4379 | Email: &lt;A href="mailto:GEOZ905@kellyservices.com" target="_blank"&gt;GEOZ905@kellyservices.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 21:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3338187#M149688</guid>
      <dc:creator>gtsuma</dc:creator>
      <dc:date>2018-02-26T21:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Are you a partner? If so,</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760343#M149690</link>
      <description>&lt;P style="text-align: left;"&gt;hi marvin,&lt;/P&gt;
&lt;P style="text-align: left;"&gt;i used this tool before few years ago on a 5510 8.2 &amp;gt; 5525-X 9.x but it only had a handful NAT and ACL to be converted, so it's still manageable.&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;i have an ASA 5520 8.2 config to convert a 9.1 (for a 5555-X) using the FWM tool but this time it has a lot of NAT/ACL config which manual conversion isn't going to be practical (using the tunnelsup.com tool). and given only a few days to get this done (closing projects before 2018 ends).&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;my question is, how accurate is the FWM tool given with a lot of 8.2 NAT/ACL to convert? is it 100%&lt;/P&gt;
&lt;P style="text-align: left;"&gt;did you run into a problem where a NAT or ACL was converted wrongly (or missed)?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 01:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760343#M149690</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-12-10T01:18:16Z</dc:date>
    </item>
    <item>
      <title>FWM Tool</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760376#M149692</link>
      <description>&lt;P&gt;I've not had any issue with the FWM tool's migration accuracy. That said, I've only done about 5-6 migrations using it so I have a limited sample size. I've not done any huge (e.g., 10,000+ line configuration files) with it. My customers tend to have smaller configurations.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 05:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760376#M149692</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-12-10T05:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: FWM Tool</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760380#M149695</link>
      <description>&lt;P&gt;thanks marvin!&lt;/P&gt;
&lt;P&gt;i would say the 8.2 ACL/NAT config would not exceed 100+ lines. so i'm quite hesitant using this tool.&lt;/P&gt;
&lt;P&gt;but there's also time constraint, so i'm forced to use this tool.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 05:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/3760380#M149695</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2018-12-10T05:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: FWM Tool</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/4840303#M1100681</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;
&lt;P&gt;Does anybody still have a copy of the FWM Tool that they could share with me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;
&lt;P&gt;Ian&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 15:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/4840303#M1100681</guid>
      <dc:creator>iwearing</dc:creator>
      <dc:date>2023-05-22T15:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWM Tool</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/4840389#M1100696</link>
      <description>&lt;P&gt;FWM was referring to a Cisco portal for staff and partners to use. It was at fwm.cisco.com. However it has long since been deprecated in favor of the Secure Firewall Migration tool. It no longer supports the old ASA Security modules (ASASM). Supported source ASA platforms can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/m-getting-started-with-the-secure-firewall-migration-tool.html#id_70647" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/m-getting-started-with-the-secure-firewall-migration-tool.html#id_70647&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The tool is freely downloadable from Cisco.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 17:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-v4-1-to-asa-v9-6-1-on-firepower-4100/m-p/4840389#M1100696</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-05-22T17:16:16Z</dc:date>
    </item>
  </channel>
</rss>

