HomeCloud ComputingCisco Reside for You: Migration to Cisco Safe Firewall

Cisco Reside for You: Migration to Cisco Safe Firewall


Seamless Transition: Mastering Migration to Cisco Safe Firewall

Firewall migration is usually seen as a fancy activity that requires downtime and different operational disruptions. At Cisco Reside APJC, Principal Engineer Raghu Kulkarni, an nearly 15-year Cisco veteran, goals to shift this attitude. Kulkarni demonstrates that transitioning to Cisco Safe Firewall is a simple and manageable course of when particular actions are addressed proactively. Within the session, Kulkarni explains the three phases to Firewall migration, illustrating that not all migration actions have to be carried out throughout downtime, which is what most prospects concern. In actual fact, Kulkarni particulars that round 95% of the method may be staged earlier than the precise migration happens.

Earlier than diving into the migration course of, let’s check out three useful questions that Kulkarni solutions throughout this session:

  • What are the instruments accessible for migration? How does Cisco’s Firewall Administration Device (FMT) particularly ease the migration course of?
  • What are the pre-checks that may be carried out earlier than migration happens?
  • When you’ve got current Firepower units which have reached finish of life, and they’re managed via the Firepower Administration Middle (FMC), how can their configurations be migrated to newer {hardware}?

Getting began with the migration course of

To be able to guarantee a seamless transition, there are two duties that must be accomplished even earlier than the pre-migration section. Firstly, it’s essential to establish stakeholders who shall be impacted by migration or who must validate the brand new firewall atmosphere, corresponding to software house owners and testing groups. Overlooking particular software testing wants might result in problems in post-migration.

Secondly, Kulkarni discusses the significance of staging the atmosphere for readiness. This course of entails establishing all the mandatory elements earlier than the migration course of begins. Key parts embody:

  • Provisioning the FMC, whether or not on-prem or digital
  • Making ready the brand new Firepower Risk Protection (FTD) {hardware}
  • Making certain the FMT is downloaded, put in, and suitable

Key issues for pre-migration actions

As Kulkarni mentions in his introduction, the pre-migration section is the place many of the work occurs, considerably decreasing cutover downtime. Cisco’s FMT guides customers via configuration extraction, enabling selective migration of options like entry management lists, community objects, routes, and interfaces. Most significantly, the instrument gives optimization capabilities to establish and resolve points with unreferenced objects or redundant safety guidelines, stopping a bloated configuration.

The total course of carried out by the FMT is as follows:

  • Extract Configuration Data
  • Choose Goal(s)
  • Map FTD Interface
  • Map Safety Zones
  • Utility Mapping
  • Optimize, Overview & Validate
  • Full Migration

Furthermore, when it comes to pre-cutover validation, the FMC’s Packet Tracer permits for replaying packet captures to simulate software habits, whereas Safety Cloud Management gives greatest apply suggestions. Collectively, these options and actions present customers with confidence that their migration course of is performing as anticipated. Kulkarni constantly stresses the significance of those options as decreasing complexity and limiting cutover downtime.

After completion of the pre-migration course of, the FMT offers a complete pre-migration report offering key insights into the next areas: configuration traces with error and ignored or unreferenced parts. These components are crucial in understanding and resolving points earlier than deployment, and highlighting configurations that weren’t migrated as a result of irrelevance or lack of help.

Submit-migration course of and migration completion

As soon as the excellent pre-migration work is full, the FMT initiates the configuration push to the FMC. That is the primary time the FMT actively communicates with the FMC to deploy the optimized configuration. Upon completion, the FMT generates a post-migration report, offering a abstract of things corresponding to: configurations which were efficiently migrated, configurations that might not be migrated, or any manually chosen parts that had been chosen to not be migrated.

This abstract is invaluable for evaluating with the pre-migration report, highlighting variations and validating the migration’s success. Extra particulars on the configuration push and the post-migration course of may be discovered right here.

Study extra by watching the complete session

Kulkarni demonstrates that the transition to Cisco Safe Firewall may be easy when contemplating crucial actions, utilizing Cisco’s migration instruments, and guaranteeing validation and optimization at each step. Firewall migration doesn’t should be a fancy and daunting activity, and Cisco strives to verify this notion.

If you wish to study extra about Cisco Safe Firewall, or watch Raghu Kulkarni’s full session, comply with the hyperlinks under.

 

Cisco Safe Firewall | Firewall Migration Device | AIOps for Cisco Safe Firewall

 

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments