cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2268
Views
10
Helpful
4
Replies

best way to migrate VPN Cogfiguration from ASA to FTD

karthik.r911
Level 1
Level 1

what is the best way to migrate VPN configurations from ASA to FTD

4 Replies 4

Hi Karthik,

if you are planing to migrate ASA to FTD, preferred method is below link.

https://www.cisco.com/c/en/us/td/docs/security/firepower/migration-tool/11/migration-guide/ASA2FTD-with-FP-Migration-Tool-11.html

regards,
*** Pls rate all useful responses ***
Good Luck
Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi Kasun,

 

           Can I migrate VPN configurations using this migration tool? if NO. what is the alternate way

Hi Karthik,

you can migrate VPN settings manually. use below links for reference of VPN configurations.

https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/firepower_threat_defense_site_to_site_vpns.pdf

regards,
*** Pls rate all useful responses ***
Good Luck
Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

It depends on what features you are using for VPN. FTD doesn't support the
same feature set yet as ASA. Here is the list at the time of posting. I
suggest to hold for FTD migration at this point if you are using VPN and
use it as ASA with FP module.

Currently unsupported on FTD, but available on ASA:

- Double AAA Authentication
- Dynamic Access Policy
- Host Scan
- ISE posture
- RADIUS CoA
- VPN load-balancer
- Local authentication (Enhancement: CSCvf92680
<>
<>)
- LDAP attribute map
- AnyConnect customization
- AnyConnect scripts
- AnyConnect localization
- Per-app VPN
- SCEP proxy
- WSA integration
- SAML SSO
- Simultaneous IKEv2 dynamic crypto map for RA and L2L VPN
- AnyConnect modules (NAM, Hostscan, AMP Enabler etc.) – DART is
installed by default
- TACACS, Kerberos (KCD Authentication and RSA SDI)
- Browser Proxy


**** Please remember to rate useful posts