Frequently Asked Questions
Q. |
What are the new features supported on Secure Firewall migration tool release 4.0? |
A. |
The following features are supported with release 4.0:
|
Q. |
What are the new features supported on Secure Firewall migration tool release 3.0.1? |
A. |
The following features are supported with release 3.0.1:
|
Q. |
What are the new features supported on Secure Firewall migration tool release 3.0? |
A. |
The following features are supported with release 3.0:
|
Q. |
What are the new features supported on Secure Firewall migration tool release 2.5.1? |
A. |
The following features are supported with release 2.5.1:
|
Q. |
What are the new features supported on Secure Firewall migration tool release 2.5? |
A. |
The following features are supported with release 2.5:
|
Q. |
What are the new features supported on Secure Firewall migration tool release 2.4? | ||||
A. |
The following ASA VPN configuration migration to threat defense:
|
||||
Q. |
What are the new features supported on Secure Firewall migration tool release 2.3.5? | ||||
A. |
The following features are supported with release 2.3.5:
|
||||
Q. |
What are the new features supported on Secure Firewall migration tool release 2.3.4? | ||||
A. |
The following features are supported with release 2.3.4:
|
||||
Q. |
What are the source and target platforms that the Secure Firewall migration tool can migrate policy? | ||||
A. |
The Secure Firewall migration tool can migrate policies from supported ASA platform to threat defense platform. For more information, see Supported Source ASA Platforms. |
||||
Q. |
What are the tasks that you must perform in the Pre-Migration and Post-Migration Reports? | ||||
A. |
To perform the tasks as part of your plan for migrating from ASA to Firewall Threat Defense, see Sample Migrtion: ASA to Threat Defense 2100. |
||||
Q. |
What are the supported destination platforms versions? | ||||
A. |
You can use the Secure Firewall migration tool to migrate an ASA configuration to the standalone or container instance of the Firewall Threat Defense platforms for management center 6.2.3 or later. For more information on the list of supported devices, see Supported Target Threat Defense Platforms. |
||||
Q. |
What are the features the Secure Firewall migration tool supports for migration? | ||||
A. |
The Secure Firewall migration tool supports migration of L3/L4 ASA configuration to threat defense. It also allows enabling L7 features like IPS, file policy, and so on, during the migration process. The Secure Firewall migration tool can fully migrate the following ASA configurations:
|
Q. |
What are the new features supported on the Secure Firewall migration tool for Release 2.2? | ||
A. |
The following features are supported with release 2.2:
|
||
Q. |
What are the new features supported on the Secure Firewall migration tool for Release 2.0? | ||
A. |
The following features are supported with release 2.0:
|
||
Q. |
Is there any dependency on management center to use the new features introduced in the Secure Firewall migration tool? | ||
A. |
Yes. The following features are supported with target management center 6.5 and later:
The following features are supported with target management center 6.6 and later:
The following features are supported with target management center 6.7 and later:
The following features are supported with target management center 7.1 and later:
|
Q. |
Can we migrate all the access rules in the source configuration to the Prefilter policy? |
A. |
No. For migrations that are opted with Migrate Tunnel rules as Prefilter, the Secure Firewall migration tool identifies tunneling protocol-based access rules and migrates them as tunnel rules. |
Q. |
What are the features the Secure Firewall migration tool does not migrate today? |
A. |
The Secure Firewall migration tool does not support the following ASA configurations for migration. If these configurations are supported in management center, you can configure them manually after the migration is complete.
For more information, see Guidelines and Limitations. |
Q. |
What are the supported source devices and code version? |
A. |
You can use the Secure Firewall migration tool to migrate the configuration from single or multi-context ASA platforms (software version 8.4 or later). For more information on the list of devices, see Supported Source ASA Platforms. |
Q. |
Does the Secure Firewall migration tool support migration of multi-context ASA? |
A. |
Yes. The Secure Firewall migration tool can handle migration of multi-context ASA. At any given point in time, one can migrate one context of the ASA (except for System context) to either threat defense container or native instances on the target management center. |
Q. |
What is the support mechanism if there are migration errors? |
A. |
The Secure Firewall migration tool is integrated with Cisco Success Network. If there are errors or issues, contact Cisco TAC. For troubleshooting, see Troubleshooting Migration Issues. |
Q. |
How much time does the Secure Firewall migration tool take to successfully migrate a configuration? |
A. |
The time that is taken during migration depends on numerous factors like latency on network, load on the management center, config size, number of objects, ACL, and so on. In internal testing, it was observed that a config file of 2.0 MB with 7000+ Access Control List, 7000+ NAT Translations, and 3000+ Network Objects takes around 6 minutes to successfully complete the migration. |