cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
996
Views
0
Helpful
3
Replies

Two ASA migration to Firepower

Antonio Macia
Level 3
Level 3

Hello,

 

My customer wants to consolidate two ASAs in one high-end Firepower appliance. I've successfully done one-to-one ASA to Firepower migrations in the past and for this case, I wanted to do the trick of consolidating both ASA configuration into one single configuration file. For that I took the relevant configurations which are interfaces, objects, groups and ACLs.

The process works fine but at some point it returns a UTF-8 conversion error, so seems that the trick doesn't work.

 

Wondering if could be possible to import the secondary ASA configuration in Firepower without overwriting the existing Firepower config. Like appending the new interfaces and objects.

 

Regards.

 

 

1 Accepted Solution

Accepted Solutions

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi Antonio,

I have did this same for one customer, manually merge both the configurations (object-groups, ACL, NAT, Access-group) into a single file and did the conversion with FMC migration tool (not the latest ASA to FTD migration tool). Only thing you need to manually configure the interfaces and routes in FMC as per the existing ASA. I have faced lot of issues with the new migration tool. 

If you have a temporary vFMC  then convert it to migration tool and upload the merged config file this will work like a charm.

 

HTH

Abheesh

View solution in original post

3 Replies 3

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi Antonio,

I have did this same for one customer, manually merge both the configurations (object-groups, ACL, NAT, Access-group) into a single file and did the conversion with FMC migration tool (not the latest ASA to FTD migration tool). Only thing you need to manually configure the interfaces and routes in FMC as per the existing ASA. I have faced lot of issues with the new migration tool. 

If you have a temporary vFMC  then convert it to migration tool and upload the merged config file this will work like a charm.

 

HTH

Abheesh

Thanks Abheesh, good to know that someone was successful on doing the same. I managed to fix the issue with the encoding. I will let you know.

 

Regards.

For anyone interested, the procedure worked. Since I was consolidating a couple of existing firewalls on the same organization many objects were duplicated and I have to employ a Python script to remove the duplicates prior to run the migration tool.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card