cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
312
Views
0
Helpful
5
Replies

How to bulk change destination zone for imported policies using FMT

Hi,

I have imported almost 1000 policies using the FMT and have noticed that the destination zone is not set causing an error. I am looking for a way to either bulk edit destination zones on the FMC or re-import again using the FMT and set using the tool. The destination zone is set to "any" using FMT and there is no option to drop it down to the zones being used.

NetworkMonkey101_0-1724774366849.png

Zones are available as seen below so why can I not select them when using the FMT?

NetworkMonkey101_1-1724774438576.png

 

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

I've done several dozen FMT-based migrations and never encountered this issue. Normally the ACP entries would be tied to the zone of the associated interfaces. Could it be that they came from a global ACL in the ASA?

Rules on the ASA configuration are not mapped to zones. They are created within the interface with no zones assigned.

NetworkMonkey101_0-1724780113800.png

 

Yes, I understand that. But when you migrate the interfaces using FMT you assign them to zones. Those zone associations are then used in the ACP migration step.

I have re-ran the FMT and assigned interfaces to zones as I did before. The only zone that is being applied in the ACP step relates to the DMZ. The inside and outside zones are not being applied to their corresponding policies..

They are stating "no lookup" in the rule name whereas the DMZ rules are OK

NetworkMonkey101_0-1724788020470.png

 

Review Cisco Networking for a $25 gift card