cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2677
Views
15
Helpful
5
Replies

Firepower Policy and Domain Question

Community,

In the FMC, is there a way to move an Access Control Policy that was created under a subdomain into the "Global" domain? Or do I have to completely recreate the policy in the Global Domain view? When I try to copy the policy it just places it in the same domain as the original.

Thank you.

1 Accepted Solution

Accepted Solutions

That is not correct, you can just export the policy from the source domain and import it to the destination domain

1) Goto Policies > Access Control > Import/Export

Screenshot 2021-02-09 at 18.02.50.png

2) Select the policy you want to export and press "Export" -> .sfo File will be saved to Disk

Screenshot 2021-02-09 at 18.03.37.pngScreenshot 2021-02-09 at 18.04.36.png

3) Change Domain to "Global" and click on "Upload Package"

Screenshot 2021-02-09 at 18.05.01.pngScreenshot 2021-02-09 at 18.05.36.png

4) Choose the file you exportet from Child Domain

Screenshot 2021-02-09 at 18.06.03.png

5) Hit Import

Screenshot 2021-02-09 at 18.06.55.png

6) Set "Import as new" or just keep the same name - I'd recommand "Import as new" to not create duplicate names

Screenshot 2021-02-09 at 18.07.34.png

7) Wait a few seconds/minutes - A task will be scheduled and the policy should be right the in the other domain - objects from childdomain will be imported as well, just keep that in mind (policy objects like Realms might need to be remapped on Import)

 

Hope that helps

View solution in original post

5 Replies 5

You would need to recreate the ACP rules in the Global domain.  You can however automate this using API.

--
Please remember to select a correct answer and rate helpful posts

That is not correct, you can just export the policy from the source domain and import it to the destination domain

1) Goto Policies > Access Control > Import/Export

Screenshot 2021-02-09 at 18.02.50.png

2) Select the policy you want to export and press "Export" -> .sfo File will be saved to Disk

Screenshot 2021-02-09 at 18.03.37.pngScreenshot 2021-02-09 at 18.04.36.png

3) Change Domain to "Global" and click on "Upload Package"

Screenshot 2021-02-09 at 18.05.01.pngScreenshot 2021-02-09 at 18.05.36.png

4) Choose the file you exportet from Child Domain

Screenshot 2021-02-09 at 18.06.03.png

5) Hit Import

Screenshot 2021-02-09 at 18.06.55.png

6) Set "Import as new" or just keep the same name - I'd recommand "Import as new" to not create duplicate names

Screenshot 2021-02-09 at 18.07.34.png

7) Wait a few seconds/minutes - A task will be scheduled and the policy should be right the in the other domain - objects from childdomain will be imported as well, just keep that in mind (policy objects like Realms might need to be remapped on Import)

 

Hope that helps

Yes, but that is if you want to move the whole ACP policy into Global.  But if you are trying to just move some rules, this is not possible as of yet.

--
Please remember to select a correct answer and rate helpful posts

Yeah that is correct, but the question was only about copying/moving the whole policy and not a single rule.

Oliver/Marrius,

 

Thank you both very much for your replies! Yes, I was looking to move the entire policy from their current domain to the Global Domain. I did have one final question regarding this process. The Interface Zone objects that are part of each policy do not exist in the Global Object database, just in their respective domains. If I move a policy that references Interface Zone objects that are NOT in the Global domain DB, will this be a problem? I have interface zone objects in each policy that have the same name but different interfaces assigned. 

 

Thank you. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card