Remote Management Configuration (Classic Devices)
All Devices Except 7000 and 8000 Series
For information on configuring remote management for devices that use Classic licenses, see the quick start guide for your device.
7000 and 8000 Series Devices
Configure remote management of a 7000 or 8000 Series device using its local web interface, before you register the device to the FMC.
Before you can manage a Firepower device, you must set up a two-way, SSL-encrypted communication channel between the device and the Firepower Management Center. The appliances use the channel to share configuration and event information. High availability peers also use the channel, which is by default on port 8305/tcp.
To enable communications between two appliances, you must provide a way for the appliances to recognize each other, as follows:
-
The hostname or IP address of the appliance with which you are trying to establish communication.
In NAT environments, even if the other appliance does not have a routable address, you must provide a hostname or an IP address either when you are configuring remote management, or when you are adding the managed appliance.
-
A self-generated alphanumeric registration key up to 37 characters in length that identifies the connection.
-
An optional unique alphanumeric NAT ID that can help establish communications in a NAT environment.
The NAT ID must be unique among all NAT IDs used to register managed appliances.
Configuring Remote Management on a Managed Device
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
---|---|---|---|---|
Any |
Any |
7000 & 8000 Series |
N/A |
Admin/Network Admin |
Procedure
Step 1 |
On the web interface for the device you want to manage, choose . |
||
Step 2 |
Click Remote Management, if it is not already displaying. |
||
Step 3 |
Click Add Manager. |
||
Step 4 |
In the Management Host field, enter one of the following for the Firepower Management Center that you want to use to manage this appliance:
In a NAT environment, you do not need to specify an IP address or host name here if you plan to specify it when you add the managed appliance. In this case, the Firepower System uses the NAT ID you will provide later to identify the remote manager on the managed appliance’s web interface. |
||
Step 5 |
In the Registration Key field, enter the registration key that you want to use to set up communications between appliances. |
||
Step 6 |
For NAT environments, in the Unique NAT ID field, enter a unique alphanumeric NAT ID that you want to use to set up communications between appliances. |
||
Step 7 |
Click Save. |
What to do next
-
Wait until the appliances confirm that they can communicate with each other and the Pending Registration status appears.
-
Add this device to the Firepower Management Center; see Add Devices to the Firepower Management Center.
Editing Remote Management on a Managed Device
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
---|---|---|---|---|
Any |
Any |
7000 & 8000 Series |
N/A |
Admin/Network Admin |
When editing a remote manager, note that:
-
The Host field specifies the fully qualified domain name or the name that resolves through the local DNS to a valid IP address (that is, the host name).
-
The Name field specifies the display name of the managing appliance, which is used only within the context of the Firepower System. Entering a different display name does not change the host name for the managing device.
Procedure
Step 1 |
On the web interface for the device, choose . |
Step 2 |
Click Remote Management, if it is not already displaying. |
Step 3 |
You can:
|
Changing the Management Port
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
---|---|---|---|---|
Any |
Any |
7000 & 8000 Series FMC |
Global only |
Admin/Network Admin |
Appliances communicate using a two-way, SSL-encrypted communication channel, which by default is on port 8305.
Although Cisco strongly recommends that you keep the default setting, you can choose a different port if the management port conflicts with other communications on your network. Usually, changes to the management port are made during installation.
![]() Caution |
If you change the management port, you must change it for all appliances in your deployment that need to communicate with each other. |
Procedure
Step 1 |
Choose . |
Step 2 |
Click Management Interfaces. |
Step 3 |
In the Shared Settings section, enter the port number that you want to use in the Remote Management Port field. |
Step 4 |
Click Save. |
What to do next
Repeat this procedure for every appliance in your deployment that must communicate with this appliance.