<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower migration tool in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3732723#M995072</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292144"&gt;@Antonio Macia&lt;/a&gt; With Firepower Migration Tool R1.1 you should be able to rename objects (bulk supported) within the tool itself. Here is the link to download the tool: &lt;A href="https://www.cisco.com/c/en/us/products/security/firewalls/firepower-migration-tool.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/firewalls/firepower-migration-tool.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA rule optimization features explained here: &lt;A href="https://www.youtube.com/watch?v=o2EIOh8s1Lo&amp;amp;t=1s" target="_blank"&gt;https://www.youtube.com/watch?v=o2EIOh8s1Lo&amp;amp;t=1s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Oct 2018 13:18:20 GMT</pubDate>
    <dc:creator>Munib Shah</dc:creator>
    <dc:date>2018-10-25T13:18:20Z</dc:date>
    <item>
      <title>Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725396#M995051</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After migrating the&amp;nbsp;firewall policy from an ASA to Firepower most of the objects in the rules were automatically grouped and named using the "DM_INLINE_NETWORK" or "DM_INLINE_SERVICE" naming convention. This difficult a lot the understanding and visibility of the policy. Is it possible to disable the grouping so the rules&amp;nbsp;appear as they&amp;nbsp;used to in the ASA?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725396#M995051</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2019-03-12T14:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725467#M995055</link>
      <description>&lt;P&gt;You can't disable the grouping as far as I know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However if you start with an ASA config that has well-defined named groups (network objects, object groups etc.) they should be retained in the Firepower configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725467#M995055</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-10-15T11:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725640#M995057</link>
      <description>&lt;P&gt;Thanks, Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA policy does have well-defined objects. For instance, an original ASA ACE that has 4 individuals objects as a destination get grouped under the "DM_INLINE_NETWORK_54" group when migrated. Same occurs for ports.&lt;/P&gt;
&lt;P&gt;Only those ACEs where&amp;nbsp;there is just a single object do not get grouped.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is very frustrating&amp;nbsp;because although&amp;nbsp;the rules are there,&amp;nbsp;the policy&amp;nbsp;changes make it unmanageable.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725640#M995057</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2018-10-15T15:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725672#M995061</link>
      <description>&lt;P&gt;Unfortunately, there is no way around this. The "DM_INLINE" objects are created by the ASDM when you edit or create network/service object groups on the GUI. The ASDM somehow understands the mapping and shows you the right groups separately, but the CLI still has the DM_INLINE references. Since you use the CLI config to migrate to the Firepower, this gets carried over. I really wish they did something about this in a later version of the migration tool.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725672#M995061</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-10-15T15:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725678#M995066</link>
      <description>&lt;P&gt;Hey Rahul - correct me if I'm wrong but if you create well-named Network objects and groups in ASDM and then use those in your NAT rules, ACL entries etc. they will carry over as-is in the converted configuration - correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only if you just click to add them graphically in ASDM directly (without first creating groups) will you get DM_INLINE objects.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725678#M995066</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-10-15T15:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725690#M995068</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;, that is correct. If you use just a single pre-defined object group, then this is ok. But if you add more than 1 object/object-group in a single ACE, then the ASDM automatically bunches them into another object group with the DM_INLINE reference.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that ASDM has no indicator that DM_INLINE object-groups are being created, this is all in the backend (or use the preview commands feature of ASDM). So, if an administrator has been using ASDM in the past, there is most likely a bunch of rules with that reference that they don't know about until they look at the CLI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 16:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3725690#M995068</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-10-15T16:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3726059#M995070</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/193294"&gt;@Rahul Govindan&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;for giving some light into this. I'm afraid manual work&amp;nbsp;will be necessary to get rid of these DM_INLINE objects...&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 06:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3726059#M995070</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2018-10-16T06:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3732723#M995072</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292144"&gt;@Antonio Macia&lt;/a&gt; With Firepower Migration Tool R1.1 you should be able to rename objects (bulk supported) within the tool itself. Here is the link to download the tool: &lt;A href="https://www.cisco.com/c/en/us/products/security/firewalls/firepower-migration-tool.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/firewalls/firepower-migration-tool.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA rule optimization features explained here: &lt;A href="https://www.youtube.com/watch?v=o2EIOh8s1Lo&amp;amp;t=1s" target="_blank"&gt;https://www.youtube.com/watch?v=o2EIOh8s1Lo&amp;amp;t=1s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 13:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3732723#M995072</guid>
      <dc:creator>Munib Shah</dc:creator>
      <dc:date>2018-10-25T13:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3733053#M995073</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/352145"&gt;@Munib Shah&lt;/a&gt;: Great to hear that this is fixed in the new version of the tool.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 19:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3733053#M995073</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-10-25T19:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3735031#M995077</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;Munib. Sounds great!&lt;/P&gt;
&lt;P&gt;I'll give it a try.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 16:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3735031#M995077</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2018-10-29T16:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801531#M995083</link>
      <description>&lt;P&gt;Migration tool can be used only copying Objects and Services to FMC?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801531#M995083</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2019-02-14T06:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801536#M995085</link>
      <description>&lt;P&gt;Yes definitely. Just choose only Network and Port objects in the Selective Policy section (Step 2)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801536#M995085</guid>
      <dc:creator>Munib Shah</dc:creator>
      <dc:date>2019-02-14T06:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801541#M995087</link>
      <description>&lt;P&gt;Nice, thanks, but it taking 30mins so far with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="subheader text-center"&gt;Parsing in progress. Please refer to console logs for more details&lt;/DIV&gt;
&lt;DIV class="loading-dots"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801541#M995087</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2019-02-14T06:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801546#M995090</link>
      <description>&lt;P&gt;May i know your FMC and tool version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From FMC 6.2.3.3 onward objects are pushed in bulk (1000 in one call) which should be much faster than it was before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use the console window of the tool to verify which ones are currently being pushed.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801546#M995090</guid>
      <dc:creator>Munib Shah</dc:creator>
      <dc:date>2019-02-14T06:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801548#M995092</link>
      <description>&lt;P&gt;FMC is&amp;nbsp;&lt;SPAN&gt;FMC Version: 6.2.3 (build 83)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Tool is&amp;nbsp;Firepower_Migration_Tool_v1.2.0.2-2518.exe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 06:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801548#M995092</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2019-02-14T06:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801557#M995093</link>
      <description>&lt;P&gt;FMC 6.2.3 does not support bulk push for objects. While the migration should work, it may be quite slow. I would recommend to upgrade the FMC to atleast 6.2.3.3 patch for a faster migration experience.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 07:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801557#M995093</guid>
      <dc:creator>Munib Shah</dc:creator>
      <dc:date>2019-02-14T07:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801572#M995094</link>
      <description>&lt;P&gt;It is VM and latest one is 6.3.0.84 but i hadn't even clicked the next of ASA section.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 07:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801572#M995094</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2019-02-14T07:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801573#M995095</link>
      <description />
      <pubDate>Thu, 14 Feb 2019 07:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801573#M995095</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2019-02-14T07:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower migration tool</title>
      <link>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801603#M995096</link>
      <description>&lt;P&gt;Your tool is the latest already. I would recommend to upgrade the FMC to 6.2.3.3 patch so that the tool can push bulk objects. That would be much faster.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-migration-tool/m-p/3801603#M995096</guid>
      <dc:creator>Munib Shah</dc:creator>
      <dc:date>2019-02-14T08:43:00Z</dc:date>
    </item>
  </channel>
</rss>

