cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
111
Views
2
Helpful
2
Replies

Does the FMT overwrite all FTD configuration if only selecting NAT

Am I able to only push partial configuration to a FTD and keep all other existing configuration if options are deselected?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You can elect not to choose a target FTD when running the migration tool.

https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/m-asa-to-threat-defense-migration-workflow.html#id_68145

That will trigger this workflow: "if you do not have a threat defense device, you can migrate the shared policies (Access Control Lists, NAT, and Objects) of the ASA configuration to the management center."

You could then later assign the migrated NAT policy to your existing device. However you would be responsible for manually ensuring that all of the interfaces and zones were already properly assigned so that the NAT policy would be valid.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

You can elect not to choose a target FTD when running the migration tool.

https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/migration-guide/ASA2FTD-with-FP-Migration-Tool/m-asa-to-threat-defense-migration-workflow.html#id_68145

That will trigger this workflow: "if you do not have a threat defense device, you can migrate the shared policies (Access Control Lists, NAT, and Objects) of the ASA configuration to the management center."

You could then later assign the migrated NAT policy to your existing device. However you would be responsible for manually ensuring that all of the interfaces and zones were already properly assigned so that the NAT policy would be valid.

Review Cisco Networking for a $25 gift card