01-30-2025 12:54 PM
I tried migrating our 5555-X to a 3120 instance HA pair. For the most part, it migrated, however only ONE WAY. Our firewall is set up with inbound AND outbound ACLs and only the inbound ACL's migrated, leaving a huge load of unmigrated network objects and groups.
Has the latest tool solved this issue yet, or does it still ignore outbound ACL's and associated objects? We have a few ACL's used to allow access to a server that is applied to the outgoing list on the DMZ. It is set that way since traffic can egress from multiple interfaces to that DMZ through the ASA.
01-30-2025 01:43 PM
Outbound ACLs are still unsupported:
I would not expect that this feature will get implemented.
01-30-2025 01:57 PM
you would have run some automation using API etc to accmoplish this.
i have to had to do some large scale migration using scripting etcl.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide