Onboarding methods
Onboarding is a device management process that
-
connects Firewall Threat Defense devices to Cloud-Delivered Firewall Management Center for centralized management
-
supports multiple methods including registration key and Zero-Touch Provisioning, and
-
enables policy configuration and device monitoring through the management platform.
Onboarding requirements and compatibility
Review these use cases and supported software versions that are compatible with Cloud-Delivered Firewall Management Center management.
Note | You must ensure that the Firewall Threat Defense device ports have external and outbound access for the Cloud-Delivered Firewall Management Center to onboard them. There is no requirement for an on-premises or cloud-based Security Device Controller (SDC) for this operation. For more information, see Network Requirements. To send Firewall Threat Defense Syslog events to the Cisco cloud, you can set up the Secure Event Connector (SEC). For more information, see Installing Secure Event Connectors. |
Firewall Threat Defense devices currently managed by Cloud-Delivered Firewall Management Center
These scenarios occur when you either move or migrate a device to the Cloud-Delivered Firewall Management Center:
-
If you delete a device from an On-Premises Firewall Management Center or Secure Firewall Threat Defense Firewall Device Manager to onboard to the Cloud-Delivered Firewall Management Center, the change of managers wipes any policies configured through the On-Premises Firewall Management Center.
-
If you migrate a device from an On-Premises Firewall Management Center to the Cloud-Delivered Firewall Management Center, the device retains the majority of your previously configured policies.
Note | If you do not know if your device is already managed by an alternative manager, use the show managers command in the device's CLI. |
Onboarding methods
Cloud-Delivered Firewall Management Center supports these onboarding methods:
-
Registration Key - Onboard a device with a registration key. The initial device setup wizard is complete on the device.
-
Zero-Touch Provisioning - Onboard a new factory-shipped device with its serial number. Note that this method only supports Firepower 1000, Firepower 2100, or Secure Firewall 3100 devices.
-
Zero-Touch Provisioning using a device template - Onboard new factory-shipped devices using serial numbers and a device template. Note that this method only supports Firepower 1000, Firepower 2100, Secure Firewall 1200 or Secure Firewall 3100 devices.