Migrate FTD 7.4 HA pair to a New FMC

 Migrate FTD 7.4 HA pair to a New FMC


FTD-74-A and FTD-74-B are deployed in an HA pair and currently managed by FMC-1. The objective is to migrate both FTDs to FMC-2.

Note:
Review the connection between FMC-2 and FTDs. If FMC-2 is remote, ensure the FTD use Data interface to 
establish the sftunnel to FMC-2, and avoid having sftunnel traffic traverse the S2S VPN on the FTD.

1. Prepare and Reassign FTD

  • Remove the existing manager (FMC-1) from both FTD-74-A and FTD-74-B.

  • 2. Register Devices on FMC-2

  • On FMC-2, register FTD-74-A and assign the “Initial Discovery ACP”.
  • FMC-2 should detect that FTD-74-A is part of an HA pair and automatically create the HA configuration.
  • FMC-2 will then attempt to automatically register FTD-74-B.
    • If the HA registration fails, FMC-2 will unregister FTD-74-A.

    •  If the process is successful, both FTDs will appear in FMC-2 as an HA pair.



    3. Post‑Migration Configuration

  • Reassign interfaces to the appropriate security zones.
  • Restore default routing.
  • Apply the correct Access Control Policy (ACP).
    • The ACP can be exported or recreated from FMC-1, if required.

  • Note: Exporting VPN-related configuration is not supported. We need to manually reconfigure the VPN on the FMC2 (target FMC) after the device registration


    References:


    Migrate FTD HA (Failover) to Another FMC

    https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222869-migrate-ftd-ha-failover-to-another-fmc.html


    Migrate an FTD from One FMC to another FMC

    https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/222480-migrate-an-ftd-from-one-fmc-to-another-f.html

















    Comments