03-26-2026 09:38 AM
Hi
Our consulting company currently manages our FTD using their shared FMC, which they also use to manage many other clients. I am planning to migrate to my own Cisco FMC appliance so I can manage my FTD directly.
Since we have Site-to-Site VPNs, AnyConnect VPNs, NAT, and numerous other policies on this FTD, what specific configuration files or information should I ask them to provide to ensure a smooth migration?
Thanks
04-05-2026 11:22 AM - edited 04-05-2026 11:34 AM
I've done simillair migrations in the past and you have two options. Either you can ask for a full backup of their FMC, but then you have to do a lot of cleaning afterwards to get rid of everything that doesn't belong to your firewall. What I have done instead is to use the export option and only export things relevant to your firewall. Unfortunately you cannot export Site-to-Site VPNs or AnyConnect VPNs but you can export ACP's, IPS and NAT policys and the relevant objects and object groups and also other things like platform and health policys etc.
/Chess
04-14-2026 12:12 AM
Hi
I have about 10 policy based vpn tunnels with pre shared key. I was hoping the sfo file includes most of configuration and I can just type in the keys manually. And regardi g anyconnect configuration, as long as I use the same url/ip, xml and pkg, will users connect without any issues? We are using azure as IDP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide