12-28-2023 05:59 AM
Dear community,
I’m trying to use Cisco’s migration tool to migrate an ASA config to a FTD but I’m facing issues running it. Indeed, it tries to reach out cisco but it fails:
2023-12-28 14:35:21,125 [INFO | common] > "proxies : {}"
2023-12-28 14:35:21,145 [INFO | common] > "Telemetry push : Unable to connect to SSE Cloud server https://sign-on.security.cisco.com HTTPSConnectionPool(host='sign-on.security.cisco.com', port=443): Max retries exceeded with url: / (Caused by NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x0000026BC2EBA250>: Failed to establish a new connection: [Errno 11001] getaddrinfo failed'))"
Wireshark capture indicate that the tool doesn’t use the proxy settings of my corporate device but instead tries to use a direct internet connection, which fails because we cannot resolve public domains and access directly internet with our corporate devices:
DNS 86 Standard query 0xb8c4 A sign-on.security.cisco.com
DNS 176 Standard query response 0xb8c4 No such name A sign-on.security.cisco.com SOA pranspri01.phys.prod
Did anyone manage to run the migration tool using a proxy or run it offline ? I’ve looked the documentation Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense with the Migration Tool - Getting Started with the Secure Firewall Migration Tool [Cisco Secure Firewall ASA] - Cisco but didn’t see anything relating to my problem.
Thanks for your inputs and have a nice holidays.
Solved! Go to Solution.
01-15-2024 01:07 AM
In case someone else has the issue, TAC confirmed that the tool is not configurable to use the system proxy yet, but the BU provided an offline tool that can be executed on a corporate device without direct access to internet, fixing my issue.
12-29-2023 11:57 AM
@uRLKuzE to address this, you might want to check whether the migration tool has specific proxy settings that need configuration. If the tool is not utilizing your corporate device's proxy settings, you may need to manually configure proxy settings within the migration tool itself.
Best of luck in resolving your migration challenges, and happy holidays!
01-15-2024 01:07 AM
In case someone else has the issue, TAC confirmed that the tool is not configurable to use the system proxy yet, but the BU provided an offline tool that can be executed on a corporate device without direct access to internet, fixing my issue.
05-05-2025 10:16 AM
hello dear,
hope your are still viewing this, could you share the link to download this offline version please ?
05-06-2025 12:29 AM
@Cybersecurity_life the offline version must be specifically requested from Cisco TAC. The link is given on a case-by-case basis.
05-12-2025 12:44 AM
Hello,
I had to ask the Cisco support to get the offline migration tool, it wasn't available to download on the cisco website.
01-15-2024 01:11 AM
By the way, I guessed that was the reason!
@uRLKuzE, thank you for writing the solution!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide