12-13-2024 05:42 AM
Hi,
I'm trying migrate ASA 9.16 access-lists and objects using Firewall Migration Tool 7.0.1 to a FTD. So far only the access-lists defined by "access-group in interface" are migrated. All the ACLs "access-group out interface" are ignored.
access-group <ifname>_access_in in interface <ifname>
access-group <ifname>_access_out out interface <ifname>
Am I missing something? I haven't found an option in the migration tool to select also the interface out ACLs. Am I the only one who ever used ACLs matching interface outbound or is it yet another bug with ASA in multicontext mode? I would expect that the migration tools generates FTD rules with the interface as destination zone.
Regards,
Bernd
Solved! Go to Solution.
12-13-2024 06:32 AM
It works as intended (although not as expected). Only incoming and global ACLs are supported:
12-13-2024 06:32 AM
It works as intended (although not as expected). Only incoming and global ACLs are supported:
12-15-2024 11:23 PM
Create image: Cisco logo with a facepalm emoticon
CheatGPT won't win any of US spelling bee contests ...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide