cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
420
Views
1
Helpful
5
Replies

FTD migration

Smak231334
Level 1
Level 1

I’m currently working with an FTD 2110 firewall running version 7.0.6, which is managed by an FMC 2500 also on version 7.0.6.2. I've been tasked with migrating the FTD to a different FMC.

I came across this document outlining the migration process.- https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222480-migrate-an-ftd-from-one-fmc-to-another-f.html

In Step 3, it mentions that the device settings can be exported. However, on my current FMC managing the FTD, I don't see the "Device Configuration" option referenced in the guide.

Is there a setting I need to enable, or a specific condition that must be met, for the "Device Configuration" field to become visible?

Please see attached of the screenshot of what i see on my FMC

5 Replies 5

nspasov
Cisco Employee
Cisco Employee

The ability to export device configurations was introduced in version 7.1: https://www.cisco.com/c/en/us/td/docs/security/firepower/710/relnotes/firepower-release-notes-710/features.html

Thus, you will need to upgrade your deployment before you can utilize this functionality. 

Thank you for rating helpful posts!

Thank you for rating helpful posts!

Marvin Rhoads
Hall of Fame
Hall of Fame

Adding to what Neno said, you should definitely upgrade the FMC 2500. 7.0.6.2 is becoming quite dated by now and you are missing out on many features.

Smak231334
Level 1
Level 1

Thank you for the response.

The FMC 2500 highest OS version is 7.0.7, so I do not believe i can get to 7.1 on the FMC. Is there any other way i can get this done

If FTD 2110 is running in HA this can be done with minimal impact on traffic following step by step migration. If you are using a standalone firewall, traffic will be impacted and the only way is to manually configure the device settings. 

There is not much configuration to be done on the device and can be easily documented and done during the migration: settings like, interfaces and zones, routing and DHCP.

The Access control policies, Intrusion Policies, NAT and platform settings can be exported via FMC and then imported to the new FMC.

Optionally you can export the configuration using API and then also using API configure the new FMC also using API calls.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card