03-15-2021 07:54 AM
06-24-2021 01:41 AM
I found this request for enhancement https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvi31505 to move objects between domains to make migration possible with minimum amount of pain.
I'm trying to move to multi tenancy to allow admin in each domain separately & have a TAC case with Cisco as there does NOT appear to be any documentation on how to achieve this. Looks like Cisco expected that decision when FMC is built
Anyone have any info on this ?
08-31-2022 06:31 AM
Same problem here: I used the firewall migration tool to migrate the configuration of an ASA to an FTD in a leaf domain; that correctly created hundreds of objects and object groups in the leaf domain. Then I installed another FTD in another leaf domain, hoping to recycle some of the object definitions from the first leaf domain, but I discovered that there was no easy way to move object (and group) definitions from a leaf domain to the Global domain.
I openend a TAC case and they gave me a few alternatives, none of them easy:
- use the API explorer in order to GET definitions from one domain and paste them into the POST endpoint for creating them in another domain: it works fine for simple objects (one at a time), but not for groups, or groups containing other groups
- dump the policy into a fictious ASA configuration, edit it by hand, cleaning everything it is not needed, and re-import it in another domain wiht the firewall migration tool... officially importing a configuration edited by hand is not supported, and you may need to create a fictuous ftdv to use as a target for the import
- write a program for selectively dumping object definitions from one domain, re-create the objects in the global domain via API, modify pointers, etc... I'm actually following this way, but it will take days to produce a good tool, able to cope with nested groups, objects shared between groups, and so... I wonder if anybody already wrote something similar
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide