08-07-2023 03:44 PM
Hi Experts,
I am looking for some options to migrate and FTD 2140 managed by an existing FMC over to a new FTD 3110 which will be managed by a new FMC.
I've been having a look at the migration tool and I see that all the options are only form FDM managed and not an appliance that is already managed by an FMC.
I am having a look at the CDO as well.
Any suggestions are much appreciated.
Solved! Go to Solution.
08-08-2023 02:13 AM
Hi @Arun2022,
FMT is designed to migrate non-FTD/FMC device to FMC. Migration from FMC to FMC should be much simpler.
What I would do (in high level) would be:
Kind regards,
Milos
08-08-2023 02:13 AM
Hi @Arun2022,
FMT is designed to migrate non-FTD/FMC device to FMC. Migration from FMC to FMC should be much simpler.
What I would do (in high level) would be:
Kind regards,
Milos
08-08-2023 06:25 PM
Thanks @Milos_Jovanovic, I appreciate your quick response. In an FMC managed FTD is there any way to login to the appliance directly and take a backup of the config (like any other NGFW vendor). I believe this can be done only via external authentication and not using the local admin account. If I can obtain that config, I can still use FMT, upload the config file manually and push it onto the few FTD/FMC.
08-09-2023 12:00 AM
Yes, you can SSH into device, either with local FTD credentials or with AAA account (depending on your setup, but both are possible technically) and issue "show running-config", as you would do it on ASA. You would get ASA-like output. However, I'm not confident that you could re-import that config into FMT again, as concepts are bit different on FTD then on ASA (there is no more interface specific ACL, rather just one, applied globally), so I'm not sure that it would work.
Kind regards,
Milos
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide