Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

PDF

Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

Obtain ASA configuration files

Want to summarize with AI?

Log in

Export the configuration file

Export the ASA configuration file to manually upload it to the Firewall Migration Manager for migration purposes.

This task is required only if you want to manually upload an configuration file. If you want to connect to and from the Firewall Migration Manager, skip to Connect to the ASA from the Secure Firewall Migration Manager.

Do not hand code or make changes to the configuration after you export the file. These changes will not be migrated, and they create errors in the migration or cause the migration to fail. For example, opening and saving the configuration file in terminal can add white space or blank lines that the Firewall Migration Manager cannot parse.

Ensure that the exported configuration file does not contain the --More-- keyword as text, because this can cause the migration to fail.

Procedure

1.

Use the show running-config command for the ASA device or context that you are migrating and copy the configuration from there.

See View the Running Configuration section in Cisco Secure Firewall ASA Series General Operations CLI Configuration Guide.

Alternately, use Adaptive Security Device Manager (ASDM) for the ASA device or context that you want to migrate and choose File > Show Running Configuration in New Window to obtain the configuration file.

Note

For a multi context, you can use the show tech-support command to obtain the configuration for all the contexts in a single file.

2.

Save the configuration as either .cfg or .txt.

You cannot upload the configuration to the Firewall Migration Manager if it has a different extension.

3.

Transfer the configuration file to your computer where you downloaded the Firewall Migration Manager.


Connect to the ASA from Firewall Migration Manager

Enable Firewall Migration Manager to retrieve configuration data from an ASA device for migration to Secure Firewall Threat Defense.

Use Firewall Migration Manager to access an ASA device and extract all necessary configuration information for migrating to Secure Firewall Threat Defense.

Before you begin

  • For a single-context ASA, obtain the management IP address, administrator credentials, and enable password.

  • For a multi-context ASA, obtain the IP address for the admin context, administrator credentials, and enable password.

    Note

    If the ASA does not have an Enable Password, you can leave that field blank in Firewall Migration Manager.

Procedure

1.

On the Select firewalls window, choose Live Connect option in the Select configuration extraction method area.

2.

Enter the IP Address/Hostname/FQDN of the ASA:

  • For single-context ASA, enter the management IP address or hostname.

  • For multi-context ASA, enter the IP address or hostname of the admin context.

3.

Enter the administrator credentials in the Connect to Firewall dialog box:

  • Fill in the Username, Password, and Enable Password fields.

  • If the ASA does not have an Enable password configured, leave that field blank.

4.

(Optional) Select the HitCount option to compute and display rule usage statistics, which helps evaluate rule effectiveness before migration.

This allows you to evaluate the efficacy and relevance of the rule before migration.

5.

Click Connect & extract configuration.

  • Firewall Migration Manager connects to the ASA and extracts its configuration.

  • Once extraction completes, the system identifies if your ASA uses single-context or multi-context mode and displays the available contexts for migration.

What to do next

Specify the Firewall Threat defense device details in Target information section. See, Specify destination parameters.