cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2916
Views
3
Helpful
8
Replies

ACL import/export from FMC

KayaaKashyap
Level 1
Level 1

Hello,

What are the steps to import and export ACL policy from FMC?

For import - what will be the format?For export- what will be the file type (e.g. pdf or excel) ? 

If I am importing the ACL, will it override the existing ACL? 

3 Accepted Solutions

Accepted Solutions

M02@rt37
VIP
VIP

Hello @KayaaKashyap 

You could export your configuration using FMC API, modify the JSON files to match your FTD ; also you could apply your config FTD using FDM API.

- Export/import on FMC: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/configuration_import_and_export.html

JSON is a common format for exporting and importing configurations in network devices, including Cisco FMC.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

View solution in original post

@KayaaKashyap well if you have an FMC you can apply the same policies to the new FTD or just duplicate an existing Access Control Policy to assign to the new FTD. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/access-policies.html

 

View solution in original post

8 Replies 8

M02@rt37
VIP
VIP

Hello @KayaaKashyap 

You could export your configuration using FMC API, modify the JSON files to match your FTD ; also you could apply your config FTD using FDM API.

- Export/import on FMC: https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/configuration_import_and_export.html

JSON is a common format for exporting and importing configurations in network devices, including Cisco FMC.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

you import the ACL under device so I think there is no conflict. 
MHM

Let’s assume I am implementing new FTD in my network, Is it possible to make new list of ACLs and export in one go?

yes please let me know how and in which format? 

@KayaaKashyap well if you have an FMC you can apply the same policies to the new FTD or just duplicate an existing Access Control Policy to assign to the new FTD. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/access-policies.html

 

What if We will configure new FMC and FTD and we have 1000 of ACLs to configure in this?

what can be the best possible way? 

@KayaaKashyap ok so you have a new FMC and an old FMC? You could take a backup from the old FMC and restore the configuration to the new FMC. Or export and import the policies to the new FMC.

when we use import export ? when we update or backup config 
what about new FTD, only under new FTD device apply the ACL not need export/import 
MHM

Review Cisco Networking for a $25 gift card