Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

PDF

Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

Unsupported features

Want to summarize with AI?

Log in

Learn which Firewall Threat Defense migration features are unsupported in Security Cloud Control, including excluded configurations, analytics-only devices, EVE exception rules, rule recommendations, and custom network analysis policy requirements.


Migration of a Firewall Threat Defense device registered only for analytics-only with the Firewall Management Center feature is not currently supported.

The following configuration are not imported from the Firewall Management Center to Security Cloud Control as part of migration:

  • Custom Widgets, Application Detectors, Correlation, SNMP and Email Alerts, Scanners, Groups, Dynamic Access Policy, Custom AMP Configuration, Users, Domains, Scheduled Deployment Tasks, ISE configuration, Scheduled GeoDB Updates, Threat Intelligence Director configuration, Dynamic Analysis Connections.

  • ISE internal certificate object is not imported as part of the migration. You must export a new system certificate or a certificate and its associated private key from ISE and import it into Security Cloud Control.

  • Custom Network Analysis Policies (NAPs). Remove them from source access control policies before migration; create a supported NAP in Security Cloud Control afterward if needed.

  • New or updated intrusion rule recommendations. Migrated recommendations remain linked to the intrusion policy, but Security Cloud Control does not generate new ones or automatically update imported ones.

Secure firewall recommended rules

Migrating Firewall Threat Defense to the cloud migrates existing rule recommendations linked to intrusion policies. However, the Cloud-Delivered Firewall Management Center does not generate new rule recommendations or auto-update migrated ones post-migration, as it does not support rule recommendations. See Auto Cisco Recommended Rules.

Remove custom Network Analysis Policies

Before migration, Custom Network Analysis policies must be removed from the On-Premises Firewall Management Center.

  1. Log on to the On-Premises Firewall Management Center.

  2. Choose Policies > Access Control.

  3. Click the edit icon on the access control policy you want to disassociate the custom NAP and then click the Advanced tab.

  4. In the Network Analysis and Intrusion Policies area, click the edit icon.

  5. In the Default Network Analysis Policy list, select a system-provided policy.

  6. Click OK.

  7. Click Save to save the changes and then click Deploy to download the changes to the device.

After migration, you can manually create the Network Analysis Policy in Security Cloud Control Firewall Management.