Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Backing Up FDM-Managed Devices

Want to summarize with AI?

Log in

Learn how to back up and restore FDM-managed device configurations in Security Cloud Control, including backup schedules, retention limits, restore requirements, connectivity requirements, and configuration state best practices.


You can use Security Cloud Control to back up an FDM-managed device's system configuration so that you can restore the device to a previous state. Backups include the configuration only, and not the system software. If you need to completely reimage the device, you need to reinstall the software, then you can upload a backup and recover the configuration. Security Cloud Control saves the last 5 backups made for a device. When a new backup occurs, the oldest backup is deleted in order to store the newest backup.

Note

The backup does not include the management IP address configuration. Thus, when you recover a backup file, the management address is not replaced from the backup copy. This ensures that any changes you made to the address are preserved, and also makes it possible to restore the configuration on a different device on a different network segment.

The configuration database is locked during backup. You cannot make configuration changes during a backup, although you can view policies, dashboards, and so forth. During a restore, the system is completely unavailable.

To make backup schedules across your devices consistent, you can configure your own default backup schedule. When you schedule a backup for a particular device, you can use your own default settings or change them. You can schedule recurring backups with cadences from daily to once a month and you can perform an on-demand backup. You can also download backups and then use the Firewall Threat Defense device manager to restore them.

Requirements and best practice for backing up and restoring an FDM-managed device using Security Cloud Control

  • Security Cloud Control can backup FDM-managed devices running software version 6.5 and later.

  • The FDM-managed device must be onboarded to Security Cloud Control using a registration key.

  • You can restore a backup onto a replacement device only if the two devices are the same model and are running the same version of the software, including the build number, not just the same point release. For example, a backup of an FDM-managed device running software version 6.6.0-90 can only be restored to an FDM-managed device running 6.6.0-90. Do not use the backup and restore process to copy configurations between appliances. A backup file contains information that uniquely identifies an appliance, so that it cannot be shared in this manner.

  • For the Secure Firewall Threat Defense backup functionality to work in Security Cloud Control, Firewall Threat Defense needs to access one of these Security Cloud Control URLs based on your tenant region.

  • Ensure that port 443 has external and outbound access for the HTTPS protocol. If the port is blocked behind a firewall, the backup and restore process may fail.

Best Practice

The device you are going to backup should be in the Synced state in Security Cloud Control. Security Cloud Control backs up the configuration of the device from the device not from Security Cloud Control. So, if the device is in a Not Synced state, changes on Security Cloud Control will not be backed up. If the device is in a Conflict Detected state, those changes will be backed up.


Back up an FDM-Managed Device On-Demand

This procedure describes how to backup an FDM-managed device so that it can be restored if need be.

Before you Begin

Review these requirements and best practices before you backup up an FDM-managed device.


Procedure

Procedure

1.

(Optional) Create a change request for the backup.

2.

In the left pane, click Security Devices.

3.

Click the Devices tab.

4.

Click the FTD tab and select the device you want to backup.

5.

In the Device Actions pane on the right, click Manage Backups.

6.

Click Backup Now. The Device enters the Backing Up configuration state.

When the backup is done, the Security Cloud Control displays the device's configuration state it was in before the backup started. You can also open the change log page to look for a recent change log record with the description, "Backup completed successfully."

If you created a change request in step 1, you can also filter by that value to find the change log entry.

7.

If you created a change request in step 1, clear the change request value so you do not inadvertently associated more changes with the change request.


Configure a Recurring Backup Schedule for a Single FDM-Managed Device


Procedure

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and select the device you want to backup.

4.

In the Device Actions pane on the right, click Manage Backups.

5.

In the Device Backups page, click Set Recurring Backup or click the schedule in the Recurring Backup field. Security Cloud Control presents the default backup schedule for all FDM-managed devices on your tenant. See Configure a Default Recurring Backup Schedule for all FDM-Managed Devices for more information.

6.

Select the time of day, in 24-hour time, you want the backup to occur. Note that you schedule the time in Coordinated Universal Time (UTC) time.

7.

In the Frequency field, select daily, weekly, or monthly backup.

  • Daily backups: Give the scheduled backup a name and a description.

  • Weekly backups: Check the days of the week on which you want the backup to occur. Give the scheduled backup time a name and a description.

  • Monthly backups: Click in the Days of Month field and add whichever days of the month you want to the schedule the backup. Note: If you enter day 31 but a month doesn't have 31 days in it, the backup will not take place. Give the scheduled backup time a name and a description.

8.

