Onboard Secure Firewall ASA

This chapter explains the various different methods using which a Secure Firewall ASA can be onboarded.

Supported devices, software, and hardware for Security Cloud Control Firewall Management

Security Cloud Control Firewall Management is a cloud-based management solution enabling the management of security policies and device configurations across multiple security platforms.

This section describes the supported device types, software, hardware, and constraints for managing firewall, cloud, SD-WAN, Cisco IOS, Cisco Umbrella, and management center integrations in Security Cloud Control Firewall Management.

Support scope

Security Cloud Control Firewall Management is a cloud-based management solution for security policies and device configurations across multiple security platforms. The source identifies support for these management areas:

  • Cisco Secure Firewall ASA, both on-premises and virtual

  • Cisco Secure Firewall Threat Defense (FTD), both on-premises and virtual

  • Cisco Catalyst SD-WAN Manager

  • Cisco Secure Firewall Management Center, on-premises

Security Cloud Control Firewall Management documentation identifies the devices, software, and hardware that Security Cloud Control Firewall Management supports. If the documentation does not explicitly claim support for a software version or device type, Security Cloud Control Firewall Management does not support it.

Cisco Secure Firewall ASA

Cisco Adaptive Security Appliance (ASA) is a security device that integrates firewall, VPN, and intrusion prevention capabilities. Security Cloud Control supports ASA device management to streamline configuration management and support regulatory compliance across the network infrastructure.

Cisco Secure Firewall Threat Defense

Cisco Secure Firewall Threat Defense integrates traditional firewall features with advanced threat protection capabilities. It includes security functions such as intrusion prevention, application control, URL filtering, and advanced malware protection.

A Secure Firewall Threat Defense device can be deployed on ASA hardware appliances, Cisco firewall hardware appliances, and virtual environments. You can manage threat defense devices through management interfaces such as Cisco Firewall Management Center, Security Cloud Control, and Firewall Device Manager.

Firewall Threat Defense integrates traditional firewall features with advanced threat protection capabilities. It offers comprehensive security functions, including intrusion prevention, application control, URL filtering, advanced malware protection, and so on. An FTD can be deployed on ASA hardware appliances, and Cisco firewall hardware appliances, and in virtual environments. Managing threat defense devices is possible through various management interfaces, such as Cisco Firewall Management Center and Security Cloud Control

For more information on software and hardware compatibility, see the Cisco Secure Firewall Threat Defense Compatibility Guide.

Cisco Secure Firewall Management Center

Security Cloud Control Firewall Management simplifies the management of on-premises Firewall Management Center by establishing a secure integration, discovering security devices, and enabling centralized policy management. Security policies such as firewall rules, VPN settings, and intrusion prevention policies can be efficiently managed and deployed across all devices under FMC.

ASA support specifics

Security Cloud Control Firewall Management support for ASA has these constraints:

  • Security Cloud Control Firewall Management can manage all ASA platforms that run currently supported code versions, including ASAv instances.

  • Security Cloud Control Firewall Management does not support ASA Services Module (ASASM).

  • Security Cloud Control Firewall Management does not test end-of-life ASA code versions and does not recommend them for production.

  • Use currently supported ASA code versions for optimal results.

  • ASA 8.3 is not supported with the new policy view.

  • Security Cloud Control Firewall Management does not manage the ASA FirePOWER module because the module runs a different operating system from ASA. Manage the ASA FirePOWER module separately with Secure Firewall Management Center or ASDM.

  • End-of-life code and hardware might continue to work with Security Cloud Control Firewall Management. Because end-of-life code and hardware are not part of Security Cloud Control Firewall Management testing, correct operation with end-of-life software and hardware is not guaranteed or assured.

    Refer to the version download page for Cisco "suggested release" or "gold star" versions.

  • ASA versions 8.x, 9.1, and 9.2 do not support TLS 1.2 on the management plane and are considered insecure for ASA software management.

For a full discussion of ASA, ASDM, and hardware compatiblity, see the Cisco Secure Firewall ASA Compatibility guide.

Secure Firewall Threat Defense Device Support Specifics

Secure Firewall Threat Defense is Cisco's next generation firewall. It can be installed on a variety of hardware and virtual platforms; see the Cisco Secure Firewall Threat Defense Compatibility Guide.

Firewall Threat Defense with Secure Firewall Device Manager

You can add Security Cloud Control managment to threat defense Version 6.4+ with Firewall Device Manager. However, this option is only available upon request for those who already have device manager support enabled on their tenant. See:

Snort

Snort 3 is the default inspection engine for threat defense starting in threat defense Version 6.7 (with device manager) and Version 7.0 (with management center).


Important


If you are still using the Snort 2 inspection engine, switch to Snort 3 now for improved detection and performance. Snort 2 will be deprecated in a future release and will eventually prevent threat defense upgrade.


Cloud Device Support Specifics

The following table describes software and device type support for cloud-based devices. Read the affiliated links for more information about onboarding and feature functionality for the device types in the table below:

Devices Types

Notes

Google Cloud Platform

Google Cloud Platform (GCP) receives updates through the GCP console. Refer to Google Cloud documentation for more information about the platform and available services.

Microsoft Azure

Azure receives updates through the Azure console. Refer to Azure documentation for more information about the platform and available services.

Onboard Secure Firewall ASA

This chapter explains the various different methods using which a Secure Firewall ASA can be onboarded.

Onboard ASA device to Security Cloud Control Firewall Management

Use this procedure to onboard a single live ASA device, not an ASA model, to Security Cloud Control. If you want to onboard multiple ASAs at once, refer to Onboard ASAs in Bulk.

Before you begin

Device Prerequisites
  • The device must be running version 8.4 or later.


    Note


    TLS 1.2 became available for the ASA management plane in version 9.3(2). To onboard to Security Cloud Control Firewall Management using version 9.3(2), a local SDC is required.


  • The running configuration file of your ASA must be less than 4.5 MB.

  • IP addressing: Each ASA, ASAv, or ASA security context must have a unique IP address, and the SDC must connect to it on the interface configured to receive management traffic.

Certificate Prerequisites

If your ASA device does not have a compatible certificate, onboarding the device may fail. Make sure that these requirements are met:

  • The device must use TLS version 1.0 or later.

  • The certificate presented by the device must not be expired, and its issuance date must be in the past. This means the certificate is already valid and not scheduled to become valid later.

  • The certificate must be a SHA-256 certificate. SHA-1 certificates are not accepted.

  • One of the following conditions must be met:

    • The device uses a self-signed certificate, and it is the same as the most recent one trusted by an authorized user.

    • The device uses a certificate signed by a trusted Certificate Authority (CA) and provides a certificate chain that links the presented leaf certificate to the relevant CA.

Open SSL Cipher Prerequisites

If the device does not have a compatible SSL cipher suite, it cannot successfully communicate to the Secure Device Connector (SDC). Use any of these cipher suites:

  • ECDHE-RSA-AES128-GCM-SHA256

  • ECDHE-ECDSA-AES128-GCM-SHA256

  • ECDHE-RSA-AES256-GCM-SHA384

  • ECDHE-ECDSA-AES256-GCM-SHA384

  • DHE-RSA-AES128-GCM-SHA256

  • ECDHE-RSA-AES128-SHA256

  • DHE-RSA-AES128-SHA256

  • ECDHE-RSA-AES256-SHA384

  • DHE-RSA-AES256-SHA384

  • ECDHE-RSA-AES256-SHA256

  • DHE-RSA-AES256-SHA256

Procedure


Step 1

Choose Inventory.

Step 2

Choose Security Devices.

Step 3

Click the Onboard device or service (Add icon.) icon.

Step 4

Click the ASA tile.

Step 5

In the Locate Device step, perform the following:

  1. Enter a name for the device.

  2. Enter the location of the device or service (IP address, FQDN, or URL). The default port is 443.

  3. Click Next.

Step 6

In the Credentials step, enter the username and password of the ASA administrator, or similar highest-privilege ASA user, that Security Cloud Control will use to connect to the device and click Next.

Step 7

After labeling your device or service, you can view it in the Security Devices list.

Note

 

Analyzing the configuration may take some time, depending on its size and the number of devices or services.


Onboard a high availability pair of ASA devices to Security Cloud Control Firewall Management

Onboard only the primary ASA to Security Cloud Control Firewall Management. The failover link manages the secondary ASA automatically, so you do not need to onboard it separately. For more information about onboarding ASA devices to Security Cloud Control, refer to Onboard ASA device to Security Cloud Control Firewall Management.

Onboard an ASA in multi-context mode to Security Cloud Control Firewall Management

About multi-context mode

You can partition a single ASA, installed on a physical appliance, into multiple logical devices known as contexts. The three types of configurations used in an ASA configured in multi-context mode are:

  • Security context

  • Admin context

  • System configuration

About security contexts

Each security context acts as an independent device, with its own security policy, interfaces, and administrators. Multiple security contexts are similar to having multiple standalone devices. A security context is not a virtual ASA in the sense of a virtual machine image installed in a private cloud infrastructure. A security context is configured on an ASA that is installed on a hardware appliance. Each context is configured on a physical interface of that appliance.

For more information about multi-context mode, refer to ASA CLI and ASDM configuration guides.

Security Cloud Control Firewall Management onboards each security context as a separate ASA and manages it as if it were a separate ASA.

About admin contexts

The admin context is similar to a security context, except that when a user logs in to the admin context, the user has system administrator rights and can access the system and all other contexts. The admin context is not restricted in any way and can be used as a regular context. However, because logging into the admin context grants administrator privileges over all contexts, access to the admin context should be restricted to authorized users.

Security Cloud Control Firewall Management onboards each admin context as a separate ASA and manages it as if it were a separate ASA. Security Cloud Control Firewall Management also uses the admin context when upgrading ASA and ASDM software on the appliance.

About system configuration

The system administrator adds and manages contexts by configuring each context configuration location, allocated interfaces, and setting other context operating parameters within the system configuration, which, like a single mode configuration, is the startup configuration. The system configuration identifies basic settings for the ASA. The system configuration does not include any network interfaces or network settings for itself. When the system needs to access network resources, such as downloading the contexts from the server, it uses one of the contexts designated as the admin context.

Security Cloud Control Firewall Management does not onboard the system configuration.

Onboard prerequisites for security and admin contexts

Before you onboard security or admin contexts, check the prerequisites in Onboard ASA device to Security Cloud Control Firewall Management.

to up

To learn which Cisco appliances support ASAs in multi-context mode, refer to the "Multiple Context Mode" chapter in the CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide for your ASA software version.

An ASA running as a single context firewall, or as the admin context of a multiple-context firewall, can use different port numbers for ASDM and Security Cloud Control Firewall Management access. ASA security contexts use a fixed port (port 443) for ASDM and Security Cloud Control Firewall Management access.

Onboard ASA security and admin contexts

To onboard a security context or admin context, follow the instructions in Onboard ASA device to Security Cloud Control Firewall Management or Onboard multiple ASAs to Security Cloud Control Firewall Management.

Upgrade security contexts

Security Cloud Control Firewall Management treats each security and admin context of a multiple-context ASA as a separate ASA and each is onboarded separately. However, all security and admin contexts of a multiple-context ASA run the same version of ASA software installed on the appliance.

To upgrade the ASA and ASDM versions used by the security contexts, onboard the admin context and perform the upgrade there.

Onboard multiple ASAs to Security Cloud Control Firewall Management

Security Cloud Control Firewall Management allows you to bulk onboard ASA devices by providing the necessary information for all the ASA devices in a .csv file. As the ASA devices are being onboarded, you can use the filter pane to show which onboarding attempts are queued, loading, complete, or have failed.

Before you begin

  • Prepare a .csv file with the connection information for the ASA devices you want to onboard. Add the information about each ASA on a separate line. To include a comment, add a # at the beginning of the line.

    • ASA location (either IP address or FQDN)

    • ASA administrator username

    • ASA administrator password

    • (Optional) Device name for Security Cloud Control Firewall Management

    • (Optional) device labels for Security Cloud Control Firewall Management

    • To add one label, add the label name to the last CSV field.

    • To add more than one label to a device, surround the values with quotation marks. For example, alpha,beta,gamma.

    • To add a category and choice label, separate the two values with a colon (:). For example, Rack:50.

Here is a sample configuration file.


#Location,Username,Password,DeviceName,SDCName,DeviceLabel 
192.168.3.2,admin,CDO123!,ASA3,sdc1,"HA-1,Rack:50" 
192.168.4.2,admin,CDO123!,ASA4,sdc1,"HA-1,Rack:50" 
ASA2.example.com,admin,CDO123!,ASA2,none,Rack:51 
asav.virtual.io,admin,CDO123!,ASA-virtual,sdc3,Test

Caution


Security Cloud Control does not validate any of the data in the .csv file. You need to ensure the accuracy of the entries.


Procedure


Step 1

Choose Security Devices.

Step 2

Click the plus button to onboard an ASA.

Step 3

On the Onboarding page, click the Multiple ASAs tile.

Step 4

Click Browse to locate the .csv file containing your ASA entries. The devices you specify appear in the ASA Bulk Onboarding table as queued and are ready for onboarding.

Caution

 

Stay on the ASA Bulk Onboarding page until the onboarding process is complete. If you leave the page, the onboarding process stops.

Step 5

Click Start.

The status column in the ASA Bulk Onboarding table shows the progress of onboarding. When onboarding finishes, the status displays "Complete."


What to do next

To pause bulk onboarding and resume later, refer to Pause and resume onboarding multiple ASA devices.

Pause and resume onboarding multiple ASA devices

If you need to pause the onboarding process, click Pause. Security Cloud Control completes onboarding any device it has started. To resume bulk onboarding, click Start. Security Cloud Control will begin onboarding the next queued device.

If you click Pause and leave this page, you must return and restart the bulk onboarding process. Security Cloud Control identifies already onboarded devices, flags duplicates from this new attempt, and quickly starts onboarding the remaining queued devices.

Create and import an ASA model to Security Cloud Control Firewall Management

Procedure


Step 1

Choose Security Devices.

Step 2

Click the Devices tab.

Step 3

Click the ASA tab.

Step 4

Select an ASA device. In the Management section, click Configuration.

Step 5

To download the device configuration to your local computer, click Download.


Import ASA configuration

Before you begin

The ASA running configuration file you are onboarding must be less than 4.5 MB. Confirm the size of the configuration file before you onboard it.

Procedure


Step 1

Choose Inventory.

Step 2

Choose Security Devices.

Step 3

Click the add button (Add button.) to import the configuration file.

Step 4

Click Import configuration for offline management.

Step 5

Select the Device Type as ASA.

Step 6

Click Browse, and select the configuration file in text format to upload.

Step 7

After labeling your model device, you can view it in the Security Devices list.

Note

 

The configuration may take some time to be analyzed, depending on its size and the number of other devices or services.


Import Configuration for Offline Device Management

Importing a device configuration for offline management allows you to review, analyze, and optimize the settings of a device without requiring access to a live device in your network. In Security Cloud Control Firewall Management, these uploaded configuration files are referred to as models. A model represents a copy of a device configuration that you can be used for policy review, planning, and reuse.

You can import the configurations for the following device types into Security Cloud Control Firewall Management:

  • Adaptive Security Appliance (ASA): You can upload an ASA configuration file to create an ASA model for offline review and management. For more information, refer to Create and Import an ASA Model.

  • Cisco IOS devices such as Aggregation Services Routers (ASRs) and Integrated Services Routers (ISRs): You can upload a text-based running configuration file to create an IOS model for offline analysis and reuse.

After you import and process a configuration file, the model appears in the Security Devices list, where it can be labeled, reviewed, and managed like other supported devices in Security Cloud Control Firewall Management.