cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
742
Views
6
Helpful
10
Replies

FTD Migraton Uisng FMC

benolyndav
Level 4
Level 4

Hi

I dont have access to a  lab so am asking a couple of questions'

I want to migrate from one FTD to an HA pair, On the FMC thats is currently managing the single FTD there is a sub doamin for the FTD but on the new FMC where I want to migrate the FTD policies to for the new HA pair there is just global domain, will the policy import fail due to this.????

also is it ok if VDB levels dont match ??

1 Accepted Solution

Accepted Solutions

@benolyndav I tested the following scenario in my lab. I created a Policy under a custom domain (not Global) and exported that policy. I then deleted all domains, leaving just "Global". I then imported the policy, this was succesfully imported to "Global".

View solution in original post

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

if i were you, i first take the backup and upload to new environment with FMC and FTD, then check all the configuration working, then you can add them to HA - that is best way to do.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@balaji.bandi 

How does that work the new FTD will have a different management IP Address, not sure your understanding, we have an existing FTD manged by a FMC, I want o migrate the FTDs configs to anothe FTD manged by another FMC

@benolyndav you could try and export the policies from the current FMC and import to the new FMC, rather than doing a backup and restore of the FMC.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/tools-import-export.html

 


@Rob Ingram wrote:

@benolyndavyou could try and export the policies from the current FMC and import to the new FMC, rather than doing a backup and restore of the FMC.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/tools-import-export.html

 


Great point. cleaner and more controlled approach

@Rob Ingram 

Hi Yes tjis is my prefered method, I was wondering on the od FMC its Global domain, then internet sub-domain for internet facing Firewalls, on the new FMC we arent planning a sub domain just global domain would this affect the import of the policies on the new FMC.??

@benolyndav I don't believe so. I do not have access to my lab to check atm, if you wish me to I can test at somepoint?

@Rob Ingram 
Thankyou that would be great

@benolyndav I tested the following scenario in my lab. I created a Policy under a custom domain (not Global) and exported that policy. I then deleted all domains, leaving just "Global". I then imported the policy, this was succesfully imported to "Global".

Excellent I just tried on our FMCs and worked for me

Thanks

May be that was not clear its going to new IP Address, then in that case i go with suggestion made @Rob Ingram only export policies.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card