09-26-2023 10:33 AM - edited 09-26-2023 10:34 AM
Say I have a FMCv (running in VMware) managing about 20 FTD firewalls (1k and 2k models) currently. I want to plan to move my existing FMCv to cdFMC within CDO. Is there a way to migrate the existing FMC configuration, such as the policies and objects, into the cdFMC? I have not found a potential option yet...
Assuming there is no such migration path yet, does it mean cdFMC is really just for greenfield?
Solved! Go to Solution.
09-26-2023 11:52 AM
It's supported. See https://docs.defenseorchestrator.com/#!g-about-the-cloud-delivered-firewall-management-center-in-cdo.html
"A migration wizard is available to help you migrate your Secure Firewall Threat Defense devices from your on-premises Secure Firewall Management Center to the cloud-delivered Firewall Management Center. The devices must have Threat Defense software Version 7.0.3 or a later 7.0.x release, or Version 7.2 or later installed to be migrated. Threat Defense 7.1 releases are not supported."
09-29-2023 05:59 AM
Confirmed verbally with Cisco: "CDO will onboard the devices and import all shared policies and associated objects, device-specific policies, and device configuration from the management center to CDO".
09-26-2023 11:52 AM
It's supported. See https://docs.defenseorchestrator.com/#!g-about-the-cloud-delivered-firewall-management-center-in-cdo.html
"A migration wizard is available to help you migrate your Secure Firewall Threat Defense devices from your on-premises Secure Firewall Management Center to the cloud-delivered Firewall Management Center. The devices must have Threat Defense software Version 7.0.3 or a later 7.0.x release, or Version 7.2 or later installed to be migrated. Threat Defense 7.1 releases are not supported."
09-26-2023 12:27 PM
Thanks, Marvin. But thats not really what I am looking for... Apologize if I was not clear on the question...
I am aware of the option to migrate FTD from on-prem to cdFMC, once the on-prem FMC is onboarded in CDO...But I am looking for the option to migrate FMC configuration from on-prem to cdFMC, such as the policies, VPN, objects etc...
Unless the migration wizard mentioned in your link does those as well when migrating existing FTDs to cdFMC???
09-26-2023 08:00 PM
I don't have access to a cdFMC at the moment, but I believe the wizard mentioned actually migrates the devices' management. It's not just onboarding an on-prem FMC to the cloud.
09-27-2023 05:18 AM - edited 09-27-2023 05:20 AM
You referring to this migration wizard (screenshot below), right? I do not have a viable lab to try it out but I think the wizard would migrate FTD registration and FTD local configuration (Interface, routing etc.). But will it also migrate the configuration within on-prem FMC for the FTD, such as the ACP, NAT, Objects and VPN, to cdFMC?
09-27-2023 05:36 AM
Yes, it's my understanding that everything needed to manage the selected devices will be migrated from the OnPrem FMC to the cdFMC using this wizard.
09-29-2023 05:59 AM
Confirmed verbally with Cisco: "CDO will onboard the devices and import all shared policies and associated objects, device-specific policies, and device configuration from the management center to CDO".
09-27-2023 05:44 AM
Okey, will see if I would be able to find more specific doc or get a temp lab to give this migration wizard a try...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide