Cisco Security Cloud Control: Secure Firewall Management

PDF

Cisco Security Cloud Control: Secure Firewall Management

Overview of Firewall Threat Defense to Cloud-Delivered Firewall Management Center migration

Want to summarize with AI?

Log in

Learn how to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud-Delivered Firewall Management Center while preserving policies, configurations, and settings through Security Cloud Control Firewall Management.


Introduction

This feature enables you to migrate Firewall Threat Defense devices from On-Premises Firewall Management Center to Cloud-Delivered Firewall Management Center through Security Cloud Control Firewall Management. Migration enables organizations to move device management from on-premises infrastructure to Cisco’s cloud-based management. This migration preserves existing policies, objects, and configurations.

Customer benefits

  • Preserves existing policies and configuration

  • Imports device-specific configuration, including interfaces, routing, and related settings

  • Handles duplicate policy and object names according to defined conflict-resolution rules

  • Transfers feature licenses automatically

  • Supports high availability pairs and clusters

  • Provides 14-day evaluation window before permanent commit

  • Allows analytics to remain on-prem or move to cloud

  • Provides an intuitive troubleshooting page with status summaries and step‑by‑step progress to pinpoint issues.

  • Provides migration reports for validation and audit

User role changes

The user roles of the On-Premises Firewall Management Center are no longer applicable in Security Cloud Control Firewall Management after migration. Your authorization to perform tasks on the migrated device is based on your user role in Security Cloud Control Firewall Management. See the Users topic to understand the On-Premises Firewall Management Center Center and Cloud-Delivered Firewall Management Center user role mapping.


How Firewall Threat Defense Migration to Cloud-Delivered Firewall Management Center Works

Security Cloud Control Firewall Management performs migration in the following sequence:

  1. Onboards on-premises Firewall Management Center to Security Cloud Control Firewall Management.

  2. Exports configurations from on-premises Firewall Management Center.

  3. Imports shared policies, objects, and device-specific configurations to Cloud-Delivered Firewall Management Center.

  4. Registers Firewall Threat Defense devices with Cloud-Delivered Firewall Management Center.

  5. Starts a 14-day evaluation window to commit or revert changes.

  6. Allows a commit or revert changes.

After migration:

  • Cloud-Delivered Firewall Management Center manages devices and their configuration.

  • Events and analytics can be handled by either the on-premises Firewall Management Center (analytics-only mode) or Security Cloud Control Firewall Management.

  • Devices appear on the Security Devices page.


About 14-day evaluation period

When a migration job is successful, you have 14 days to test and assess migration changes using Cloud-Delivered Firewall Management Center. If you are convinced about the migration changes, we recommend that you commit the devices manually, and not wait for Secure Firewall Management Center to automatically commit the migration changes. You have a 14-day evaluation period to review and assess the migration changes that are made to the devices before Secure Firewall Management Center automatically commits them.

After successful migration:

  • You have 14 days to evaluate configuration.

  • You can undo the changes and continue managing the device with On-Premises Firewall Management Center.

  • You can commit migration changes to Cloud-Delivered Firewall Management Center.

After 14 days evaluation period:

  • Changes are automatically committed.

  • Revert is no longer possible after auto-commit.

During 14 day evaluation window:

  • High availability break may not be supported (depending on onboarding method).

  • Performing advanced high availability or cluster operations may result in migration commit failure.

  • Deleting devices is not allowed.

  • Changes made in Cloud-Delivered Firewall Management Center are lost, if reverted.


How Firewall Threat Defense licenses are handled during migration to Cloud-Delivered Firewall Management Center

  • When the Firewall Threat Defense is migrated to the cloud, all feature licenses associated with the device are transferred to Security Cloud Control and released from the Firewall Management Center to the Smart License pool. The device reclaims the device-specific licenses during its registration with Security Cloud Control. You need not apply license on the device again.

  • The device-specific licenses are not required if you want to keep devices in the Firewall Management Center for analytics.