Learn how to configure an Umbrella organization for ASA devices, including ASA integration with Cisco Umbrella and secure internet gateway use cases.
Read Umbrella tunnel configuration
After onboarding an Umbrella organization to Security Cloud Control, you can manually prompt Security Cloud Control to request and update the tunnel configuration from Umbrella. This update process applies to any tunnels that were added, deleted, or modified.
If you delete a tunnel from Security Cloud Control while the Umbrella organization credentials are invalid or have changed since you onboarded the organization, Security Cloud Control can deploy the tunnel configuration only to the ASA devices associated with the organization. When you update the credentials, Security Cloud Control reads the Umbrella configuration and restores any deleted tunnels. If the tunnel exists in the Umbrella organization but not in any ASA device, a synchronization issue occurs. In this case, you may not see the ASA devices as peers to the organization.
Procedure
| 1. | Log in to Security Cloud Control. |
|
| 2. | Choose . |
|
| 3. | Click the ASA tab. |
|
| 4. | Select the Umbrella organization so it is highlighted. |
|
| 5. | Under Actions, select Read Tunnels. |
Cross-launch to the Umbrella tunnels page
After you successfully onboard the ASA device and the Umbrella organization to Security Cloud Control, you can cross-launch to the Umbrella dashboard for tunnels from the Security Cloud Control UI.
Use this procedure to cross-launch to your device's Umbrella tunnels page:
Procedure
| 1. | From the Security Cloud Control Home page, click Firewall. |
|
| 2. | Choose . |
|
| 3. | Select the tunnel you want to highlight. |
|
| 4. | In the Actions pane, click Manage Tunnel in Umbrella. A new tab opens in your browser to display the Tunnels overview page. |
Configure a SASE tunnel for Umbrella
Use this procedure to create a SASE tunnel for an Umbrella organization:
Before you begin
The Umbrella organization and the ASA device you want to create the tunnel for must already be onboarded to Security Cloud Control.
If the ASA or Umbrella organization associated with the tunnel you just deployed is in an unhealthy state, Security Cloud Control may not be able to successfully deploy the tunnel. If you experience any issues, contact Cisco TAC.
Procedure
| 1. | From the Security Cloud Control Home page, click Firewall. |
|
| 2. | Choose . |
|
| 3. | Click the add button and select Create SASE Tunnel. |
|
| 4. | Enter the Umbrella peer information:
|
|
| 5. | Enter the ASA peer information:
|
|
| 6. | The Passphrase is automatically filled once you select the Umbrella organization and the ASA peer device. The Confirm Passphrase is also automatically filled. You can manually enter these fields if necessary. |
|
| 7. | (Optional) The Deploy changes to ASA immediately toggle at the bottom of the pop-up window is enabled by default. When enabled, the SASE tunnel configuration is immediately deployed to the ASA peer selected in the tunnel configuration. To stage changes and deploy later, manually disable the option. |
|
| 8. | Click Deploy. Optionally, click Deploy and Create Another to simultaneously deploy this SASE tunnel and create another tunnel. Once deployed, the tunnel will appear in the VPN Tunnels page. If you choose to Deploy and Create Another SASE tunnel, Security Cloud Control saves both the Umbrella organization selection and the Deploy changes to ASA immediately toggle setting and automatically applies these selections to the next tunnel configuration. You can manually alter these selections prior to deploying. |
Edit a SASE tunnel
Use this procedure to modify an existing SASE tunnel:
Procedure
| 1. | From the Security Cloud Control Home page, click Firewall. |
|
| 2. | Choose . |
|
| 3. | Select the tunnel you want to modify. |
|
| 4. | In the Actions pane, select Edit. |
|
| 5. | Edit these fields of the SASE tunnel:
|
|
| 6. | (Optional) The Deploy changes to ASA immediately toggle at the bottom of the pop-up window is enabled by default. When enabled, the SASE tunnel configuration is deployed immediately to the ASA peer selected in the tunnel configuration. To stage changes and deploy later, manually set the option to disable. If you choose to stage changes and deploy later, the status of the ASA peer in the Security Devices page appears as |
|
| 7. | Select Save Updates. |
Delete a SASE tunnel from Umbrella
Use this procedure to delete a SASE tunnel on Security Cloud Control:
Before you begin
To delete a SASE tunnel, the ASA associated with it must have a synced status in Security Cloud Control. If the device is unhealthy, you cannot delete the tunnel.
When you delete a SASE tunnel from Security Cloud Control, the tunnel is removed from both the ASA device and its Umbrella organization.
Before deleting a tunnel, confirm that the Umbrella organization credentials are valid. If the credentials are invalid or have changed, Security Cloud Control deploys the tunnel configuration only to the associated ASA devices. After you update the credentials, Security Cloud Control reads the Umbrella configuration and restores any tunnels you deleted. Because the tunnel exists in the Umbrella organization but not on any ASA device, synchronization issues can occur. The ASA devices may not appear as peers to the organization.
Procedure
| 1. | From the Security Cloud Control Home page, click Firewall. |
|
| 2. | Choose . |
|
| 3. | Select the tunnel you want to delete from Security Cloud Control. |
|
| 4. | Under Actions, click Delete. |
|
| 5. | Confirm you want to delete the tunnel and click OK. |