Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

PDF

Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

Threat Defense device prerequisites for ASA migration

Want to summarize with AI?

Log in

Describes the requirements and prerequisites to follow when you migrate ASA configurations to your Threat Defense device and management center, ensuring the migration is successful.


To successfully migrate ASA configurations to a Threat Defense device managed by the management center, consider the following requirements:

  • You do not need to add the target Threat Defense device to the management center before migration. You can migrate policies to the management center for future deployment to a Threat Defense device.

  • If a Threat Defense device is added to the management center, the target device must be registered with the management center.

  • The target Threat Defense device can be configured for high availability.

  • The Threat Defense device can be standalone or a container instance, but it must not be part of a cluster.

  • For native Threat Defense devices, ensure there are at least as many used physical data and port channel interfaces (excluding "management-only" and subinterfaces) as those in the ASA device. Add required interfaces as needed.

  • For container instances, ensure there are at least as many used physical interfaces, physical subinterfaces, port channel interfaces, and port channel subinterfaces (excluding "management-only") as those in the ASA device. Add required interfaces as needed.