Managing On-Premises Firewall Management Center with Security Cloud Control

About On-Premises Firewall Management Center

On-Premises Firewall Management Center is a centralized management console with graphical user interface. You can use it to perform administrative, management, analysis, and reporting tasks. This console is similar to ASDM and FDM but differs in certain features.

On-Premises Firewall Management Center support is limited to onboarding, viewing its managed devices, viewing, managing network objects, and cross launching to the on-premises Firewall Management Center UI for managing associated devices and objects. Additional features will be available soon. If a feature is not supported by Security Cloud Control at this time, use the on-premises Firewall Management Center console. To learn more about the features provided by on-premises Firewall Management Center, see Cisco Secure Firewall Management Center Configuration Guide for your system's version.

For a list of on-premises Firewall Management Center devices and software versions that Security Cloud Control supports, see Software and Hardware support by Security Cloud Control.

Version Support

Security Cloud Control supports version 6.4 and later. On-Premises Firewall Management Center can manage older devices, typically a few major versions back. For example, devices running version 6.6.0 can manage devices running version 6.4.0. If an on-premises Firewall Management Center manages a device that is running a version earlier than 6.4, the device may be displayed in the Security Devices page, but cannot be deployed to or its policies modified from Security Cloud Control. You must make changes and deploy from the on-premises Firewall Management Center UI.

Note

If a managed device is disabled, or unreachable, Security Cloud Control may display the device in the Security Devices page, but cannot successfully send requests or view device information.

How does Security Cloud Control Communicate with an FMC

Security Cloud Control acts as a REST API client to send requests to on-premises Firewall Management Center, and then on-premises Firewall Management Center uses its designated client to channel the requests to its managed devices.

As the device does not allow multiple logins with the same credentials, you must create a new user on the on-premises Firewall Management Center specifically for Security Cloud Control communication. This user must have administrator level permissions. This new user will have to be replicated on Security Cloud Control, as either a Security Cloud Control-provided Administrator or a custom user role with system and devices permissions. Without an admin login, Security Cloud Control cannot use REST API commands to modify or create policies, rules, or objects.

Onboard or Remove an On-Premises Firewall Management Center

You can onboard or remove an on-premises Firewall Management Center at any time. On-Premises Firewall Management Center and its registered devices must be running at least version 6.4 to be read by Security Cloud Control. To onboard an on-premises Firewall Management Center and its registered devices, see Onboard an FMC.

Once an on-premises Firewall Management Center is onboarded, select the on-premises Firewall Management Center from Administration > Integrations > Firewall Management Center and click Devices under Management or any actions on the right pane to open up the Verify FMC Cross Launch URL wizard, which lets you enter the public IP address or the FQDN and the port number of your management center. Click Continue to cross launch to the selected on-premises Firewall Management Center web UI in a new tab using the IP address you entered. You can also add external links manually using the Add External Links option under External Links on the right pane.

Removing an on-premises Firewall Management Center from your Security Cloud Control tenant also removes the devices registered to that on-premises Firewall Management Center. See Remove an FMC from Security Cloud Control for more information.

If an on-premises Firewall Management Center experiences an "Invalid Credentials" status after onboarding, you can reconnect the appliance. See Troubleshoot Invalid Credentials for more information.

Note

Devices running Firewall 6.6 do not support the reconnect feature. If you have to reconnect the appliance, we recommend removing the on-premises Firewall Management Center and re-onboarding the appliance.

Devices Managed by an On-Premises Firewall Management Center

Once you onboard an on-premises Firewall Management Center to Security Cloud Control, all the devices registered to that on-premises Firewall Management Center are also imported into Security Cloud Control. On the Security Devices page, you can view device information such as name, IP address, device type, software version, and state. Note that your on-premises Firewall Management Center is displayed on the Services page and the devices it manages are listed on the Security Devices page. In the Services page, you can see information such as version, devices managed, device type, and status. Clicking the devices icon on the Services page, which shows the number of devices your FMC manages, directs you to the Security Devices page with a filter applied to display all devices managed by the selected on-premises Firewall Management Center.

