About the Secure Firewall Migration Tool
This guide contains information on how you can download the Secure Firewall migration tool and complete the migration. In addition, it provides you troubleshooting tips to help you resolve migration issues that you may encounter.
The sample migration procedure (Sample Migration: FDM-managed device to Threat defense 2100) included in this book helps to facilitate understanding of the migration process.
The Secure Firewall migration tool converts supported FDM-managed device configurations to a supported threat defense platform. The Secure Firewall migration tool allows you to automatically migrate supported FDM-managed device features and policies to threat defense. You must manually migrate all unsupported features.
The Secure Firewall migration tool gathers FDM-managed device information, parses it, and finally pushes it to the Secure Firewall Management Center. During the parsing phase, the Secure Firewall migration tool generates a Pre-Migration Report that identifies the following:
-
FDM-managed device configuration items that are fully migrated, partially migrated, unsupported for migration, and ignored for migration.
-
FDM-managed device configuration lines with errors that lists the FDM-managed device components which the Secure Firewall migration tool cannot recognize; this blocks the migration.
Console
The console opens when you launch the Secure Firewall migration tool. The console provides detailed information about the progress of each step in the Secure Firewall migration tool. The contents of the console are also written to the Secure Firewall migration tool log file.
The console must stay open while the Secure Firewall migration tool is open and running.
![]() Important |
When you exit the Secure Firewall migration tool by closing the browser on which the web interface is running, the console continues to run in the background. To completely exit the Secure Firewall migration tool, exit the console by pressing the Command key + C on the keyboard. |
Logs
The Secure Firewall migration tool creates a log of each migration. The logs include details of what occurs at each step of the migration and can help you determine the cause if a migration fails.
You can find the log files for the Secure Firewall migration tool in the following location: <migration_tool_folder>\logs
Resources
The Secure Firewall migration tool saves a copy of the Pre-Migration Reports, Post-Migration Reports, FDM-managed device configs, and logs in the resources folder.
You can find the resources folder in the following location: <migration_tool_folder>\resources
Unparsed File
You can find the unparsed file in the following location: <migration_tool_folder>\resources
Search in the Secure Firewall Migration Tool
You can search for items in the tables that are displayed in the Secure Firewall migration tool, such as those on the Optimize, Review and Validate page.
To search for an item in any column or row of the table, click the Search () above the table and enter the search term in the field. The Secure Firewall migration tool filters the table rows and displays
only those that contain the search term.
To search for an item in a single column, enter the search term in the Search field that is provided in the column heading. The Secure Firewall migration tool filters the table rows and displays only those that match the search term.
Ports
The Secure Firewall migration tool supports telemetry when run on one of these 12 ports: ports 8321-8331 and port 8888. By default, Secure Firewall migration tool uses port 8888. To change the port, update port information in the app_config file. After updating, ensure to relaunch the Secure Firewall migration tool for the port change to take effect. You can find the app_config file in the following location: <migration_tool_folder>\app_config.txt.
![]() Note |
We recommend that you use ports 8321-8331 and port 8888, as telemetry is only supported on these ports. If you enable Cisco Success Network, you cannot use any other port for the Secure Firewall migration tool. |
Cisco Success Network
Cisco Success Network is a user-enabled cloud service. When you enable Cisco Success Network, a secure connection is established between the Secure Firewall migration tool and the Cisco cloud to stream usage information and statistics. Streaming telemetry provides a mechanism to select data of interest from the Secure Firewall migration tool and to transmit it in a structured format to remote management stations for the following benefits:
-
To inform you of available unused features that can improve the effectiveness of the product in your network.
-
To inform you of additional technical support services and monitoring that is available for your product.
-
To help Cisco improve our products.
The Secure Firewall migration tool establishes and maintains the secure connection and allows you to enroll in the Cisco Success Network. You can turn off this connection at any time by disabling the Cisco Success Network, which disconnects the device from the Cisco Success Network cloud.