Onboard Devices to Cloud-Delivered Firewall Management Center Device Management Manage Devices Migrate Firewall Threat Defense Devices Guidelines and Limitations for Migration

Last updated: Aug 18, 2025

Guidelines and Limitations for Migration

Guidelines

  • For devices in multi-instance mode:

    During migration, ensure that you map the interfaces according to the table below:

    Source Device

    Target Device

    Physical interface

    Physical interface

    EtherChannel interface

    EtherChannel interface

    Supervisor-provisioned subinterface​

    Supervisor-provisioned subinterface​

    Tagged interface

    Tagged interface

    Untagged interface

    Untagged interface

    Shared interface

    Shared and dedicated interface

    Dedicated interface

    Dedicated interface

    You cannot map a supervisor-provisioned subinterface to a subinterface created by an instance.​

  • For HA devices, you can migrate:

    • Source HA device to target HA device.

    • Source HA device to target standalone device.

  • For devices in remote branch deployment:

    • Map the source manager access interface to the target manager access interface.

    • Ensure that the manager access interfaces of the source and target Firewall Management Centers are of the same IP address type (static or DHCP).

    • Both manager access interfaces must have IPv4 or IPv6 addresses.

    • If the manager access interfaces have static IP addresses, ensure that they are in the same subnet.

  • For Snort:

  • For devices using diagnostic interfaces:

    Only merged management interfaces are available on the target devices after migration.

Limitations

  • The migration wizard does not migrate:

    • Site-to-site VPN policies

    • SNMP device configurations for Firepower 2100 Series

      After the migration, you can configure SNMP using the platform settings for the device.

  • You can perform only one migration at a time.

  • Remote access VPN trustpoint certificates are not enrolled after migration.

  • For HA devices:

    • Target device: You cannot migrate a standalone device to an HA device.

  • Clustering is not supported.

  • For devices in remote branch deployment:

    • The wizard does not migrate a single WAN manager access data interface to a dual WAN manager access data interface.