Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

PDF

Cisco Security Cloud Control: On-Premises Managed Firewall Threat Defense Migration to Cloud Management

About Firewall Threat Defense migration to Cloud Management

Want to summarize with AI?

Log in

Learn how to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud Management while preserving policies, configurations, and settings through Security Cloud Control Firewall Management.


Introduction

This feature enables you to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud Management through Security Cloud Control Firewall Management. Migration enables organizations to move device management from on-premises infrastructure to Cisco’s cloud-based management. This migration preserves existing policies, objects, and configurations.

Customer benefits

  • Preserves existing policies and configuration

  • Imports device-specific configuration, including interfaces, routing, and related settings

  • Handles duplicate policy and object names according to defined conflict-resolution rules

  • Transfers feature licenses automatically

  • Supports high availability pairs and clusters

  • Provides 14-day evaluation window before permanent commit

  • Allows analytics to remain on-prem or move to cloud

  • Provides an intuitive troubleshooting page with status summaries and step‑by‑step progress to pinpoint issues.

  • Provides migration reports for validation and audit

User role changes

The user roles of the On-Premises Firewall Management Center are no longer applicable in Security Cloud Control Firewall Management after migration. Your authorization to perform tasks on the migrated device is based on your user role in Security Cloud Control Firewall Management. See the Users topic to understand the On-Premises Firewall Management Center Center and Cloud-Delivered Firewall Management Center user role mapping.


Evaluation period and manager changes

When a migration job is successful, you have 14 days to test and assess migration changes using Security Cloud Control. If you are convinced about the migration changes, we recommend that you commit the devices manually, and not wait for Secure Firewall Management Center to automatically commit the migration changes. You have a 14-day evaluation period to review and assess the migration changes that are made to the devices before Secure Firewall Management Center automatically commits them.

After successful migration

  • You have 14 days to evaluate configuration.

  • You can undo the changes and continue managing the device with On-Premises Firewall Management Center.

  • You can commit migration changes to Cloud-Delivered Firewall Management Center.

During evaluation window

  • High availability break may not be supported (depending on onboarding method).

  • Advanced high availability or cluster operations can cause commit failure. Commit before changing HA or cluster configuration

  • Deleting devices is not allowed.

  • Changes made in Cloud-Delivered Firewall Management Center are lost, if reverted.

  • Do not create or modify domains or subdomains on the On-Premises Firewall Management Center if the domain change includes a Firewall Threat Defense device that was migrated to Security Cloud Control. Commit the migration changes in Security Cloud Control, or revert device management to the on-premises On-Premises Firewall Management Center, before you make domain changes that include the migrated device.

    If you create or modify a domain before the migration job is committed, deployment of the device and domain configuration can fail. You can continue to create or modify domains on the On-Premises Firewall Management Center for devices that remain managed by that On-Premises Firewall Management Center and are not part of an uncommitted migration job.

After evaluation period

  • Changes are automatically committed.

  • Selected commit actions cannot be revoked.


How Firewall Threat Defense licenses are handled during migration

  • When the Firewall Threat Defense is migrated to the cloud, all feature licenses associated with the device are transferred to Security Cloud Control and released from the Firewall Management Center to the Smart License pool. The device reclaims the device-specific licenses during its registration with Security Cloud Control. You need not apply license on the device again.

  • The device-specific licenses are not required if you want to keep devices in the Firewall Management Center for analytics.