Guidelines and Limitations
Note | Configurations that are not supported in CDO will be dropped during migration as Unsupported and will be reported in the Migration Report. |
|
Feature or Function Name |
What Can be Migrated |
Restrictions or Limitations of Migration |
||
|---|---|---|---|---|
|
Firewall Modes |
Routed firewall mode |
Transparent mode configurations cannot be migrated. |
||
|
Interface Configurations |
|
|
||
| EtherChanels |
EtherChannels configured on physical interfaces. The member interfaces mapped to EtherChanels are retained during migration. |
|
||
| Routing |
Static routes |
|
||
|
Access Control Rules (ACLs) |
|
The following ACL features will not be migrated to FTD:
|
||
|
Network Address Translation (NAT) Rules |
|
The following NAT rules features will not be migrated to FTD:
|
||
|
Service Objects and Service Group Objects |
Service Objects and Nested Groups See Supported Protocols on CDO for the list of protocols used in services objects that CDO supports. |
|
||
|
Network Objects and Network Group Objects |
Network Objects and Network Group Objects |
The following network object or network group are unsupported:
|
||
|
ICMP Types |
ICMP Types |
The following ICMP types are unsupported:
|
||
|
Miscellaneous Unsupported Objects |
- |
The following miscellaneous objects are unsupported:
|
||
Site-to-Site VPN |
| The following Site-to-Site VPN features are not supported:
|
Note | Remote Access VPN is completely unsupported. |
For more information on Guidelines and Limitations, see Guidelines and Limitations for ASA Configurations and Guidelines and Limitations for Firepower Threat Defense Devices.