Learn how Security Cloud Control Firewall Management unifies firewall and device management, simplifies policy consistency, supports multiple device managers, and helps reconcile configuration changes across Cisco security environments.
Get started with Security Cloud Control Firewall Management
Learn how to get started with Security Cloud Control Firewall Management, including supported products, licenses, maintenance schedules, Cloud-Delivered Firewall Management Center setup, provisioning, access, and dashboard monitoring.
How To Request a Security Cloud Control Tenant
Learn about foundational Security Cloud Control Firewall Management setup, sign-in, licensing, platform support, objects, and network address translation concepts used before managing AWS VPC resources.
Sign in to Security Cloud Control
An overview of network address translation for ASA devices, including NAT rule types, translated addresses, interface scope, IPv4 and IPv6 translation, policy impact, and rule management tasks.
Manage Tenants and Users
Learn how to manage Security Cloud Control user records, identity provider relationships, Super Admin roles, support access, API users, and invitations for tenant access.
Onboard devices in Security Cloud Control Firewall Management
Find supported devices, software versions, hardware, and management constraints for Security Cloud Control Firewall Management, including ASA, Threat Defense, Meraki, IOS, Umbrella, AWS, SD-WAN, and management center integrations.
Manage objects
Learn how to create, edit, compare, filter, share, override, and clean up reusable network, service, URL, and application objects used across device policies in Security Cloud Control.
Manage Firewall administration in Security Cloud Control Firewall Management
Learn how to manage organization-wide firewall settings, user access, notifications, logging visibility, filters, and role permissions in Security Cloud Control Firewall Management.
Onboard devices in Security Cloud Control Firewall Management
Find supported devices, software versions, hardware, and management constraints for Security Cloud Control Firewall Management, including ASA, Threat Defense, Meraki, IOS, Umbrella, AWS, SD-WAN, and management center integrations.
Manage objects
Learn how to create, edit, compare, filter, share, override, and clean up reusable network, service, URL, and application objects used across device policies in Security Cloud Control.
About Dynamic Attributes Connector
General information about the dynamic attributes connector.
Configure the Dynamic Attributes Connector
Configure the dynamic attributes connector in Security Cloud Control.
Dynamic firewall
After configuring an identity source and assuming you have integrated Cisco Identity Intelligence with systems like a user source and human resources systems, you can add user trust scores to user identity mappings. This information can be used by the Secure Firewall Management System in access control policies.
Use Dynamic Objects in Access Control Policies
Introduces dynamic objects for creating flexible access control policies and guides users through implementing dynamic attributes, filters, and rule conditions across network security policies.
Troubleshoot the Dynamic Attributes Connector
Provides troubleshooting guidance for common error messages, subscription issues, and certificate authority problems using both command line and graphical interface methods.
Onboard Secure Firewall ASA
Learn how to onboard ASA devices and services in Security Cloud Control Firewall Management, including single-device onboarding, bulk onboarding, model import, high-availability considerations, and ASA/ASDM software upgrades.
Configure Secure Firewall ASA
Learn how to manage ASA security policies in Security Cloud Control Firewall Management.
Monitor Secure Firewall ASA Events
Learn how to send ASA syslog and NSEL events to Cisco cloud analytics, configure Secure Event Connector destinations, create macros, verify event flows, and troubleshoot logging data.
Monitor device health metrics
Learn how Security Cloud Control effectively monitors the performance of your ASA devices. Monitor device health metrics to review status, performance indicators, and device conditions that help identify operational issues.
Use Cisco Secure Cloud Analytics Portal
Upgrade Secure Firewall ASA
Learn how to upgrade Secure Firewall ASA and ASDM images in Security Cloud Control Firewall Management for single devices, multiple devices, high availability pairs, and custom image repositories.
Troubleshoot Secure Firewall ASA
Learn how to troubleshoot Secure Firewall ASA issues in Security Cloud Control, including reconnect failures, certificate errors, CLI diagnostics, Remote Access VPN, real-time logging, packet tracer, advisories, and large configurations.
