Migrate Microsoft Azure Native Firewall with the Firewall Migration Tool in Security Cloud Control

This task allows migrating configurations from Azure firewall to threat defense devices managed by your Cloud-Delivered Firewall Management Center. You can manually derive the configuration file from your Azure firewall and upload it to the migration tool to begin your migration.

The Firewall migration tool in Security Cloud Control enables configuration upload, target selection, validation, and deployment. To learn about supported Azure firewall configurations, see Azure Configuration Support.

Procedure


Step 1

On the Select Source Configuration page, choose Microsoft Azure and click Start Migration.

Step 2

Click Upload to choose the Azure configuration file and click Next.

Step 3

In the Select Target page, select the Cloud-Delivered Firewall Management Center provisioned on your Security Cloud Control tenant.

The threat defense devices managed by that management center are listed. You can choose the threat defense device you wish to migrate the configuration to, and proceed with the migration.

The threat defense devices listed are displayed either as In Use or Available based on whether the device is being used in another migration instance. However, you can perform an override by clicking Change Device Status, selecting the device from the In Use list, and clicking Continue, which will make the device available for being selected as the target. Choosing Proceed without FTD pushes only NAT objects, ACLs, and port objects to the Cloud-Delivered Firewall Management Center. For more information about the commonly used ASA features and their equivalent threat defense features, see Cisco Secure Firewall ASA to Threat Defense Feature Mapping guide.

Caution

Changing the device status from In Use to Available impacts the ongoing migration instance that is using the device already. We recommend that you exercise caution when doing this.

The flowchart that follows illustrates the step-by-step procedure for migration of Azure firewall configurations to threat defense devices:

To perform the procedure with more detailed steps, continue to Export the Configuration from Microsoft Azure Native Firewall in Migrating Microsoft Azure Native Firewall to Cisco Secure Firewall Threat Defense with the Migration Tool guide.

Fortinet firewall to multicloud defense End-to-End migration
The diagram illustrates the end-to-end migration process from a Fortinet firewall to a multicloud defense setup, highlighting key steps and components involved in the migration workflow.

Workspace

Steps

The Firewall Migration Tool interface displays the steps required to migrate a Microsoft Azure Native Firewall, including configuration options and progress indicators.

Security Cloud Control

Log in to your Security Cloud Control tenant, and in the left pane, click Administration > Migration > Firewall Migration Tool and click the blue plus The Firewall Migration Tool interface displays options for provisioning a new migration instance in Microsoft Azure. button to start provisioning a new migration instance.

The Firewall Migration Tool interface displays options for migrating a Microsoft Azure Native Firewall, including the Launch button and selection for Azure.

Security Cloud Control

After your migration instance is ready, click Launch and choose Microsoft Azure.

The Azure Firewall Migration Tool interface displays options for launching the migration process and exporting the Azure configuration to a local system.

Azure Firewall

Export the Azure configuration to the local system. To export the configuration from Azure firewall, see Export the Configuration from Microsoft Azure Native Firewall.

The Firewall Migration Tool facilitates the transfer of Azure Firewall configurations to a secure environment, ensuring a smooth migration process.

Secure Firewall Migration Tool

Upload the Azure configuration file exported from Azure firewall, see Upload the Microsoft Azure Configuration File.

The Secure Firewall Migration Tool interface displays options for uploading the Azure configuration file and specifying destination parameters for the migration process.

Secure Firewall Migration Tool

In this step, you can specify the destination parameters for the migration. For detailed steps, see Specify Destination Parameters for the Secure Firewall Migration Tool.

The Secure Firewall Migration Tool interface displays options for specifying destination parameters during the migration process.

Secure Firewall Migration Tool

Navigate to where you downloaded the pre migration report and review the report. For detailed steps, see Review the Pre-Migration Report.

The Secure Firewall Migration Tool interface displays options for reviewing and optimizing the pre-migration report, ensuring the configuration aligns with the desired settings for the threat defense device.

Secure Firewall Migration Tool

Optimize and review the configuration carefully and validate that it is correct and matches how you want to configure the threat defense device. For detailed steps, see Optimize, Review and Validate the Configuration to be Migrated.

The Secure Firewall Migration Tool interface displays options for optimizing, reviewing, and validating the configuration before sending it to the management center. It also includes a feature to download the post-migration report.

Secure Firewall Migration Tool

This step in the migration process sends the migrated configuration to management center and allows you to download the post-migration report. For detailed steps, see Push the Migrated Configuration to Management Center.

The Secure Firewall Migration Tool sends the migrated configuration to the management center and enables the download of the post-migration report.

Local Machine

Navigate to where you downloaded the post migration report and review the report. For detailed steps, see Review the Post-Migration Report and Complete the Migration.

The post-migration report provides an overview of the migration process for the Microsoft Azure Native Firewall, detailing the steps taken and any issues encountered during the migration.

Cloud-Delivered Firewall Management Center

Deploy the migrated configuration from the Cloud-Delivered Firewall Management Center to threat defense.


The Microsoft Azure Native Firewall configuration is successfully migrated to Secure Firewall Threat Defense, with the configuration validated and deployed through the Firewall Migration Tool.