Learn how to onboard a Secure Firewall Threat Defense cluster to Cloud-Delivered Firewall Management Center using a CLI registration key, including platform support, cluster creation limits, policy assignment, licensing, labels, and post-onboarding actions.
The following table provides information about device models that support cluster onboarding and creation on the Cloud-Delivered Firewall Management Center:
| Secure Firewall Threat Defense Platforms |
Minimum Secure Firewall Threat Defense Version for Cluster Management |
Support cluster creation from Cloud-Delivered Firewall Management Center? |
|---|---|---|
| VMware, KVM |
7.2.1 |
Yes |
| AWS, GCP |
7.2.1 |
No |
| Azure |
7.3 |
No |
| Secure Firewall 3100 |
7.2.1 |
Yes |
| Firepower 4100 |
7.2.x |
No |
| Secure Firewall 4200 |
7.4 |
Yes |
| Firepower 9300 |
7.2.x |
No |
When you onboard a Secure Firewall Threat Defense cluster to Cloud-Delivered Firewall Management Center, you register only the cluster control node. After the control node registers, Cloud-Delivered Firewall Management Center discovers the data nodes in the cluster.
Before you begin
Read through the following limitations:
-
Firepower 4100 and Firepower 9300 devices must be clustered through the device's Firewall Chassis Manager.
-
Secure Firewall 3100 devices, Secure Firewall 4200 devices, KVM, and VMware environments must be clustered through the Secure Firewall Management Center UI.
-
Azure, AWS, and GCP environment clusters must be created through their own environment and onboarded to Secure Firewall Management Center.
Verify that the Secure Firewall Threat Defense virtual devices are successfully configured as a cluster before you register the cluster with Cloud-Delivered Firewall Management Center.
For example, in the Secure Firewall Threat Defense CLI, enter the
show cluster infocommand. Confirm that the output shows the cluster asOn, one unit inCONTROL_NODEstate, and the remaining units inDATA_NODEstate.
Procedure
| 1. | In the left pane, click . |
|
| 2. | Click Onboard device or service ( |
|
| 3. | Click the FTD tile. |
|
| 4. | Under Management Mode, select FTD. By selecting FTD under Management Mode, you will not be able to manage the device using the previous management platform. All existing policy configurations except for interface configurations will be reset. You must re-configure policies after you onboard the device.
|
|
| 5. | Select Use CLI Registration Key. |
|
| 6. | Enter the device name in the Device Name field and click Next. |
|
| 7. | In the Policy Assignment step, use the drop-down menu to select an access control policy to deploy once the device is onboarded. If you have no policies configured, select the Default Access Control Policy. |
|
| 8. | Specify whether the device you are onboarding is a physical or virtual device. If you are onboarding a virtual device, you must select the device's performance tier from the drop-down menu. |
|
| 9. | Select the subscription licenses you want to apply to the device. Click Next. |
|
| 10. | Security Cloud Control generates a command with the registration key. Paste the entire registration key as is into the device's CLI. |
|
| 11. | (Optional) Add labels to your device to help sort and filter the Security Devices page. Enter a label and select the blue plus button. Labels are applied to the device after it's onboarded to Security Cloud Control. Once the device is synchronized, select the device you just onboarded from the Security Devices page and select any of the options listed under the Device Management pane located to the right. We strongly recommend the following actions:
|
) icon.