Migrate Palo Alto Networks Firewall to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control

This task enables you to migrate Palo Alto Networks firewall configurations to Secure Firewall Threat Defense using the Firewall Migration Tool, preserving your security policies while transitioning to Cisco's threat defense platform.

You can migrate configurations from your Palo Alto Networks firewall by choosing Palo Alto Networks (6.1+) in the Source Firewall Vendor drop-down and manually uploading the derived configuration file to Firewall Migration Tool. To read about the Palo Alto Networks firewall configurations that are supported for migration and the limitations around them, see Guidelines and Limitations in the Migrating Palo Alto Networks Firewall to Secure Firewall Threat Defense with the Migration Tool book.

Procedure


Step 1

Log in to your Security Cloud Control tenant, and in the left pane, click Administration > Migration > Firewall Migration Tool, and click the blue plus The Firewall Migration Tool interface displays options for migrating configurations from Palo Alto Networks Firewall to Secure Firewall Threat Defense, highlighting key features and steps in the migration process. button to start provisioning a new migration instance.

Step 2

Launch the migration instance from Security Cloud Control and choose Palo Alto Networks (6.1+).

Step 3

Export the Configuration File from your Palo Alto Networks Firewall.

To export the configuration from Palo Alto Networks Firewall, see Export the Configuration from Palo Alto Networks.

Step 4

Select the target threat defense device for migration.

In the Select Target page, the Cloud-Delivered Firewall Management Center provisioned on your Security Cloud Control tenant is selected by default, and the Firewall Threat Defense devices managed by that management center are listed. You can choose the Firewall Threat Defense device you wish to migrate the configuration to, and proceed with the migration.

Note that the threat defense devices listed are displayed either as In Use or Available based on whether the device is being used in another migration instance. However, you can perform an override by clicking Change Device Status, selecting the device from the In Use list, and clicking Continue, which will make the device available for being selected as the target. Choosing Proceed without FTD pushes only NAT objects, ACLs, and port objects to the Cloud-Delivered Firewall Management Center. For more information about the commonly used ASA features and their equivalent threat defense features, see Cisco Secure Firewall ASA to Threat Defense Feature Mapping guide.

Caution

Changing the device status from In Use to Available impacts the ongoing migration instance that is using the device already. We recommend that you exercise caution when doing this.

Changing the device status from In Use to Available affects the ongoing migration instance using the device. This diagram illustrates the impact of this status change on the migration process.

Step 5

Specify the destination parameters for the migration.

Step 6

Review the pre-migration report.

Navigate to where you downloaded the pre migration report and review the report. For detailed steps, see Review the Pre-Migration Report.

Step 7

Map PAN interfaces to threat defense interface objects, security zones, and interface groups.

To ensure that the PAN configuration is migrated correctly, map the PAN interfaces to the appropriate threat defense interface objects, security zones, and interface groups. For detailed steps, see Map PAN Firewall Configurations with Secure Firewall Management Center Threat Defense Interfaces.

Step 8

Map PAN interfaces to security zones.

For detailed steps, see Map PAN interfaces to security zones.

Step 9

Map PAN configuration to corresponding target applications.

For detailed steps, see Map Configurations with Applications.

Step 10

Optimize, review, and validate the configuration.

Optimize and review the configuration carefully and validate that it is correct and matches how you want to configure the threat defense device. For detailed steps, see Optimize, Review and Validate the Configuration to be Migrated.

Step 11

Push the migrated configuration to Cloud-Delivered Firewall Management Center.

This step in the migration process sends the migrated configuration to management center and allows you to download the post-migration report. For detailed steps, see Push the Migrated Configuration to Cloud-Delivered Firewall Management Center.

Step 12

Review the post-migration report.

Navigate to where you downloaded the post migration report and review the report. For detailed steps, see Review the Post-Migration Report and Complete the Migration.

Step 13

Deploy the migrated configuration from the Cloud-Delivered Firewall Management Center to threat defense.


Your Palo Alto Networks firewall configuration has been successfully migrated to Secure Firewall Threat Defense. The migrated configuration is now deployed and active on your target threat defense device.