02-19-2026 08:07 AM
Hey all,
Does anyone have experience using the Threat Defense Model Migration? We are migrating from a 2110 in HA to a 3105 in HA. We are debating whether to do this manually or is it less error prone to use the migration utility built into FMC?
Thanks,
David
02-19-2026 09:44 AM
check the model migration guide :
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
02-19-2026 09:54 AM
Thanks, I have the guide. I just have not tried this yet. If it works well, it looks like it would be a time saver. If it tends too be buggy, I think I'd rather manually do the migration to avoid delays with opening TAC cases.
Thannks,
David
02-19-2026 09:57 AM
@davparker if the FTD is managed by an FMC you can just configure the basic to establish network connectivity and then apply the same policies already in use on the existing firewall.
02-19-2026 10:07 AM
Thanks, it is. I'm leaning this way. Seems like the outcome might be more predictable. I've stood up enough of these lately. Also I can't find much of anything on user's experience using the Migrate tool. If it could migrate certificates I'd take a crack at it, but it looks like we'll need to re-enroll those no matter which way we go.
02-19-2026 10:17 AM
@davparker it's simple enough to export/import the certificates - or better create new if internally signed certificate. Most of the time I prefer manual migrations (any vendor) as it's a good chance to get tweak the implementation and not migrate poor configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide