Best Practices for Threat Defense Device Migration
After a successful migration, we recommend that you perform the following actions before the deployment:
-
IP addresses of the interfaces are copied to the target device from the source device. Change the IP addresses of the target device interfaces, if the source device is live
-
Ensure that you update your NAT policies with the modified IP addresses.
-
Configure the interface speeds if they are set to default values after migration.
-
Re-enroll the device certificates, if any, on the target device.
-
For Firepower 1100 and 2100, if you have a HA setup, configure HA parameters such as monitored interfaces, failover trigger criteria, and interface MAC addresses.
-
Configure the diagnostic interface as it gets reset after migration.
-
(Optional) Configure SNMP for Firepower 1100 and 2100 using the platform settings for the device.
-
(Optional) Configure SNMP for Firepower 1100 and 2100 using the platform settings for the device.
-
(Optional) Configure remote branch deployment configurations.
If the source or target device had manager access through a data interface, after the migration, the manager access will be lost. Update the manager access configuration on the target device. For more information, see the Change the Manager Access Interface from Management to Data topic in the Cisco Secure Firewall Management Center Device Configuration Guide or the Online Help.
-
Configure site-to-site VPN, if required. These configurations are not migrated from the source device.
-
View the deployment preview before the deployment. Choose Deploy > Advanced Deploy and click the Preview (
) icon for the device.
- Monitor the health of the device in the health monitor (choose Troubleshooting > Health > Monitor). After migration, the health policy of the source device becomes the health policy of the target device. You can also configure a new health policy for the device.
After migration, the device monitoring dashboard may temporarily display redundant colored lines because the device has different UUIDs before and after migration. This redundancy appears only during the migration time. An hour after migration, the dashboard will show a single line per metric.