Click Save. Notice that on the Device Backup page, the Recurring Backup field is replaced by the backup schedule you set and reflects your local time.


Download the Device Backup

This procedure describes how to download a .tar file containing a backup of an FDM-managed device.

Procedure

1.

In the navigation bar, choose Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and the device whose backup you want to download.

4.

In the Actions pane on the right, click Manage Backups.

5.

Select the backup you want to download and, in its row, click the Generate Download Link button . The button changes to read, "Download Backup Image."

6.

The button now reads Download Backup Image. Do one of these things:

  • If you are on a device that can also reach the Firewall Device Manager of the device you want to restore, click the Download Backup Image button and save the downloaded file. Save it with a name that you will remember.

  • If you are not on a device that can also reach the FDM of the device you want to restore:

    1. Right-click the Download Backup Image button and copy the link address.

      The link address expires 15 minutes after you click the Generate Download Link button.

    2. Open a browser on a device that will also reach the Firewall Device Manager of the Secure Firewall Threat Defense you want to restore the image to.

    3. Enter the download link into the browser address bar and download the backup file to that device. Save it with a name that you will remember.


Edit a Backup

This procedure allows you to edit the name or description of a successful FDM-managed device download.

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and select the device you want to edit.

4.

In the Actions pane on the right, click Manage Backups.

5.

Select the backup you want to edit and it's row, click the edit icon .

6.

Change the name or description of the backup. You can see the new information in the Device Backups page.


Delete a Backup

Security Cloud Control saves the last 5 backups made for a device. When a new backup occurs, the oldest backup is deleted in order to store the newest backup. Deleting existing backups may help you manage which backups are kept and which are deleted.

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and select the device you want to delete.

4.

In the Actions pane on the right, click Manage Backups.

5.

Select the backup you want to delete and it's row, click the trash icon .

6.

Click OK to confirm.


Managing Device Backup

Backups of FDM-managed devices you produce using Security Cloud Control can be seen in the Device Backups page:

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab.

4.

Click the filter icon and check FDM under Devices/Services to see only FDM-managed devices in the device table.

5.

Select the device you want.

6.

In the Device Actions pane, click Manage Backups. You will see up to 5 of the latest backups made of that device.


Restore a Backup to an FDM-Managed Device

Review this information before you restore a backup of an FDM-managed managed Firewall Threat Defense device.

  • Review these requirements and best practices before you restore a backup to an FDM-managed Firewall Threat Defense device.

  • If the backup copy you want to restore is not already on the device, you must upload the backup first before restoring it.

  • During a restore, the system is completely unavailable. After the backup is restored, the device reboots.

  • This procedure assumes that you have an existing backup of the device ready to be restored to the device.

  • You cannot restore a backup if the device is part of a high availability pair. You must first break HA from the Device > High Availability page, then you can restore the backup. If the backup includes the HA configuration, the device will rejoin the HA group. Do not restore the same backup on both units, because they would then both go active. Instead, restore the backup on the unit you want to go active first, then restore the equivalent backup on the other unit.

Note

The backup does not include the management IP address configuration. Thus, when you recover a backup file, the management address is not replaced from the backup copy. This ensures that any changes you made to the address are preserved, and also makes it possible to restore the configuration on a different device on a different network segment.

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the FTD tab and select the device you want to restore.

4.

In the Device Actions pane on the right, click Manage Backups.

5.

Select the backup you want to restore. In its row, click the Generate Download Link button .

Note

The link address expires 15 minutes after you click the Generate Download Link button.

6.

The button now reads Download Backup Image. Do one of these things:

  • If you are on a device that can also reach the Firewall Device Manager of the device you want to restore, click the Download Backup Imagebutton and save the downloaded file. Save it with a name that you will remember.

  • If you are not on a device that can also reach the Firewall Device Manager of the device you want to restore:

    1. Right-click the Download Backup Image button and copy the link address.

    2. Open a browser on a device that will also reach the Firewall Device Manager you want to restore the image to.

    3. Enter the download link into the browser address bar and download the backup file to that device. Save it with a name that you will remember.

7.

Log on to Firewall Device Manager for the device you want to restore.

8.

Open version 6.5 or higher of the Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager. Navigate to the System Management chapter, and search for Restoring a Backup. Follow those instructions to restore the image you just downloaded to your FDM-managed device.

Tip

You will need to upload your image to Firewall Device Manager in order to restore it.

9.

Follow the prompts in Firewall Device Manager. When the restore starts, your browser is disconnected from Firewall Device Manager. After the restore has finished, the device reboots.