Supported devices, software, and hardware for Security Cloud Control Firewall Management
Security Cloud Control Firewall Management is a cloud-based management solution enabling the management of security policies and device configurations across multiple security platforms.
This section describes the supported device types, software, hardware, and constraints for managing firewall, cloud, SD-WAN, Cisco IOS, Cisco Umbrella, and management center integrations in Security Cloud Control Firewall Management.
Support scope
Security Cloud Control Firewall Management is a cloud-based management solution for security policies and device configurations across multiple security platforms. The source identifies support for these management areas:
-
Cisco Secure Firewall ASA, both on-premises and virtual
-
Cisco Secure Firewall Threat Defense (FTD), both on-premises and virtual
-
Cisco Catalyst SD-WAN Manager
-
Cisco Secure Firewall Management Center, on-premises
Security Cloud Control Firewall Management documentation identifies the devices, software, and hardware that Security Cloud Control Firewall Management supports. If the documentation does not explicitly claim support for a software version or device type, Security Cloud Control Firewall Management does not support it.
Cisco Secure Firewall ASA
Cisco Adaptive Security Appliance (ASA) is a security device that integrates firewall, VPN, and intrusion prevention capabilities. Security Cloud Control supports ASA device management to streamline configuration management and support regulatory compliance across the network infrastructure.
Cisco Secure Firewall Threat Defense
Cisco Secure Firewall Threat Defense integrates traditional firewall features with advanced threat protection capabilities. It includes security functions such as intrusion prevention, application control, URL filtering, and advanced malware protection.
A Secure Firewall Threat Defense device can be deployed on ASA hardware appliances, Cisco firewall hardware appliances, and virtual environments. You can manage threat defense devices through management interfaces such as Cisco Firewall Management Center, Security Cloud Control, and Firewall Device Manager.
Firewall Threat Defense integrates traditional firewall features with advanced threat protection capabilities. It offers comprehensive security functions, including intrusion prevention, application control, URL filtering, advanced malware protection, and so on. An FTD can be deployed on ASA hardware appliances, and Cisco firewall hardware appliances, and in virtual environments. Managing threat defense devices is possible through various management interfaces, such as Cisco Firewall Management Center and Security Cloud Control
For more information on software and hardware compatibility, see the Cisco Secure Firewall Threat Defense Compatibility Guide.
Cisco Secure Firewall Management Center
Security Cloud Control Firewall Management simplifies the management of on-premises Firewall Management Center by establishing a secure integration, discovering security devices, and enabling centralized policy management. Security policies such as firewall rules, VPN settings, and intrusion prevention policies can be efficiently managed and deployed across all devices under FMC.
ASA support specifics
Security Cloud Control Firewall Management support for ASA has these constraints:
-
Security Cloud Control Firewall Management can manage all ASA platforms that run currently supported code versions, including ASAv instances.
-
Security Cloud Control Firewall Management does not support ASA Services Module (ASASM).
-
Security Cloud Control Firewall Management does not test end-of-life ASA code versions and does not recommend them for production.
-
Use currently supported ASA code versions for optimal results.
-
ASA 8.3 is not supported with the new policy view.
-
Security Cloud Control Firewall Management does not manage the ASA FirePOWER module because the module runs a different operating system from ASA. Manage the ASA FirePOWER module separately with Secure Firewall Management Center or ASDM.
-
End-of-life code and hardware might continue to work with Security Cloud Control Firewall Management. Because end-of-life code and hardware are not part of Security Cloud Control Firewall Management testing, correct operation with end-of-life software and hardware is not guaranteed or assured.
Refer to the version download page for Cisco "suggested release" or "gold star" versions.
-
ASA versions 8.x, 9.1, and 9.2 do not support TLS 1.2 on the management plane and are considered insecure for ASA software management.
For a full discussion of ASA, ASDM, and hardware compatiblity, see the Cisco Secure Firewall ASA Compatibility guide.
Secure Firewall Threat Defense Device Support Specifics
Secure Firewall Threat Defense is Cisco's next generation firewall. It can be installed on a variety of hardware and virtual platforms; see the Cisco Secure Firewall Threat Defense Compatibility Guide.
Firewall Threat Defense with Secure Firewall Device Manager
You can add Security Cloud Control managment to threat defense Version 6.4+ with Firewall Device Manager. However, this option is only available upon request for those who already have device manager support enabled on their tenant. See:
-
Open a Support Ticket with TAC to request this option.
Snort
Snort 3 is the default inspection engine for threat defense starting in threat defense Version 6.7 (with device manager) and Version 7.0 (with management center).
Important |
If you are still using the Snort 2 inspection engine, switch to Snort 3 now for improved detection and performance. Snort 2 will be deprecated in a future release and will eventually prevent threat defense upgrade. |
Cloud Device Support Specifics
The following table describes software and device type support for cloud-based devices. Read the affiliated links for more information about onboarding and feature functionality for the device types in the table below:
|
Devices Types |
Notes |
|---|---|
|
Google Cloud Platform |
Google Cloud Platform (GCP) receives updates through the GCP console. Refer to Google Cloud documentation for more information about the platform and available services. |
|
Microsoft Azure |
Azure receives updates through the Azure console. Refer to Azure documentation for more information about the platform and available services. |
) icon.
Feedback