10-31-2019 01:19 AM - edited 02-21-2020 09:38 AM
Whats the best approach for Bulk configuration on FMC -> FTD ?
I want to replicate ASA Access policies, objects & services to FTD (managed via FMC), so configuring via FMC takes a lot of time and terribly tedious.
Since we cant configure Access policies on FMC via cli, can we configure FTD (cli) and sync with FMC ? Any thoughts ?
10-31-2019 02:51 AM - edited 10-31-2019 02:54 AM
Have not tried it my self, but you could check Firepower migration tool.
https://software.cisco.com/download/home/286306503/type/286321688/release/1.1.3
Edit: Not sure if you meant ASA config to FMC.
br, Mikael
10-31-2019 07:19 AM
Definitely use the Migration Tool. If you're open to cloud-based management, CDO is a good option also. (It cannot coexist with FMC management though.) CDO has ASA to FTD migration support built-in.
You cannot create Firepower configurations for ACL, objects and service via cli no matter what platform you try it from (but you can via API if you're really good at scripting).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide