cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1172
Views
5
Helpful
3
Replies

Firewall Migration Tool error

keithcclark71
Level 3
Level 3

Love the tool thus far but nothing is ever perfect so I hope to get some help here n there on some migration issues I come into. The one I have today is the attached screenshot. "

Migration Unsuccessful!

Error while pushing s2s vpn: Device interface doesn't support VPN."

pushFailedforS2sVPN.jpg

1 Accepted Solution

Accepted Solutions

rhuysmans
Level 1
Level 1

Hi, it looks to me like you just want to delete the FTD device and rebuild it again manually. No problems. Remember that the Policies created by you or the FMT will still remain, as will all the objects and groups in the Object Management tab. You can use these for your new FTD. This includes the interface group objects and zone objects.

If you want to run the FMT again, you can choose what you want to migrate from your ASA config but if you want to run the full FMT then manually deleting all the policies, objects and groups will be the best action, otherwise you may get duplicates. This shouldn't pose a problem as you'll select what you want to use but it's just messy.

Good luck.

View solution in original post

3 Replies 3

rhuysmans
Level 1
Level 1

You haven't mentioned what type of interface you're using but are you trying to create the s2s VPN on a sub-interface?  The FMT doesn't do sub-interfaces so you'll need to create this manually.

Hey thuysmans when I went through the tool it just errored on the s2s tunnels. I'm not concerned with now but what I want to now do is delete the FTD from the FMC that I ran the tool against and pushed the config to so that I can run the tool again. Do I need to manually delete everything the tool brought over to the FMC like objects, NAT, ACP or will deleting the FTD from the FMC also remove any settings related to it.Thougts if you don't mind?I was thinking I could do some things then run the tool again but was thinking it might duplicate the existing objects from the first job run by the tool 

rhuysmans
Level 1
Level 1

Hi, it looks to me like you just want to delete the FTD device and rebuild it again manually. No problems. Remember that the Policies created by you or the FMT will still remain, as will all the objects and groups in the Object Management tab. You can use these for your new FTD. This includes the interface group objects and zone objects.

If you want to run the FMT again, you can choose what you want to migrate from your ASA config but if you want to run the full FMT then manually deleting all the policies, objects and groups will be the best action, otherwise you may get duplicates. This shouldn't pose a problem as you'll select what you want to use but it's just messy.

Good luck.

Review Cisco Networking for a $25 gift card