Learn how to configure FDM-managed device settings in Security Cloud Control, including management access, logging, DHCP, DNS, hostname, NTP, URL filtering, cloud services, and web analytics.
Configure an FDM-Managed Device's System Settings
Use this procedure to configure settings on a single FDM-managed device:
Procedure
| 1. | In the left pane, click . |
|
| 2. | Click the Devices tab to locate your device. |
|
| 3. | Click the FTD tab and select the FDM-managed device you want to configure the settings. To narrow down your search results and easily find the FDM-managed devices, you can make use of the filter button. |
|
| 4. | In the Management pane at the right, click Settings. |
|
| 5. | Click the System Settings tab. |
|
| 6. | Edit any of these device settings: |
Configure Management Access
By default, you can reach the device's management address from any IP address. System access is protected by username and password only. However, you can configure an access list to allow connections from specific IP addresses or subnets only to provide another level of protection.
You can also open data interfaces to allow an FDM-managed device or SSH connections to the CLI. You can then manage the device without using the management address. For example, you could allow management access to the outside interface, so that you can configure the device remotely. The username and password protects against unwanted connections. By default, HTTPS management access to data interfaces is enabled on the inside interface, but it's disabled on the outside interface. For device models that have a default "inside" bridge group, this means that you can make FDM-managed device connections through any data interface within the bridge group to the bridge group IP address (default is 192.168.1.1). You can open a management connection only on the interface through which you enter the device.
If you constrain access to specific addresses, you can easily lock yourself out of the system. If you delete access for the IP address that you are currently using, and there's no entry for "any" address, you'll lose access to the system when you deploy the policy. Be mindful of this when configuring the access list.
Create Rules for Management Interfaces
Use the following procedure to create rules for managment interfaces:
Procedure
| 1. | Click New Access in the Management Interface section.
|
|
| 2. | Click Save. |
Create Rules for Data Interfaces
Use the following procedure to create rules for data interfaces:
Procedure
| 1. | Click New Access in the Data Interface section.
|
|
| 2. | Click Save. |
|
| 3. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Configure Logging Settings
This procedure describes how to enable logging of diagnostic (data) messages, file and malware events, intrusion events, and console events. Connection events are not logged as a result of these settings; they are logged if connection logging is configured on access rules, security intelligence policies, or SSL decryption rules.
Procedure
| 1. | ||
| 2. | On the System Settings page click Logging in the settings menu. |
|
| 3. | Data logging. Slide the Data Logging slider to On to capture diagnostic logging syslog messages. This will send data logging events for any type of syslog message, with your minimum chosen severity level, to the syslog server.
|
|
| 4. | File/Malware Log Settings. Slide the slider to On to capture file and malware events. File and malware events are generated at the same severity level. The minimum level of event severity you select will be assigned to all file and malware events. File and malware events are reported when a file or malware policy in any access control rule has been triggered. This is not the same as a connection event. Note that the syslog settings for file and malware events are relevant only if you apply file or malware policies, which require the and Malware licenses. For Cisco Security Analytics and Logging subscribers:
|
|
| 5. | Intrusion Logging. Intrusion events are reported when an intrusion policy in any access control rule has been triggered. This is not the same as a connection event. Note that the syslog settings for intrusion events are relevant only if you apply intrusion policies, which require the license. For Cisco Security Analytics and Logging subscribers:
|
|
| 6. | Console Filter. Slide the slider to On to send data logging (diagnostic logging) events to a console rather than to a syslog server. Additionally, select the minimum level of event severity you want to log. This will send a data logging event for any type of syslog message, with your chosen severity level. You will see these messages when you log into the CLI on the console port of your FDM-managed device. You can also see these logs in an SSH session to other FDM-managed device interfaces (including the management interface) by using the show console-output command. In addition, you can see these messages in real time in the diagnostic CLI by entering system support diagnostic-cli from the main CLI. |
|
| 7. | Click Save. |
|
| 8. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Message Severity Levels
The following table lists the syslog message severity levels.
| Level Number |
Severity Level |
Description |
|---|---|---|
| 0 |
emergencies |
System is unusable. |
| 1 |
alert |
Immediate action is needed. |
| 2 |
critical |
Critical conditions. |
| 3 |
error |
Error conditions. |
| 4 |
warning |
Warning conditions. |
| 5 |
notification |
Normal but significant conditions. |
| 6 |
informational |
Informational messages only. |
| 7 |
debugging |
Debugging messages only. |
|
|
FDM-managed device does not generate syslog messages with a severity level of zero (emergencies). |
|
Configure DHCP Servers
A Dynamic Host Configuration Protocol (DHCP) server provides network configuration parameters, such as IP addresses, to DHCP clients. You can configure a DHCP server on an interface to provide configuration parameters to DHCP clients on the attached network.
An IPv4 DHCP client uses a broadcast rather than a multicast address to reach the server. The DHCP client listens for messages on UDP port 68. The DHCP server listens for messages on UDP port 67. The DHCP server does not support BOOTP requests.
DHCP clients must be on the same network as the interface on which the server is enabled. There cannot be an intervening router between the server and client, although there can be a switch.
Do not configure a DHCP server on a network that already has a DHCP server operating on it. The two servers will conflict with each other, and the results will be unpredictable.
Procedure
| 1. | The section has two areas. Initially, the Configuration section shows the global parameters. The DHCP Servers area shows the interfaces on which you have configured a server, whether the server is enabled, and the address pool for the server. |
|
| 2. | In the Configuration section, configure auto configuration and global settings.
DHCP auto configuration enables the DHCP server to provide DHCP clients with DNS server, domain name, and WINS server information obtained from a DHCP client that's running on the specified interface. Typically, you would use auto configuration if you're obtaining an address using DHCP on the outside interface, but you could choose any interface that obtains its address through DHCP. If you cannot use auto configuration, you can manually define the required options.
|
|
| 3. | In the DHCP Servers section, either edit an existing server, or click New DHCP Server to add and configure a new server.
|
|
| 4. | Click Save. |
|
| 5. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Configure DNS Server
A Domain Name System (DNS) server is used to resolve hostnames to IP addresses. DNS servers are used by the management interface.
Procedure
| 1. | In Primary, Secondary, Tertiary DNS IP Address, enter the IP addresses of up to three DNS servers in order of preference. The primary DNS server is used unless it cannot be contacted, in which case the secondary is tried, and finally the tertiary. Click Apply Umbrella Settings if you want to populate the DNS IP address fields with Cisco Umbrella DNS servers. Clicking the button loads the appropriate IP addresses into the fields. |
|
| 2. | In Domain Search Name, enter the domain name for your network; for example, example.com. This domain gets appended to hostnames that are not fully qualified; for example, serverA becomes serverA.example.com. |
|
| 3. | Click Save. |
|
| 4. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Management Interface
The management interface is a virtual interface attached to the physical management port. The physical port is named the Diagnostic interface, which you can configure on the Interfaces page with the other physical ports. On virtual FDM-managed devices, this duality is maintained even though both interfaces are virtual.
The management interface has two uses:
-
You can open web and SSH connections to the IP address and configure the device through the interface.
-
The system obtains smart licensing and database updates through this IP address.
If you use the CLI setup wizard, you configure the management address and gateway for the device during initial system configuration. If you use the FDM-managed setup wizard, the management address and gateway remain the defaults.
If necessary, you can change these addresses through an FDM-managed device. You can also change the management address and gateway in the CLI using the configure network ipv4 manual and configure network ipv6 manual commands.
You can define static addresses, or obtain an address through DHCP if another device on the management network is acting as a DHCP server. By default, the management address is static, and a DHCP server runs on the port (except for Virtual FDM-Managed Device, which does not have a DHCP server). Thus, you can plug a device directly into the management port and get a DHCP address for your workstation. This makes it easy to connect to and configure the device.
If you change the address to which you are currently connected, you will lose access to the FDM-managed device (or the CLI) when you save the changes, as they are applied immediately. You will need to reconnect to the device. Ensure that the new address is valid and available on the management network.
Procedure
| 1. | Configure the management IP address, network mask or IPv6 prefix, and gateway (if necessary) for IPv4, IPv6, or both. You must configure at least one set of properties. Leave one set blank to disable that addressing method. |
|
| 2. | Select to obtain the address and gateway through DHCP or IPv6 auto configuration. However, you cannot use DHCP if you are using the data interfaces as the gateway. In this case, you must use a static address. |
|
| 3. | Click Save. |
|
| 4. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Hostname
You can change the device hostname.
Procedure
| 1. | In the Firewall Hostname field, enter a new hostname for the device. |
|
| 2. | Click Save. |
|
| 3. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Configure NTP Server
Configure Network Time Protocol (NTP) servers to set the time on the system.
Procedure
| 1. | Select whether you want to use your own (manual) or Cisco's time servers.
|
|
| 2. | Click Save. |
|
| 3. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Configure URL Filtering
The system obtains the URL category and reputation database from Cisco Collective Security Intelligence (CSI). These preferences control database updates and how the system handles URLs with unknown category or reputation. You must enable the URL Filtering license to set these preferences.
You can configure URL Filtering Preferences if you do not have a URL Smart License, but you need the smart license to deploy. You will be blocked from deploying until you add a URL Smart License.
Procedure
| 1. | Enable the applicable options:
|
|
| 2. | Click Save. |
|
| 3. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Cloud Services
Use the Cloud Services page to manage cloud-based services.
Connecting to the Cisco Success Network and configuring which events are sent to the Cisco cloud are features that can be configured on FDM-managed devices running software versions 6.6 and higher.
Connecting to the Cisco Success Network
By enabling Cisco Success Network, you are providing usage information and statistics to Cisco that are essential for Cisco to provide you with technical support. This information also allows Cisco to improve the product and to make you aware of unused available features so that you can maximize the value of the product in your network.
When you enable the connection, your device establishes a secure connection to the Cisco Cloud so that your device can participate in additional service offerings from Cisco such as technical support services, cloud management and monitoring services. Your device will establish and maintain this secure connection at all times.
Before you begin
To enable Cisco Success Network the device must be enrolled with the cloud using an FDM-managed device. To enroll the device either register the device with Cisco Smart Software Manager (on the Smart Licensing page) or enroll with Security Cloud Control by entering a registration key.
If you enable Cisco Success Network on the active unit in a high availability group, you are also enabling the connection on the standby unit.
Procedure
| 1. | Click the Cloud Services tab. |
|
| 2. | Click the Enabled slider for the Cisco Success Network feature to change the setting as appropriate. |
|
| 3. | Click Save. |
|
| 4. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Sending Events to the Cisco Cloud
You can send events to the Cisco Security Cloud. From there, various Cisco Security Cloud services can access the event data. You can then use these cloud applications, such as Cisco XDR, to analyze the events and to evaluate threats that the device might have encountered.
Before you begin
You must register the device with the Cisco Smart Software Manager before you can enable this service.
When you subscribe to Cisco XDR, you will receive an email with a link to sign in to Cisco XDR through Cisco Security Cloud Sign On. To sign in to Cisco XDR, you need a Cisco Security Cloud Sign On account. If you don’t have an account, you can create one using Creating a Security Cloud Sign On Account.
For more information about integrating Cisco XDR with FTD, see Cisco Secure Firewall Threat Defense and Cisco XDR Integration Guide.
Procedure
| 1. | Click the Cloud Services tab. |
|
| 2. | Click the Enabled slider for the Send Events to the Cisco Cloud option to change the setting as appropriate. |
|
| 3. | When you are enabling the service, you are prompted to select the events to send to the cloud.
|
|
| 4. | Click Save. |
|
| 5. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |
Enabling or Disabling Web Analytics
Enabling web analytics provides anonymous product usage information to Cisco based on page hits. The information includes pages viewed, the time spent on a page, browser versions, product version, device hostname, and so forth. This information can help Cisco determine feature usage patterns and help Cisco improve the product. All usage data is anonymous and no sensitive data is transmitted. You can use Security Cloud Control to configure this feature on all versions of FDM-managed device.
Web analytics is enabled by default.
Procedure
| 1. | Click the Web Analytics tab. |
|
| 2. | Click the Enable slider for the Web Analytics feature to change the setting as appropriate. |
|
| 3. | Click Save. |
|
| 4. | Review and deploy the changes you made now, or wait and deploy multiple changes at once. |