01-15-2021 03:58 AM
Hello for everybody.
Initial data - ASA-5515X with NAT and firepower 1140 managed by FMC.
Is it possible to transfer only NAT rules from ASA-5515X to FP1140 using this Firepower Migration Tool?
After watching video on youtube and reading config guides, it was believed that the config from the ASA can be picked up in two ways - by downloading it in text (notepad++) and connecting to the ASA directly from migration tools. But it is possible to transfer only NAT rules is unclear.
01-15-2021 04:28 AM
if it is less NAT policies, then i go with Notepad++ it give ability learn what NAT rules are in place and any one required to remove you can make them redundant.
01-15-2021 04:44 AM
There are about 50-60 nat rules.
01-15-2021 04:54 AM
if it 50-60 i do manually, but you can use the migration tool.
01-15-2021 04:39 AM
Yes - during the FMT process you have the option of transferring the whole configuration (or at least as much as the tool supports) or only selecting sections such as the NAT rules or access-lists or objects.
01-15-2021 05:11 AM - edited 01-15-2021 06:14 AM
Moment with a whole configuration we didnt consider, because the inside and outside addresses were changed.
And if we transfer from ASA to HA of FP1140, we need to specify the mgmt address of the main device.
01-22-2021 11:34 AM
Before this transfer of NAT rules, i deleted all unused rules. As a result, there were about 10 used. I moved all manually.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide