Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Onboard multiple ASAs to Security Cloud Control Firewall Management

Want to summarize with AI?

Log in

Learn how to onboard multiple ASAs to Security Cloud Control Firewall Management, including prerequisites, connector selection, credentials, labels, and inventory results.


Security Cloud Control Firewall Management allows you to bulk onboard ASA devices by providing the necessary information for all the ASA devices in a .csv file. As the ASA devices are being onboarded, you can use the filter pane to show which onboarding attempts are queued, loading, complete, or have failed.

Before you begin

  • Review Allow inbound access for direct cloud connectivity.

  • Prepare a .csv file with the connection information for the ASA devices you want to onboard. Add the information about each ASA on a separate line. To include a comment, add a # at the beginning of the line.

    • ASA location (either IP address or FQDN)

    • ASA administrator username

    • ASA administrator password

    • (Optional) Device name for Security Cloud Control Firewall Management

    • In the SDCName field, specify the name of a Secure Device Connector (SDC) in your network you want to use to connect Security Cloud Control Firewall Management to your ASA. You can also enter "none" if you are not going to connect your ASA to Security Cloud Control Firewall Management using an SDC. When onboarding the device, specifying "none" in SDCName field, onboards the ASA using the Cloud Connector. The Cloud Connector allows you to connect your device to Security Cloud Control Firewall Management without installing an SDC. Choose an option based on how you connect Security Cloud Control to your managed device.

    • (Optional) device labels for Security Cloud Control Firewall Management

    • To add one label, add the label name to the last CSV field.

    • To add more than one label to a device, surround the values with quotation marks. For example, alpha,beta,gamma.

    • To add a category and choice label, separate the two values with a colon (:). For example, Rack:50.

Here is a sample configuration file.


#Location,Username,Password,DeviceName,SDCName,DeviceLabel 
192.168.3.2,admin,CDO123!,ASA3,sdc1,"HA-1,Rack:50" 
192.168.4.2,admin,CDO123!,ASA4,sdc1,"HA-1,Rack:50" 
ASA2.example.com,admin,CDO123!,ASA2,none,Rack:51 
asav.virtual.io,admin,CDO123!,ASA-virtual,sdc3,Test
Caution

Security Cloud Control does not validate any of the data in the .csv file. You need to ensure the accuracy of the entries.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

Choose Security Devices.

3.

Click the plus button to onboard an ASA.

4.

On the Onboarding page, click the Multiple ASAs tile.

5.

Click Browse to locate the .csv file containing your ASA entries. The devices you specify appear in the ASA Bulk Onboarding table as queued and are ready for onboarding.

Caution

Stay on the ASA Bulk Onboarding page until the onboarding process is complete. If you leave the page, the onboarding process stops.

6.

Click Start.

The status column in the ASA Bulk Onboarding table shows the progress of onboarding. When onboarding finishes, the status displays "Complete."

What to do next

To pause bulk onboarding and resume later, refer to Pause and resume onboarding multiple ASA devices.


Pause and resume onboarding multiple ASA devices

If you need to pause the onboarding process, click Pause. Security Cloud Control completes onboarding any device it has started. To resume bulk onboarding, click Start. Security Cloud Control will begin onboarding the next queued device.

If you click Pause and leave this page, you must return and restart the bulk onboarding process. Security Cloud Control identifies already onboarded devices, flags duplicates from this new attempt, and quickly starts onboarding the remaining queued devices.