10-11-2024 12:01 PM
Hi
I dont have access to a lab so am asking a couple of questions'
I want to migrate from one FTD to an HA pair, On the FMC thats is currently managing the single FTD there is a sub doamin for the FTD but on the new FMC where I want to migrate the FTD policies to for the new HA pair there is just global domain, will the policy import fail due to this.????
also is it ok if VDB levels dont match ??
Solved! Go to Solution.
10-16-2024 07:27 AM
@benolyndav I tested the following scenario in my lab. I created a Policy under a custom domain (not Global) and exported that policy. I then deleted all domains, leaving just "Global". I then imported the policy, this was succesfully imported to "Global".
10-11-2024 12:29 PM
if i were you, i first take the backup and upload to new environment with FMC and FTD, then check all the configuration working, then you can add them to HA - that is best way to do.
10-14-2024 12:21 PM
How does that work the new FTD will have a different management IP Address, not sure your understanding, we have an existing FTD manged by a FMC, I want o migrate the FTDs configs to anothe FTD manged by another FMC
10-14-2024 12:35 PM
@benolyndav you could try and export the policies from the current FMC and import to the new FMC, rather than doing a backup and restore of the FMC.
10-15-2024 12:32 AM - edited 02-24-2025 05:04 AM
@Rob Ingram wrote:@benolyndavyou could try and export the policies from the current FMC and import to the new FMC, rather than doing a backup and restore of the FMC.
Great point. cleaner and more controlled approach
10-15-2024 11:26 AM
Hi Yes tjis is my prefered method, I was wondering on the od FMC its Global domain, then internet sub-domain for internet facing Firewalls, on the new FMC we arent planning a sub domain just global domain would this affect the import of the policies on the new FMC.??
10-15-2024 11:36 AM
@benolyndav I don't believe so. I do not have access to my lab to check atm, if you wish me to I can test at somepoint?
10-16-2024 06:36 AM
@Rob Ingram
Thankyou that would be great
10-16-2024 07:27 AM
@benolyndav I tested the following scenario in my lab. I created a Policy under a custom domain (not Global) and exported that policy. I then deleted all domains, leaving just "Global". I then imported the policy, this was succesfully imported to "Global".
10-17-2024 04:59 AM
Excellent I just tried on our FMCs and worked for me
Thanks
10-14-2024 11:44 PM
May be that was not clear its going to new IP Address, then in that case i go with suggestion made @Rob Ingram only export policies.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide