cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

615
Views
15
Helpful
6
Replies
Highlighted
Participant

transferring NAT with Firepower Migration Tool

Hello for everybody.

 

Initial data - ASA-5515X with NAT and firepower 1140 managed by FMC. 

Is it possible to transfer only NAT rules from ASA-5515X to FP1140 using this Firepower Migration Tool? 

 

After watching video on youtube and reading config guides, it was believed that the config from the ASA can be picked up in two ways - by downloading it in text (notepad++) and connecting to the ASA directly from migration tools. But it is possible to transfer only NAT rules is unclear.

6 REPLIES 6
Highlighted
VIP Expert

if it is less NAT policies, then i go with Notepad++ it give ability learn what NAT rules are in place and any one required to remove you can make them redundant.



BB


*** Rate All Helpful Responses ***

Highlighted

There are about 50-60 nat rules.

Highlighted

if it 50-60 i do manually, but you can use the migration tool.



BB


*** Rate All Helpful Responses ***

Highlighted
Hall of Fame Guru

Yes - during the FMT process you have the option of transferring the whole configuration (or at least as much as the tool supports) or only selecting sections such as the NAT rules or access-lists or objects.

Highlighted

Moment with a whole configuration we didnt consider, because the inside and outside addresses were changed.

 

And if we transfer from ASA to HA of FP1140, we need to specify the mgmt address of the main device.

Highlighted
Participant

Before this transfer of NAT rules, i deleted all unused rules. As a result, there were about 10 used. I moved all manually.

Content for Community-Ad