About System Configuration
System configuration settings apply to either a Firepower Management Center or a Classic managed device (7000 and 8000 Series, ASA FirePOWER, NGIPSv):
-
For the Firepower Management Center these configuration settings are part of a "local" system configuration. Note that system configuration on the Firepower Management Center is specific to a single system, and changes to a FMC's system configuration affect only that system.
-
For a Classic managed device, you apply a configuration from the Firepower Management Center as part of a platform settings policy. You create a shared policy to configure a subset of the system configuration settings, appropriate for managed devices, that are likely to be similar across a deployment.
Tip
For 7000 and 8000 Series devices, you can perform limited system configuration tasks from the local web interface, such as console configuration and remote management. These are not the same configurations that you apply to a 7000 or 8000 Series device using a platform settings policy.
Navigating the Firepower Management Center System Configuration
Smart License |
Classic License |
Supported Devices |
Supported Domains |
Access |
---|---|---|---|---|
Any |
Any |
FMC |
Global only |
Admin |
The system configuration identifies basic settings for a Firepower Management Center.
Procedure
Step 1 |
Choose . |
Step 2 |
Use the navigation panel to choose configurations to change; see Table 1 for more information. |
System Configuration Settings
Note that for managed devices, many of these configurations are handled by a platform settings policy applied from the FMC; see Platform Settings Policies. For 7000/8000 series devices, you can also log into the local web interface for non-policy based system configurations; see Local System Configuration for 7000/8000 Series Devices.
Setting |
Description |
---|---|
Access Control Preferences |
Configure the system to prompt users for a comment when they add or modify an access control policy; see Policy Change Comments. |
Access List |
Control which computers can access the system on specific ports; see Access List. |
Audit Log |
Configure the system to send an audit log to an external host; see Audit Logs. |
Audit Log Certificate |
Configure the system to secure the channel when streaming the audit log to an external host; see Audit Log Certificate . |
Change Reconciliation |
Configure the system to send a detailed report of changes to the system over the last 24 hours; see Change Reconciliation. |
Console Configuration |
Configure console access via VGA or serial port, or via Lights-Out Management (LOM); see Remote Console Access Management. |
Dashboard |
Enable Custom Analysis widgets on the dashboard; see Dashboard Settings. |
Database |
Specify the maximum number of each type of event that the Firepower Management Center can store; see Database Event Limits. |
DNS Cache |
Configure the system to resolve IP addresses automatically on event view pages; see DNS Cache. |
Email Notification |
Configure a mail host, select an encryption method, and supply authentication credentials for email-based notifications and reporting; see Email Notifications. |
External Database Access |
Enable external read-only access to the database, and provide a client driver to download; see External Database Access Settings. |
HTTPS Certificate |
Request an HTTPS server certificate, if needed, from a trusted authority and upload certificates to the system; see HTTPS Certificates. |
Information |
View current information about the appliance and edit the display name; see Appliance Information. |
Intrusion Policy Preferences |
Configure the system to prompt users for a comment when they modify an intrusion policy; see Policy Change Comments. |
Language |
Specify a different language for the web interface; see Language Selection. |
Login Banner |
Create a custom login banner that appears when users log in; see Login Banners. |
Management Interfaces |
Change options such as the IP address, hostname, and proxy settings of the appliance; see Management Interfaces. |
Network Analysis Policy Preferences |
Configure the system to prompt users for a comment when they modify a network analysis policy; see Policy Change Comments. |
Process |
Shut down, reboot, or restart Firepower processes; see Shut Down or Restart. |
Remote Storage Device |
Configure remote storage for backups and reports; see Remote Storage Management. |
REST API Preferences |
Enable or disable access to the Firepower Management Center via the Firepower REST API; see REST API Preferences. |
Shell Timeout |
Configure the amount of idle time, in minutes, before a user’s login session times out due to inactivity; see Session Timeouts. |
SNMP |
Enable Simple Network Management Protocol (SNMP) polling; see SNMP Polling. |
Time |
View and change the current time setting; see Time and Time Synchronization. |
Time Synchronization |
Manage time synchronization on the system; see Time and Time Synchronization. |
UCAPL/CC Compliance |
Enable compliance with specific requirements set out by the United States Department of Defense; see Enable Security Certifications Compliance. |
VMware Tools |
Enable and use VMware Tools on a Firepower Management Center Virtual; see VMware Tools and Virtual Systems. |
Vulnerability Mapping |
Map vulnerabilities to a host IP address for any application protocol traffic received or sent from that address; see Vulnerability Mapping. |