Onboard a Firewall Threat Defense Device
Learn how to onboard Firewall Threat Defense devices for management with Cloud-Delivered Firewall Management Center or by association through an onboarded On-Premises Firewall Management Center.
Migrate Threat Defense to Cloud-Delivered Firewall Management Center
Migrate on-prem managed-threat defense device (FTD) to Cloud-Delivered Firewall Management Center.
Configure Cloud-Delivered Firewall Management Center-Managed Secure Firewall Threat Defense
Introduction to AgenticOps insights
Learn how to manage Secure Firewall Threat Defense with Security Cloud Control, including onboarding, migration, configuration, AIOps insights, Agent Workforce, Security Analytics and Logging, dashboards, and policy optimization.
Introduction to Agent Workforce
Learn how Agent Workforce in Security Cloud Control uses AI-driven agents to troubleshoot VPN issues, remediate traffic congestion, analyze operations, and optimize firewall policies through natural language workflows.
Monitor Cloud-Delivered Firewall Management Center-Managed Threat Defense Device Events
Learn how to send and monitor Cloud-Delivered Firewall Management Center-managed Threat Defense events in Security Cloud Control using Security Analytics and Logging.
FTD Dashboard
An overview of the FTD Dashboard in Security Cloud Control, including how to understand and view predefined widgets for threat, network, application, and device status insights.
Analyze and Remediate Security Policy Anomalies with Policy Analyzer and Optimizer
Security Cloud Control provides the Policy Analyzer and Optimizer, which is an intelligent cloud service that can analyze security policies, detect anomalies, and provide recommendations on remediations that can be performed to optimize the policies.
Integrate Catalyst SD-WAN Manager with Security Cloud Control
This chapter explains the integration of Catalyst SD-WAN Manager with Security Cloud Control.
Onboard Catalyst SD-WAN Manager
Learn how to onboard Catalyst SD-WAN Manager to Security Cloud Control, align RBAC models, manage NGFW capabilities, view intrusion and malware events, and deboard the integration.
Configure Next-Generation Firewall Capabilities of Catalyst SD-WAN Manager
Learn how the integration of Security Cloud Control Firewall Management and Catalyst SD-WAN Manager allows you to manage (create, view, edit, and deploy).
Monitor Catalyst SD-WAN Events
Learn how Security Analytics and Logging captures Catalyst SD-WAN connection events in Security Cloud Control, enabling centralized event viewing, filtering, searching, threat hunting, and security rule analysis.
Onboard an On-Premises Firewall Management Center
Learn how to onboard, integrate, redirect, and remove an on-premises Firewall Management Center in Security Cloud Control. This chapter also covers supported devices, software versions, hardware, and Cisco Security Cloud integration paths.
Configure On-Premises Firewall Management Center-Managed Threat Defense Devices
This chapter guides users through configuring, managing, and deploying changes to on-premises Firewall Management Center devices using Security Cloud Control, including viewing, updating, and removing managed resources.
Onboard an Umbrella Organization
An overview of onboarding an Umbrella organization including prerequisites, connector selection, credentials, labels, and inventory results.
Configure an Umbrella Organization
Learn how to configure an Umbrella organization for ASA devices, including ASA integration with Cisco Umbrella and secure internet gateway use cases.
Onboard Cisco Meraki MX devices
Learn how to onboard Cisco Meraki MX devices and templates by preparing API access, retrieving the Meraki API key, and adding networks or configuration templates to Security Cloud Control.
Configure Cisco Meraki
An overview of managing Cisco Meraki with Security Cloud Control, including onboarding Meraki MX devices and templates, updating credentials, managing access control policies, and understanding how changes are deployed through the Meraki dashboard.
Onboard AWS VPC
Learn how to onboard AWS VPCs to Security Cloud Control Firewall Management.
Configure AWS VPC
Learn how to manage AWS VPC credentials, monitor VPN tunnel connectivity, review AWS VPC policy, and create, edit, or delete AWS security group rules.
Onboard Cisco IOS Devices
Learn how to onboard live Cisco IOS devices and model configurations in Security Cloud Control, including SSH requirements, Secure Device Connector selection, credentials, cipher support, imports, and downloads.
Configure Cisco IOS
Learn how to view full Cisco IOS device configurations and use the Security Cloud Control command-line interface to run commands, manage macros, and inspect device settings.
Onboard an SSH Device
Learn how to onboard network devices with Generic SSH access to Security Cloud Control, review supported platforms, use Secure Device Connector prerequisites, and delete onboarded SSH devices.
Configure SSH Devices
Learn how to configure Generic SSH devices in Security Cloud Control, including device management capabilities and command line interface workflows for supported SSH-accessible devices.
Virtual Private Network Management
Configuring Firewall for Universal Zero Trust Network Access
Universal Zero Trust Network Access solution comprises Secure Firewall and Secure Access to provide secure access to private resources. Secure Firewall manages Firewall Threat Defense through a Firewall Management Center. Configure uZTNA on a Firewall Threat Defense device and associate private resources to enable traffic inspection and secure access to the resources.
Manage device configuration
Learn how to detect and resolve configuration conflicts between Security Cloud Control and managed devices, automatically accept out-of-band changes, and schedule polling to keep device configurations in sync.
Manage onboarded device settings
Learn how to find devices, objects, and policies in Security Cloud Control Firewall Management using inventory views, labels, filters, page search, and global search.
Use the Security Cloud Control Command Line Interface Tool (CLI)
Learn how to use the command line interface to run ASA commands, review command output, and apply configuration changes across selected managed devices.
Manage CLI Templates
An overview of managing CLI templates in Security Cloud Control, including creating reusable command templates, adding parameters, and applying customized configurations across supported devices.
Migrate Firewalls with the Migration Tool in Security Cloud Control
An overview of migrating firewalls with the Firewall Migration Tool in Security Cloud Control, including supported source firewalls, migration workflows, validation steps, and related migration documentation.
Events in Security Cloud Control
Learn how to view and analyze security events in Security Cloud Control, including event types, filtering, event details, and investigation workflows.
Security Analytics and Logging Licenses
Learn how to send syslog and NSEL events to Cisco cloud analytics, configure Secure Event Connector destinations, create macros, verify event flows, and troubleshoot logging data.
Secure Event Connectors
Install and configure Secure Event Connectors so firewall events can reach Security Cloud Control logging and analytics services.
View Events in Security Cloud Control Firewall Management
Learn how to view live and historical events in Security Cloud Control to filter event data, inspect details, and investigate firewall activity.
Monitor Remote Access Virtual Private Network Sessions from Secure Firewall ASA and Firewall Threat Defense
Learn how to monitor remote access VPN sessions on ASA devices, including active users, session details, filtering, and disconnect actions.
Monitor and report change logs, workflows, and jobs
Learn how to monitor change logs, workflows, jobs, change requests, and executive summary reports for operational visibility in Security Cloud Control.
Smart Licensing Dashboard
This concept explains how the Smart Licensing Dashboard provides centralized management, real-time insights, and efficient planning for license usage and compliance for Secure Firewall ASAs and Cloud-Delivered Firewall Management Center-managed Secure Firewall Threat Defense devices.
Troubleshooting
Learn how to troubleshoot errors in Security Cloud Control including issues with Secure Firewall ASA devices, Secure Device Connectors, Secure Event Connectors, and device connectivity states.
FAQ and support
Learn about Security Cloud Control FAQs and resources for onboarding, device types, troubleshooting, policy optimization, connectivity, data interfaces, personal information, and contacting support.
Security and Internet Access
Outlines the security requirements and internet access specifications needed for proper system deployment and operation.
Terraform
Learn how to automate the setup and management of your Security Cloud Control organization using Terraform providers and modules.
Open Source and 3rd Party License Attribution
An overview of Cisco Open Source and 3rd Party License Attribution, including the license notices for third-party components used in Security Cloud Control.
Cisco AI Assistant User Guide
An overview of the Cisco AI Assistant User Guide, including onboarding, prompt guidance, policy insights, policy optimization, automated rule creation, support case management, notifications, and FAQs.