cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1375
Views
0
Helpful
5
Replies

Firepower Migration Tool Can't Recognize ASA's Version

DarlynDiaz2948
Level 1
Level 1

Hi, team.

 

I hope that you're right. 

 

I have a situation with migration Cisco Firepower Chassis with ASA Software to Migrate Cisco Firepower Threat Defense with FMC.

 

The point is the following, I have Cisco ASA in Firepower Chassis and its version is 9.14(1). I need to migrate the configurations and I's using Firepower Migration Tool to complete that process, but when I upload the configuration file, the FMT say me "ASA Software Version not found, kindly upload 'show running-config' collected from ASA".

 

I'm uploading the TXT configuration's file that contain the "show running-config".

I don't find the cause about that, and are the any solutions for that?

 

FMT-IMG.png

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

Is it possible for you to select the source and connect via ssh vs. uploading the config file manually? I prefer that method when converting as it is more full-featured.

It's not possible because I'm going to migrate ASA to FTD software to connect with the FMC, So that mean, when I will migrate the ASA to FTD, I won't have connection with ASA.

You run the migration tool while the old ASA and new FMC are online. Only after you have pushed the config to the FMC and validated it would you need to take the ASA offline in anticipation of replacing it with the FTD device.

Yes, I'm understanding that you said me, but the devices that has ASA OS will be the same same devices that will have FTD OS. So if I pass the configuration to FMC without FTD device, a lot of configuration wii not to pass to the FMC, for example the VPN tunneling s2s.

Most of the configuration will transfer even without a target FTD device to assign the policies. For instance, Access Control Policy and NAT Policy will transfer completely.

One possible work around is that if you are moving from one HA pair to another you could break the HA and use the standby unit as the target device and thus migrate all of the bits that might be omitted without having a live target.

In any case, you can still connect to the live source device.

Review Cisco Networking for a $25 gift card