Migrate FTD 7.4 HA pair to a New FMC
FTD-74-A and FTD-74-B are deployed in an HA pair and currently managed by FMC-1. The objective is to migrate both FTDs to FMC-2.
Note:
Review the connection between FMC-2 and FTDs. If FMC-2 is remote, ensure the FTD use Data interface to
establish the sftunnel to FMC-2, and avoid having sftunnel traffic traverse the S2S VPN on the FTD.
1. Prepare and Reassign FTD
2. Register Devices on FMC-2
- If the HA registration fails, FMC-2 will unregister FTD-74-A.
3. Post‑Migration Configuration
- The ACP can be exported or recreated from FMC-1, if required.
Note: Exporting VPN-related configuration is not supported. We need to manually reconfigure the VPN on the FMC2 (target FMC) after the device registration
References:
Migrate FTD HA (Failover) to Another FMC
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222869-migrate-ftd-ha-failover-to-another-fmc.html
Migrate an FTD from One FMC to another FMC
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222480-migrate-an-ftd-from-one-fmc-to-another-f.html
Comments
Post a Comment