Learn the prerequisites for migrating ASA configurations to a Threat Defense device managed by the management center. This overview outlines essential requirements for device registration, high availability, clustering, and interface configuration to ensure a successful migration.
To successfully migrate ASA configurations to a Threat Defense device managed by the management center, consider the following requirements:
-
You do not need to add the target Threat Defense device to the management center before migration. Policies can be migrated to the management center for future deployment to a Threat Defense device.
-
If a Threat Defense device is added to the management center, the target device must be registered with the management center.
-
The target Threat Defense device can be configured for high availability.
-
The Threat Defense device can be standalone or a container instance, but it must not belong to a cluster.
-
For native Threat Defense devices, ensure there are at least as many used physical data and port channel interfaces (excluding "management-only" and subinterfaces) as those in the ASA device. Add required interfaces as needed.
-
For container instances, ensure there are at least as many used physical interfaces, physical subinterfaces, port channel interfaces, and port channel subinterfaces (excluding "management-only") as those in the ASA device. Add required interfaces as needed.