Onboard a device with a CLI registration key

This task enables you to onboard a Firewall Threat Defense device to Cloud-Delivered Firewall Management Center using a CLI registration key method, allowing for remote management and policy deployment to the device.

Use this procedure to onboard a device for Cloud-Delivered Firewall Management Center with a CLI registration key.

Note

If your device is currently managed by an On-Premises Firewall Management Center, onboarding the device will fail. You can either delete the device from the On-Premises Firewall Management Center and onboard as a fresh, new device with no policies or objects, or you can migrate the device and retain the existing policies and objects. See Migrate FTD to Cloud-Delivered Firewall Managmenet Center for more information.

Important

You can create a Security Cloud Control-managed, standalone logical Firewall Threat Defense device using the Secure Firewall chassis manager or the FXOS CLI.

Before you begin

Before you onboard a device, be sure to complete these tasks:

Follow these steps to onboard a device with a CLI registration key:

Procedure


Step 1

In the left pane, click Security Devices.

Step 2

Click Onboard device or service (The image illustrates the process of onboarding a device using a CLI registration key, highlighting the selection of FTD under Management Mode and the implications for existing policy configurations.) icon.

Step 3

Click the FTD tile.

Step 4

Under Management Mode, select FTD.

By selecting FTD under Management Mode, you will not be able to manage the device using the previous management platform. All existing policy configurations except for interface configurations will be reset. You must re-configure policies after you onboard the device.

Step 5

Select Use CLI Registration Key as the onboarding method.

Step 6

Enter the device name in the Device Name field and click Next.

Step 7

In the Policy Assignment step, use the drop-down menu to select an access control policy to deploy once the device is onboarded.

If you have no policies configured, select the Default Access Control Policy.

Step 8

Specify whether the device you are onboarding is a physical or virtual device.

If you are onboarding a virtual device, you must select the device's performance tier from the drop-down menu.

Step 9

Select the subscription licenses you want to apply to the device and click Next.

Step 10

Security Cloud Control generates a command with the registration key. Connect to the device you are onboarding using SSH, log in as "admin" or a user with equivalent admin privileges and paste the entire registration key as is into the device's CLI.

Note: For Firepower 1000, Firepower 2100, ISA 3000, and Firewall Threat Defense Virtual devices, open an SSH connection to the device and log in as admin . Copy the entire registration command and paste it into the device's CLI interface at the prompt. In the CLI, enter Y to complete the registration. If your device was previously managed by Firewall Device Manager, enter Yes to confirm the submission.

Step 11

Click Next in the Security Cloud Control onboarding wizard.

Step 12

(Optional) Add labels to your device to help sort and filter the Security Devices page.

Enter a label and select the blue plus button. Labels are applied to the device after it's onboarded to Security Cloud Control.

Once the device is synchronized, select the device you just onboarded from the Security Devices page and select any of the options listed under the Device Management pane located to the right. We strongly recommend these actions:

  • If you did not already, create a custom access control policy to customize the security for your environment. See Access Control Overview in Managing Firewall Threat Defense with Cloud-Delivered Firewall Management Center in Security Cloud Control for more information.

  • Enable Cisco Security Analytics and Logging (SAL) to view events in the Security Cloud Control dashboard or register the device to an Secure Firewall Management Center for security analytics. See Cisco Security Analytics and Logging in Managing Firewall Threat Defense with Cloud-Delivered Firewall Management Center in Security Cloud Control for more information.


The device is successfully onboarded to Cloud-Delivered Firewall Management Center and appears in the Security Devices page. The selected access control policy is deployed to the device, and any configured labels are applied for device management and filtering.