Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

PDF

Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

Obtain ASA configuration files

Want to summarize with AI?

Log in

Learn how to acquire ASA configuration files for migration to Secure Firewall by manually exporting the configuration or using the live connection method in the Firewall Migration Manager.


You can use one of the following methods to obtain a configuration file:


Export the configuration file

Export the ASA configuration file to manually upload it to the Firewall Migration Manager for migration purposes.

Perform this task only if you want to manually upload a configuration file for migration. If you prefer to connect directly to ASA and from Firewall Migration Manager, skip to Connect to the ASA from the Secure Firewall Migration Manager.

Do not manually edit or modify the configuration file after export. Such changes are not migrated and may create errors in the migration process or cause it to fail. For example, opening and saving the configuration file in a terminal can add extra white space or blank lines that the Firewall Migration Manager cannot parse.

Also, ensure the file does not include the --More-- keyword, which would cause migration failure.

Procedure

1.

Use the show running-config command on the ASA device or context that you are migrating and copy the configuration from there.

Refer to View the Running Configuration section in Cisco Secure Firewall ASA Series General Operations CLI Configuration Guide.

Alternatively, use Adaptive Security Device Manager (ASDM) for the ASA device or context that you want to migrate and click File > how Running Configuration in New Window to obtain the configuration file.

Note

For a multi-context device, use the show tech-support command to obtain the configurations for all contexts in a single file.

2.

Save the configuration file as a .cfg or .txt file.

You cannot upload configuration files with other extensions to Firewall Migration Manager.

3.

Transfer the exported configuration file to your computer, ensuring it's accessible where the Firewall Migration Manager is installed.


Connect to the ASA from Firewall Migration Manager

Enable Firewall Migration Manager to retrieve configuration data from an ASA device for migration to Secure Firewall Threat Defense.

Use Firewall Migration Manager to access an ASA device and extract all necessary configuration information for migrating to Secure Firewall Threat Defense.

Before you begin

  • For a single-context ASA, obtain the management IP address, administrator credentials, and enable password.

  • For a multi-context ASA, obtain the IP address for the admin context, administrator credentials, and enable password.

    Note

    If the ASA does not have an Enable Password, you can leave that field blank in Firewall Migration Manager.

Procedure

1.

On the Select firewalls window, choose Live Connect option in the Select configuration extraction method area.

2.

Enter the IP Address/Hostname/FQDN of the ASA:

  • For single-context ASA, enter the management IP address or hostname.

  • For multi-context ASA, enter the IP address or hostname of the admin context.

3.

Enter the administrator credentials in the Connect to Firewall dialog box:

  • Fill in the Username, Password, and Enable Password fields.

  • If the ASA does not have an Enable password configured, leave that field blank.

4.

(Optional) Select the HitCount option to compute and display rule usage statistics, which helps evaluate rule effectiveness before migration.

This allows you to evaluate the efficacy and relevance of the rule before migration.

5.

Click Connect & extract configuration.

  • Firewall Migration Manager connects to the ASA and extracts its configuration.

  • Once extraction completes, the system identifies if your ASA uses single-context or multi-context mode and displays the available contexts for migration.

What to do next

Specify the Firewall Threat defense device details in Target information section. See, Specify destination parameters.