05-17-2024 01:46 PM
Good Afternoon,
I have an ASA 5525-X on 9.12.x. We have been working with TAC to try and migrate our ASA config to a Firepower 2120 running FTD code. We also have CDO. We are hoping to use CDO's ASA to FTD conversion tool, but so far as been wildly unsuccessful. We have had several cases open with TAC, and they cant seem to figure out what is wrong either.
The latest attempt ended up with only the Inside-->Outside Rules coming over, and all of our network objects. The rules that came over were not in the order they exist inside the ASA.
I reimaged the Firepower device to remove all traces of the botched config and re-enrolled in CDO. I am getting the follow error messsage on the import:
Before this, I had these three lines error out on the conversion:
When we removed these lines, and imported, only a portion on the ACLs actually come over.
Just as a side note: I have tried using the firewall migration tool inside CDO as well. That tool only copied a fraction of the network objects, but did get all our rules, but because it couldnt "connect" to the FTD, it just ran and finished (successfully) but didnt generate a file to update from what I can tell...
If anyone has any experience moving from ASA to FTD, could you lend me some wisdom on what we need to do to make this jump?
Thanks
05-20-2024 09:15 AM
I migrated a few in a lab setting and it worked fine. I would not expect the control-plane ACL to migrate since that is only supported via flexconfig.
Did your source ASA have a Firepower service module and are you trying to migrate its settings as well? If so, did you try migrating without including that?
05-20-2024 09:17 AM
05-20-2024 10:24 AM
OK, thanks for that info. Please keep us updated on what they find.
05-23-2024 06:58 AM
I have converted several confgurations from ASA to FTD and found it best to do it from scratch, how big is your config ? Whith automatic convertion you will end up with alot of thing that you will need to fix anyway.
05-23-2024 10:43 AM
Hi, so the tool in CDO is the same FMT tool available via cisco downloads, but just a containerized version with more frequent fixes and patches, (advantage of a SaaS platform!). I will pass this thread along.
05-23-2024 10:44 AM
FYI a new FMT version rolled out in CDO this morning.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide