Meet requirements and prerequisites for the system configuration
Model support
Firewall Management Center
Supported domains
Global
User roles
Admin
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This chapter explains how to configure system configuration settings on the Cloud-Delivered Firewall Management Center.
Firewall Management Center
Global
Admin
Configure the system to establish and maintain the essential settings for the Cloud-Delivered Firewall Management Center. Ensure that these settings align with organizational requirements.
The system configuration identifies basic settings for the Cloud-Delivered Firewall Management Center. Use this task when you need to review or update the fundamental configuration options for the management center.
Access to the Cloud-Delivered Firewall Management Center interface may be required. Follow these steps to manage the Cloud-Delivered Firewall Management Center system configuration.
|
Step 1 |
Choose System ( |
|
Step 2 |
Use the navigation panel to choose configurations to change. |
When you complete the steps, the basic settings for the Cloud-Delivered Firewall Management Center will update to maintain proper system operation.
Verify that the configuration changes are applied and the system is functioning as expected.
You can track changes to access control rules by allowing or requiring users to comment when they save. This allows you to assess why critical policies in a deployment were modified. By default, this feature is disabled.
Configure object optimization to evaluate and optimize network or host policy objects that are used in rules. The system then creates associated network object groups on the device. For more information, refer to Object-group optimization.|
Step 1 |
Choose System ( |
||
|
Step 2 |
From the Comments on rule change list, choose an option:
|
||
|
Step 3 |
From the Object-group optimization list, choose an option:
|
||
|
Step 4 |
Click Save. |
Deploy the access control policies for object-group optimization to take effect.
An audit log is a security record that
records user activity in read-only logs,
allows review, sorting, filtering, deletion, and reporting of audit information, and
supports streaming audit log messages to external servers such as syslog and HTTP servers.
You can review audit log data in several ways:
Use the web interface: .
Audit logs appear in a standard event view. In this view, you can view, sort, and filter audit log messages based on any item. You can also delete audit information, generate reports, and view detailed reports of user changes.
Stream audit log messages to the syslog: Stream audit logs to syslog.
Stream audit log messages to an HTTP server: Stream audit logs to an HTTP server.
Streaming audit log data to an external server allows you to conserve space on the Cloud-Delivered Firewall Management Center. Note that sending audit information to an external URL may affect system performance.
Optionally, you can secure the channel for audit log streaming, enable TLS and mutual authentication using TLS certificates; refer to Audit log certificates.
Streaming to multiple syslog servers
You can stream audit log data to a maximum of five syslog servers. However, if you have enabled TLS for secured audit log streaming, you can stream only to a single syslog server.
Streaming configuration changes to syslog
You can stream configuration changes as part of audit log data to syslog by specifying the configuration data format and the hosts. The Cloud-Delivered Firewall Management Center supports backup and restore of the audit configuration log.
Configure audit log streaming to syslog servers to ensure centralized monitoring and compliance tracking for your system. Enable external logging of configuration changes and security events.
When this feature is enabled, audit log records appear in the syslog in the following format:
Date
Time
Host: [Tag] Sender: User_Name@User_IP, Subsystem, Action
Where the local date, time, and originating hostname precede the bracketed optional tag, and the sending device name precedes the audit log message.
For example, if you specify a tag of FMC-AUDIT-LOG for audit log messages from your management center, a sample audit log message from your Cloud-Delivered
Firewall Management Center could appear as follows:
Mar 01 14:45:24 localhost: [FMC-AUDIT-LOG] Dev-MC7000: admin@10.1.1.2, Operations > Monitoring, Page View
If you specify a severity and facility, these values do not appear in syslog messages; instead, they tell the system that receives the syslog messages how to categorize them.
This task is relevant when you need to send audit logs from your management center to an external syslog server for compliance or operational monitoring. Use this procedure when integrating with centralized log management solutions.
Make sure the Cloud-Delivered Firewall Management Center can communicate with the syslog server. When you save your configuration, the system uses ICMP/ARP and TCP SYN packets to verify syslog server connectivity. By default, the system uses port 514/UDP to stream audit logs. To secure the channel, manually configure port 1470 for TCP.
Follow these steps to stream audit logs to a syslog server:
|
Step 1 |
Choose System ( |
||||||||||||||
|
Step 2 |
Click Audit Log. |
||||||||||||||
|
Step 3 |
Choose Enabled from the Send Audit Log to Syslog drop-down menu. |
||||||||||||||
|
Step 4 |
The following fields are applicable only for audit logs sent to syslog:
|
||||||||||||||
|
Step 5 |
(Optional) To test whether the IP address of the syslog servers is valid, click Test Syslog Server. The system sends the following packets to verify whether the syslog server is reachable:
|
||||||||||||||
|
Step 6 |
Click Save. |
After you complete this task, audit logs are sent from the management center to the specified syslog server, allowing you to monitor and review system activity externally.
Verify that the syslog server is receiving audit log messages as expected. Check for log entries corresponding to configuration changes or security events.
Stream audit logs from the device to an HTTP server to centralize log management and support compliance requirements.
Use this task to forward audit logs from your device to an external HTTP server for monitoring, analysis, or compliance.
When this feature is enabled, the appliance sends audit log records to an HTTP server in the following format:
Date
Time
Host: [Tag] Sender: User_Name@User_IP, Subsystem, Action
Where the local date, time, and originating hostname precede the bracketed optional tag, and the sending appliance name precedes the audit log message.
For example, if you specify a tag of FROMMC, a sample audit log message could appear as follows:
Mar 01 14:45:24 localhost: [FROMMC] Dev-MC7000: admin@10.1.1.2, Operations > Monitoring, Page View
Make sure the device can communicate with the HTTP server.
Follow these steps to stream audit logs to an HTTP server.
|
Step 1 |
Choose System ( |
||
|
Step 2 |
Click Audit Log. |
||
|
Step 3 |
Optionally, in the Tag field, enter the tag name that you want to appear with the message. For example, if you want all audit log records to be
preceded with |
||
|
Step 4 |
Choose Enabled from the Send Audit Log to HTTP Server drop-down list. |
||
|
Step 5 |
In the URL to Post Audit field, designate the URL where you want to send the audit information. Enter a URL that corresponds to a Listener program that expects the HTTP POST variables as listed:
|
||
|
Step 6 |
Click Save. |
When you complete this task, the device sends audit logs to the specified HTTP server. Centralized monitoring and record-keeping become possible.
An audit log certificate is a security credential that
secures communications between the Cloud-Delivered Firewall Management Center and a trusted audit log server,
enables authentication and encryption using Transport Layer Security (TLS), and
supports mutual authentication and certificate revocation checks for enhanced security.
Client certificates are required to secure communications between the Cloud-Delivered Firewall Management Center and the audit log server.
Generate a certificate signing request (CSR). Submit it to a Certificate Authority (CA) for signing. Import the signed certificate onto the Cloud-Delivered Firewall Management Center.
Use the local system configuration: Obtain a signed audit log client certificate for the Cloud-Delivered Firewall Management Center and Import an audit log client certificate into the Cloud-Delivered Firewall Management Center.
Server certificates are optional and provide additional security through mutual authentication.
Require mutual authentication between the Cloud-Delivered Firewall Management Center and the audit log server by loading one or more certificate revocation lists (CRLs).
You cannot stream audit logs to servers with revoked certificates listed in those CRLs.
Secure Firewall supports CRLs encoded in Distinguished Encoding Rules (DER) format. These are the same CRLs used to validate HTTPS client certificates for the Cloud-Delivered Firewall Management Center web interface.
Use the local system configuration: Require valid audit log server certificates.
For example, a signed client certificate imported onto the Cloud-Delivered Firewall Management Center enables secure TLS communication with an audit log server, ensuring log integrity and confidentiality.
A certificate that is not signed by a trusted Certificate Authority or is listed in a certificate revocation list (CRL) cannot be used to stream audit logs securely.
An audit log certificate is like a passport for secure communication, verifying identity and granting access between the management center and the audit log server.
Configure secure audit log streaming to ensure that audit logs are transmitted safely between the Cloud-Delivered Firewall Management Center and a trusted server.
When you stream the audit log to a trusted HTTP server or syslog server, use Transport Layer Security (TLS) certificates to secure the channel between the Cloud-Delivered Firewall Management Center and the server.
You must generate a unique client certificate for each appliance you want to audit. Mutual authentication requires the client certificate to be signed by the same CA as the server certificate. For more considerations on client and server certificate requirements, refer to Audit log certificates.
Refer to ramifications of requiring client and server certificates at Audit log certificates. Ensure you have access to a recognized certificate authority (CA) for signing client certificates.
Follow these steps to secure audit log streaming.
|
Step 1 |
Obtain and install a signed client certificate on the Cloud-Delivered Firewall Management Center. |
|
Step 2 |
Configure the communication channel with the server to use Transport Layer Security (TLS) and enable mutual authentication. |
|
Step 3 |
If you have not yet configured audit log streaming, do so now. |
Audit logs are securely streamed to the trusted server using TLS, with mutual authentication enabled. The Cloud-Delivered Firewall Management Center and the server verify each other's certificates, ensuring secure transmission and integrity of audit log data.
Monitor the audit log streaming status and verify certificate validity periodically. Renew client and server certificates before expiration to maintain secure log streaming.
Obtain a signed audit log client certificate for the Cloud-Delivered Firewall Management Center. This certificate enables secure communication between the appliance and the audit log server. It ensures that the server can authenticate audit log data and that the data is transmitted securely.
The system generates certificate request keys in Base-64 encoded PEM format.
Perform this task on the active appliance to generate a certificate signing request for audit log client authentication. Do not perform this task on a standby appliance in a high availability setup.
Keep this in mind:
To ensure security, use a globally recognized and trusted certificate authority (CA) to sign your certificate.
If you will require mutual authentication between the appliance and the audit log server, the same certificate authority must sign both the client certificate and the server certificate.
Follow these steps to obtain a signed audit log client certificate for the Cloud-Delivered Firewall Management Center:
|
Step 1 |
Choose System ( |
||
|
Step 2 |
Click Generate New CSR. |
||
|
Step 3 |
Enter a country code in the Country Name (two-letter code) field. |
||
|
Step 4 |
Enter a state or province postal abbreviation in the State or Province field. |
||
|
Step 5 |
Enter a Locality or City, an Organization name, and an Organizational Unit (Department) name. |
||
|
Step 6 |
Enter the fully qualified domain name of the server for which you want to request a certificate in the Common Name field.
|
||
|
Step 7 |
Click Generate and then open a new blank file with a text editor. |
||
|
Step 8 |
Copy the block of text from the certificate request, including the |
||
|
Step 9 |
Save the file as |
After completing these steps, you will have a certificate signing request (CSR) file that can be submitted to a trusted certificate authority. After it is signed, you can import the certificate to the appliance for secure audit log streaming.
Submit the certificate signing request to the certificate authority you selected, according to the guidelines in the 'Before You Begin' section.
When you receive the signed certificate, import it to the appliance; refer to Import an audit log client certificate into the Cloud-Delivered Firewall Management Center.
Importing an audit log client certificate enables secure communication between the Secure Firewall Management Center and external systems during audit log transmission. This task verifies that you import the correct signed certificate and any necessary intermediate certificates for secure operations.
In a Secure Firewall Management Center high availability setup, you must use the active peer when importing the audit log client certificate. This procedure is relevant when configuring audit log security or after obtaining a new signed client certificate.
Obtain a signed audit log client certificate for the Cloud-Delivered Firewall Management Center.
Make sure you are importing the signed certificate for the correct Cloud-Delivered Firewall Management Center.
If the signing authority requires an intermediate CA, ensure you provide the certificate chain. The same CA must sign both the client certificate and the intermediate certificates.
Follow these steps to import an audit log client certificate into the Secure Firewall Management Center.
|
Step 1 |
On the Cloud-Delivered
Firewall Management Center, choose System ( |
|
Step 2 |
Click Audit Log Certificate. |
|
Step 3 |
Click Import Audit Client Certificate. |
|
Step 4 |
Open the client certificate in a text editor, copy the entire block of text, including the |
|
Step 5 |
To upload a private key, open the private key file and copy the entire block of text, including the |
|
Step 6 |
Open any required intermediate certificates, copy the entire block of text for each, and paste it into the Certificate Chain field. |
|
Step 7 |
Click Save. |
The audit log client certificate and any required intermediate certificates are successfully imported into the Secure Firewall Management Center.
The system supports validating audit log server certificates using imported CRLs in Distinguished Encoding Rules (DER) format.
Note |
If you choose to verify certificates using CRLs, the system uses the same CRLs to validate both audit log server certificates and certificates used to secure the HTTP connection between an appliance and a web browser. |
Understand the ramifications of requiring mutual authentication and of using certificate revocation lists (CRLs) to ensure that certificates are still valid. Refer to Audit log certificates.
Obtain and import the client certificate following the steps in Secure audit log streaming and the topics referenced in that procedure.
|
Step 1 |
On the Cloud-Delivered
Firewall Management Center , choose System ( |
||||
|
Step 2 |
Click Audit Log Certificate . |
||||
|
Step 3 |
To use Transport Layer Security to securely stream the audit log to an external server, select Enable TLS . When TLS is enabled, the syslog client ( Cloud-Delivered Firewall Management Center ) verifies the certificate received from the server. The connection between the client and the server succeeds only if server certificate verification is successful. For this verification process, these conditions must be met:
|
||||
|
Step 4 |
If you do not want the client to authenticate itself against the server, but wish to accept the server certificate when the certificate is issued by the same CA (not recommended), complete these steps. |
||||
|
Step 5 |
(Optional) To enable client certificate verification by the audit log server, select Enable Mutual Authentication.
When mutual authentication is enabled, the syslog client ( Cloud-Delivered Firewall Management Center ) sends a client certificate to the syslog server for verification. The client uses the same CA certificate of the CA who signed the server certificate of the syslog server. The connection succeeds only if client certificate verification is successful. For this verification process, these conditions must be met:
|
||||
|
Step 6 |
(Optional) To automatically recognize server certificates that are no longer valid: |
||||
|
Step 7 |
Verify that you have a valid server certificate generated by the same certificate authority that created the client certificate. |
||||
|
Step 8 |
Click Save. |
(Optional) Set the frequency of CRL updates. Refer to Schedule certificate revocation list (CRL) updates.
View the audit log client certificate to confirm its presence and details on the appliance you are logged in to. This helps ensure that audit log operations are secured with the correct certificate.
You can view the audit log client certificate only for the appliance that you are logged in to.
Follow these steps to view the audit log client certificate on the appliance:
|
Step 1 |
Choose System ( |
|
Step 2 |
Click Audit Log Certificate. |
The appliance you are logged in to displays the audit log client certificate details. For high availability pairs, only the active peer shows the certificate.
A change reconciliation report is a configuration monitoring tool that
captures snapshots whenever a user saves changes to the system configuration,
combines information from these snapshots to present a clear summary of recent system changes, and
provides a detailed report of changes made over the past 24 hours through email.
The change reconciliation report displays both the previous value for each configuration and the value after changes.
Users can view summaries of each distinct change in chronological order, beginning with the most recent.
Lists both previous and updated values for each configuration.
Summarizes multiple changes to the same configuration.
Orders changes chronologically, starting with the most recent.
An example change reconciliation report includes a User section that lists configuration changes, showing both the previous and updated values for each item.
Changes made without reconciliation are not summarized or tracked in a report, making it difficult to monitor user activity.
Change reconciliation is similar to a transaction log, where each modification is recorded and summarized for review.
Configure change reconciliation to enable the system to generate and send daily reports of configuration changes, supporting audit and compliance requirements. This helps administrators monitor and review all changes made to the system within a 24-hour period.
Use this task when you need to track and review configuration changes made to your system for security, compliance, or operational awareness.
Change reconciliation is especially useful in environments where multiple administrators make changes or where audit trails are required for regulatory purposes. Perform this configuration after setting up your email server to ensure reports are delivered successfully.
|
Step 1 |
Choose System ( |
||
|
Step 2 |
Click Change Reconciliation. |
||
|
Step 3 |
Check the Enable check box. |
||
|
Step 4 |
Choose the time of day you want the system to send out the change reconciliation report from the Time to Run drop-down lists. |
||
|
Step 5 |
Enter email addresses in the Email to field.
|
||
|
Step 6 |
If you want to include policy changes, check the Include Policy Configuration check box. |
||
|
Step 7 |
If you want to include all changes over the past 24 hours, check the Show Full Change History check box. |
||
|
Step 8 |
Click Save. |
After you complete this task, the system will automatically generate and email daily reports of all configuration changes, allowing you to monitor and review system modifications for compliance and troubleshooting.
The change reconciliation options control whether the system includes records of policy changes and the full change history in the change reconciliation report. These options determine the scope and detail of reported changes.
The Include Policy Configuration option controls whether the system includes records of policy changes in the change reconciliation report. It includes changes to access control, intrusion, system, health, and network discovery policies. If you do not select this option, the report will not show changes to any policies. This option is available only on Cloud-Delivered Firewall Management Centers.
The Show Full Change History option controls whether the system includes records of all changes over the past 24 hours in the change reconciliation report. If you do not select this option, the report includes only a consolidated view of changes for each category.
Note |
The change reconciliation report does not include changes to Firewall Threat Defense interfaces and routing settings. |
An email notification is a system alert mechanism that enables automated emailing of event-based, status, change reconciliation, and data-pruning reports.
You cannot configure a mail host. TThe mail relay host is hardcoded to a static host. It is set to email-smtp.us-west-2.amazonaws.com with authorization. For notifications, the email sender is set to cdo-alert@cisco.com.
An intrusion policy preference is a configuration option that
enables monitoring of critical policies,
tracks changes to those policies, and
supports management of policy settings in a deployment.
Configure intrusion policy preferences to manage how policy changes are tracked, logged, and monitored for security intelligence. You can enable or disable comments on policy changes, audit logging, user overrides for deleted Snort 3 rules, and Talos Threat Hunting Telemetry.
This task is relevant when you need to control how intrusion policy changes are documented, audited, and monitored for advanced threat detection and compliance.
Use this configuration to ensure that policy modifications are properly tracked and that security events are sent to Cisco Talos for analysis when required. Perform this task during initial setup or when updating security and compliance requirements for your deployment.
Follow these steps to set intrusion policy preferences:
|
Step 1 |
Choose System ( |
||
|
Step 2 |
Click Intrusion Policy Preferences. |
||
|
Step 3 |
You have these options:
|
After completing this task, your intrusion policy preferences are set according to your selections. Policy changes are tracked, logged, and, if enabled, threat-hunting telemetry is sent to Cisco Talos for analysis.
Network analysis policy preferences are configuration settings that enable tracking and documentation of policy modifications within the system.
You can configure the system to track policy-related changes using the comment functionality when users modify network analysis policies. With policy change comments enabled, administrators can quickly assess why critical policies in a deployment were modified.
If you enable comments on policy changes, you can make the comment optional or mandatory. The system prompts the user for a comment when each new change to a policy is saved.
Optionally, you can have changes to network analysis policies written to the audit log.