Migrating Palo Alto Networks Firewall to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

PDF

Migrating Palo Alto Networks Firewall to Cisco Secure Firewall Threat Defense Using Firewall Migration Manager

Device readiness and requirements

Want to summarize with AI?

Log in

Learn about the device requirements and prerequisites for migrating Palo Alto Networks Firewall configurations to Firewall Threat Defense.


When you migrate to the Firewall Management Center, it is not mandatory to have a target Firewall Threat Defense device added to it. You can migrate policies to a Firewall Management Center for future deployment to a Firewall Threat Defense device.

If Firewall Threat Defense device is added to the Firewall Management Center, before starting migration, ensure your target Firewall Threat Defense device meets these criteria:

  • Registration: The target Firewall Threat Defense device must be registered with the Firewall Management Center.

  • Configuration state:

    • Supports high availability (HA) configurations.

    • Supports standalone or container instances.

    • Restriction: The target Firewall Threat Defense device must not be part of a device cluster.

  • Interface mapping:

    • If using container instances, the Firewall Threat Defense device must have a minimum interface count (physical, sub-interfaces, and port channels) equal to or greater than the source Palo Alto Networks Firewall device.

    • The Firewall Migration Manager supports mapping across different interface types such as physical interfaces to port channel interfaces.

    Note

    The Firewall Migration Manager does not create sub-interfaces for target multi-instance Firewall Threat Defense devices. You must pre-configure them on the target device.

    Warning

    During the push migration, the Firewall Migration Manager automatically cleans and overwrites existing device-specific configurations (routes, interfaces, and so on). We highly recommend manual cleaning of the device prior to migration to avoid unintended data loss.