09-05-2019 01:05 AM - edited 02-21-2020 09:27 AM
i need to move asa 5520 9.1(7)11 config onto fmc , for the natting i have many natting rules on the asa that doesnt change the source or destination ip and im puzzled whether i need to move them or not into fmc?
09-05-2019 02:42 AM
Those would most likely be identity NAT (also known as NAT exemption) rules. They typically continue to be needed as they exempt traffic from a more general NAT rule later in the config.
09-05-2019 02:50 AM
If you do not have any overlapping NATs, you do not need to put the NAT exempts. For migration process and other caveats, you can go through the documentation for FTD migration tool:
Regards,
Puneesh
Please rate helpful posts
09-05-2019 08:57 AM
Will you migrate from ASA to FTD too?
If so, yes, you will need to move the NATs to the FMC. You can use Cisco's own Firepower Migration Tool to migrate settings.
Hope this helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide