01-05-2024 09:48 AM
Hello,
What are the steps to import and export ACL policy from FMC?
For import - what will be the format?For export- what will be the file type (e.g. pdf or excel) ?
If I am importing the ACL, will it override the existing ACL?
Solved! Go to Solution.
01-05-2024 09:53 AM
@KayaaKashyap yes you can import/export policies, full list here - https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/720/management-center-admin-72/tools-import-export.html?bookSearch=true
01-05-2024 09:56 AM - edited 01-05-2024 09:57 AM
Hello @KayaaKashyap
You could export your configuration using FMC API, modify the JSON files to match your FTD ; also you could apply your config FTD using FDM API.
- Export/import on FMC: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/configuration_import_and_export.html
JSON is a common format for exporting and importing configurations in network devices, including Cisco FMC.
01-05-2024 10:23 AM - edited 01-05-2024 10:24 AM
@KayaaKashyap well if you have an FMC you can apply the same policies to the new FTD or just duplicate an existing Access Control Policy to assign to the new FTD. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/access-policies.html
01-05-2024 09:53 AM
@KayaaKashyap yes you can import/export policies, full list here - https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/720/management-center-admin-72/tools-import-export.html?bookSearch=true
01-05-2024 09:56 AM - edited 01-05-2024 09:57 AM
Hello @KayaaKashyap
You could export your configuration using FMC API, modify the JSON files to match your FTD ; also you could apply your config FTD using FDM API.
- Export/import on FMC: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/configuration_import_and_export.html
JSON is a common format for exporting and importing configurations in network devices, including Cisco FMC.
01-05-2024 09:59 AM
you import the ACL under device so I think there is no conflict.
MHM
01-05-2024 10:21 AM
Let’s assume I am implementing new FTD in my network, Is it possible to make new list of ACLs and export in one go?
yes please let me know how and in which format?
01-05-2024 10:23 AM - edited 01-05-2024 10:24 AM
@KayaaKashyap well if you have an FMC you can apply the same policies to the new FTD or just duplicate an existing Access Control Policy to assign to the new FTD. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/access-policies.html
01-05-2024 10:26 AM
What if We will configure new FMC and FTD and we have 1000 of ACLs to configure in this?
what can be the best possible way?
01-05-2024 10:29 AM
@KayaaKashyap ok so you have a new FMC and an old FMC? You could take a backup from the old FMC and restore the configuration to the new FMC. Or export and import the policies to the new FMC.
01-05-2024 10:25 AM
when we use import export ? when we update or backup config
what about new FTD, only under new FTD device apply the ACL not need export/import
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide