<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower migration tool - diagnostic/mgmt interface change IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913627#M939284</link>
    <description>&lt;P&gt;I am converting a existing ASA to FMC/FTD (6.4) and using the Firepower migration tool (v. 1.3.1-3051). &amp;nbsp;During the "review and validation" I am wanting to change the mgmt IP (Diagnostic1/1) so that it doesn't overlap with the existing production ASA. &amp;nbsp;I have all the other interfaces cabled through switches and have them shutdown on the switch side to prevent any duplicate IP situation etc. &amp;nbsp;When I actually cutover to the FTD - I will simply no shut those interfaces on the switch. &amp;nbsp;But I still need a way to manage the FTD remotely so I need the Diag1/1 interface IP to be different than my production ASA mgmt IP is. &amp;nbsp;Is this possible? &amp;nbsp;If not, how do I stand up the new FTD and preconfigure it (with the migration tool), remotely, without it creating a duplicate IP on the mgmt port? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even have a Raritin console switch on site so I could even leverage it. &amp;nbsp;But I seem to have a "chicken/egg" issue because while I could basically shutdown the corresponding switch link for the mgmt to prevent a duplicate IP (and use the console for access) - I then could not use the Firepower migration tool to push config to it because I lack an interface on net.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to use the migration tool to ONLY push the config to the FMC and then later I can modify it and "deploy" it to the FTD?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other thoughts? ? ?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:25:45 GMT</pubDate>
    <dc:creator>Joseph Gaefe</dc:creator>
    <dc:date>2020-02-21T17:25:45Z</dc:date>
    <item>
      <title>Firepower migration tool - diagnostic/mgmt interface change IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913627#M939284</link>
      <description>&lt;P&gt;I am converting a existing ASA to FMC/FTD (6.4) and using the Firepower migration tool (v. 1.3.1-3051). &amp;nbsp;During the "review and validation" I am wanting to change the mgmt IP (Diagnostic1/1) so that it doesn't overlap with the existing production ASA. &amp;nbsp;I have all the other interfaces cabled through switches and have them shutdown on the switch side to prevent any duplicate IP situation etc. &amp;nbsp;When I actually cutover to the FTD - I will simply no shut those interfaces on the switch. &amp;nbsp;But I still need a way to manage the FTD remotely so I need the Diag1/1 interface IP to be different than my production ASA mgmt IP is. &amp;nbsp;Is this possible? &amp;nbsp;If not, how do I stand up the new FTD and preconfigure it (with the migration tool), remotely, without it creating a duplicate IP on the mgmt port? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even have a Raritin console switch on site so I could even leverage it. &amp;nbsp;But I seem to have a "chicken/egg" issue because while I could basically shutdown the corresponding switch link for the mgmt to prevent a duplicate IP (and use the console for access) - I then could not use the Firepower migration tool to push config to it because I lack an interface on net.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to use the migration tool to ONLY push the config to the FMC and then later I can modify it and "deploy" it to the FTD?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other thoughts? ? ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913627#M939284</guid>
      <dc:creator>Joseph Gaefe</dc:creator>
      <dc:date>2020-02-21T17:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool - diagnostic/mgmt interface change IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913661#M939285</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/149298"&gt;@Joseph Gaefe&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to use the migration tool to ONLY push the config to the FMC and then later I can modify it and "deploy" it to the FTD?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes. See this section of the migration tool guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/b_Migration_Guide_ASA2FTD_chapter_01011.html#id_67815" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/b_Migration_Guide_ASA2FTD_chapter_01011.html#id_67815&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There it describes the process of how we first push the migrated configuration to FMC and then, only "&lt;SPAN&gt;After you have completed your review, deploy the migrated configuration from&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;Firepower Threat Defense&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;device.&lt;/SPAN&gt;" Part of your review is modifying any necessary parameters - that could include the FTD management address.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2019 12:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913661#M939285</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-08-25T12:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool - diagnostic/mgmt interface change IP</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913683#M939286</link>
      <description>&lt;P&gt;It is this screen that has me worried. This is from the migration tool and is immediately following "validation" which is just my chance to review everything before I "push" the config. It was my understanding that this step would just send it to the FMC - not actually to the sensor/fw. &amp;nbsp;But the little warning/note seems to say otherwise. &amp;nbsp;I just cant take ANY risk in the environment I am working in, so I am looking for some clarity. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="blob:https://community.cisco.com/e6d55723-a3d4-43cf-bb21-894c90559dd9" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 01:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool-diagnostic-mgmt-interface-change-ip/m-p/3913683#M939286</guid>
      <dc:creator>Joseph Gaefe</dc:creator>
      <dc:date>2019-08-26T01:36:14Z</dc:date>
    </item>
  </channel>
</rss>

