Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

PDF

Migrating Cisco Secure Firewall ASA to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

Retrieve AnyConnect packages and profiles

Want to summarize with AI?

Log in

Configure AnyConnect packages and profiles retrieval from ASA devices to prepare for Remote Access VPN migration.


This task enables you to retrieve essential AnyConnect packages and profiles from source ASA devices for use in Remote Access VPN migration to the management center.

AnyConnect profiles are optional and can be uploaded through the management center or Firewall Migration Manager.

Before you begin

  • Remote Access VPN on the management center requires at least one AnyConnect package.

  • If the configuration consists of Hostscan and External Browser package, you must upload these packages.

    All packages must be added to the management center as part of the pre-migration activity.

  • Dap.xml and Data.xml must be added through the Firewall Migration Manager.

Procedure

1.

Use the following command to copy the required package from the source ASA to an FTP or TFTP server:

Copy <source file location:/source file name> <destination>
ASA# copy disk0:/anyconnect-win-4.10.02086-webdeploy-k9.pkg tftp://1.1.1.1 <----- Example of copying Anyconnect Package.
ASA# copy disk0:/ external-sso- 4.10.04071-webdeploy-k9.zip tftp://1.1.1.1 <----- Exampleof copying External Browser Package.
ASA# copy disk0:/ hostscan_4.10.04071-k9.pkg tftp://1.1.1.1 <----- Example of copying Hostscan Package.
ASA# copy disk0:/ dap.xml tftp://1.1.1.1. <----- Example of copying Dap.xml
ASA# copy disk0:/ sdesktop/data.xml tftp://1.1.1.1 <----- Example of copying Data.xml
ASA# copy disk0:/ VPN_Profile.xml tftp://1.1.1.1 <----- Example of copying Anyconnect Profile.
2.

Import the downloaded packages to management center (Object Management > VPN > AnyConnect File).

  1. Dap.xml and Data.xml must be uploaded to the management center from the Firewall Migration Manager in the Review and Validate > Remote Access VPN > AnyConnect File section.

  2. AnyConnect profiles can be uploaded directly to the management center or through the Firewall Migration Manager in the Review and Validate > Remote Access VPN > AnyConnect File section.

    The manually uploaded files can now be used in the Firewall Migration Manager.