Learn about the device requirements and prerequisites for migrating Palo Alto Networks configurations to Cisco Secure Firewall Threat Defense.
When you migrate to the management center, it is not mandatory to have a target threat defense device added to it. You can migrate policies to a management center for future deployment to a threat defense device.
If threat defense device is added to the management center, before starting migration, ensure your target Firewall Threat Defense device meets these criteria:
-
Registration: The target Firewall Threat Defense device must be registered with the Management Center.
-
Configuration state:
-
Supports high availability (HA) configurations.
-
Supports standalone or container instances.
-
Restriction: Must not be part of a device cluster.
-
-
Interface mapping:
-
If using container instances, the Firewall Threat Defense must have a minimum interface count (physical, sub-interfaces, and port channels) equal to or greater than the source PAN device.
-
The Migration Manager supports mapping across different interface types (e.g., physical to port channel).
The Migration Manager does not create sub-interfaces; you must pre-configure them on the target.
During push migration, the Migration Manager automatically cleans and overwrites existing device-specific configurations (routes, interfaces, etc.). We highly recommend manual cleaning of the device prior to migration to avoid unintended data loss.
-