<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firepower cutover plan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3383966#M957979</link>
    <description>First of all, can you detail HW and SW for old models and new models?</description>
    <pubDate>Wed, 16 May 2018 07:05:43 GMT</pubDate>
    <dc:creator>Florin Barhala</dc:creator>
    <dc:date>2018-05-16T07:05:43Z</dc:date>
    <item>
      <title>firepower cutover plan</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3383632#M957978</link>
      <description>&lt;P&gt;dear all,&lt;/P&gt;
&lt;P&gt;as I have to replace two of asa with two of firepower&lt;/P&gt;
&lt;P&gt;regardless in configuration issue&lt;/P&gt;
&lt;P&gt;can you help in cutover plan to avoid downtime&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3383632#M957978</guid>
      <dc:creator>Abd Mhd</dc:creator>
      <dc:date>2020-02-21T15:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: firepower cutover plan</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3383966#M957979</link>
      <description>First of all, can you detail HW and SW for old models and new models?</description>
      <pubDate>Wed, 16 May 2018 07:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3383966#M957979</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-16T07:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: firepower cutover plan</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3384088#M957980</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There will always be a drop in traffic when you migrate. however this can be minimized in certain situations.&amp;nbsp; So there are two ways you can do this.&amp;nbsp; First you can do a clean cutover, or you can migrate in phases (ASA and FTD are online parallel).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For a clean cutover do the following:&lt;/P&gt;
&lt;P&gt;1. migrate configuration from ASA to FTD&lt;/P&gt;
&lt;P&gt;2. connect FTD to the network (remember to keep the interfaces in a shutdown state either on the FTD or on the switch it connects to or you will have IP address conflicts)&lt;/P&gt;
&lt;P&gt;3. Shutown interfaces going to ASA&lt;/P&gt;
&lt;P&gt;4. No shutdown interfaces going to FTD&lt;/P&gt;
&lt;P&gt;5. check connectivity and troubleshoot if needed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For running in parallel:&lt;/P&gt;
&lt;P&gt;1. migrate configuration from ASA to FTD&lt;/P&gt;
&lt;P&gt;2. Change interface IPs on FTD (IPs should be in the same subnet and VLANs as the IPs on the ASA)&lt;/P&gt;
&lt;P&gt;3. connect FTD to the network&lt;/P&gt;
&lt;P&gt;4. Change default gateway on PCs and/or servers&amp;nbsp; (when doing this, if you have webservers you would need to take into account that you might need to migrate the public IPs at the time of migration unless you are also able to allocate a new IP and just update DNS)&lt;/P&gt;
&lt;P&gt;5. check connectivity and troubleshoot if needed&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 11:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cutover-plan/m-p/3384088#M957980</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-05-16T11:03:12Z</dc:date>
    </item>
  </channel>
</rss>