You can perform actions using options in the Device Actions, Monitoring, Device Management, and Policies panels available from the Security Devices page. If you select a device that is currently managed by an FMC and click these options, Security Cloud Control automatically launches the on-premises Firewall Management Center console that manages the devices using the cross-launch URL you had entered. Use the filter icon to further organize the Security Devices page. From this page, you can view all the devices managed by the onboarded on-premises Firewall Management Center and other supported device types. In addition, you can expand or collapse devices in a cluster and select them individually or as a group to perform actions.

Device Health Status

Security Cloud Control displays the health status of threat defense devices on the Security Devices page, such as Normal, Error, Warning, and Disabled. You can click the status of a device to navigate to the Health Monitoring page that corresponds to the device in the on-premises Firewall Management Center UI.

Note

Security Cloud Control automatically updates the device health status every 10 minutes. You can also do this manually by selecting the device and clicking Check for Changes.

Manage Security Policies in Security Cloud Control

Security policies examine network traffic with the ultimate goal of allowing the traffic to its intended destination or dropping it if a security threat is identified. You can use Security Cloud Control to configure security policies on many different types of devices.

Objects

After you onboard an on-premises Firewall Management Center to Security Cloud Control, you can choose to discover objects from on-premises Firewall Management Center and manage them in Security Cloud Control. You can do this by choosing Administration > Integrations > Firewall Management Center, selecting the desired on-premises Firewall Management Center, and clicking Settings. You can enable the Discover & Manage Network Objects toggle button. When this option is enabled, Security Cloud Control automatically imports all the objects from the On-Premises Firewall Management Center-managed devices into Security Cloud Control. Once imported, the objects can be managed from Security Cloud Control. Note that you must have the super admin or admin user role to be able to use the Settings button.

When making a configuration change to an object from Security Cloud Control, the change gets staged in Security Cloud Control and you can manually push the change to the on-premises Firewall Management Center after reviewing it from Pending Changes. When you make a configuration change to an object from the on-premises Firewall Management Center UI, Security Cloud Control detects that change as an out-of-band change that can be synchronized later. If you want your changes to be automatically synchronized with on-premises Firewall Management Center and not staged for review, enable the Enable automatic sync of network objects toggle button.

If you have existing objects in Security Cloud Control that you want to assign to your on-premises Firewall Management Center, select the on-premises Firewall Management Center from the Services page and choose Assign Objects on the right pane. Security Cloud Control displays all the existing objects and lets you select ones that you want to associate with the on-premises Firewall Management Center that you selected. This helps ensure consistent network object definitions across platforms managed by Security Cloud Control. Note that you can use the Assign Objects button only if Discover & Manage Network Objects is enabled for the selected on-premises Firewall Management Center.

Note
  • You cannot enable the Discover & Manage Network Objects toggle button if the on-premises Firewall Management Center that you have selected has one or more child domains or has the Change Management workflow enabled on it.

  • You cannot enable the Enable automatic sync of network objects toggle button if the Discover & Manage Network Objects toggle button is disabled.

On-Premises Firewall Management Center supports the following object types:

  • Network Objects

  • Network Group Objects

Object Issues

Security Cloud Control identifies duplicate, inconsistent, or unused objects, and you can filter the issues based on their issue states. However, Security Cloud Control cannot resolve object issues.

Eventing

Searching and filtering the historical and live event tables for specific events works the same way as it does for other information in Security Cloud Control. For more information, see Firepower Management Center and Cisco Security Analytics and Logging (SaaS) Integration Guide.

Cisco Security Analytics and Logging

Cisco Security Analytics and Logging allows you to capture connection, intrusion, file, malware, and security intelligence events from all your devices and view them in a single location in Security Cloud Control.

You can view events stored in the Cisco cloud on the Event Logging page in Security Cloud Control. Use filters to review which security rules are triggered in your network. The Logging and Troubleshooting package gives you these capabilities.

With the Firewall Analytics and Monitoring package, the system can apply Secure Cloud Analytics dynamic entity modeling to your events and use behavioral modeling analytics to generate Secure Cloud Analytics observations and alerts. If you obtain a Total Network Analytics and Monitoring package, the system applies dynamic entity modeling to both your device events and your network traffic and generates observations and alerts. You can cross launch from Security Cloud Control to a Secure Cloud Analytics portal provisioned for you, using Cisco Single Sign-On.