Which Application and Manager is Right for You?

Your hardware platform can run one of two applications: Secure Firewall Threat Defense or ASA. For each application, you have a choice of managers. This chapter explains the application and manager choices.

Applications

You can use either of the following applications on your hardware platform:

  • Firewall Threat Defense—The Firewall Threat Defense (formerly Firepower Threat Defense) is a next-generation firewall that combines an advanced stateful firewall, VPN concentrator, and next generation IPS.

  • ASA—The ASA is a traditional, advanced stateful firewall and VPN concentrator.

Cisco provides ASA-to-Firewall Threat Defense migration tools to help you convert your ASA to the Firewall Threat Defense if you start with ASA and later reimage to Firewall Threat Defense.

To reimage between the ASA and the Firewall Threat Defense, see the Cisco Secure Firewall ASA and Secure Firewall Threat Defense Reimage Guide.

Managers

The Firewall Threat Defense and ASA support multiple managers.

Firewall Threat Defense Managers

Table 1. Firewall Threat Defense Managers

Manager

Description

Secure Firewall Management Center (formerly Firepower Management Center)

The Firewall Management Center is a multi-device manager that runs on its own server hardware, or as a virtual device on a hypervisor.

For a local Firewall Management Center, see Firewall Threat Defense Deployment with the Firewall Management Center.

For a remote Firewall Management Center, see Firewall Threat Defense Deployment with a Remote Firewall Management Center.

Security Cloud Control (formerly Cisco Defense Orchestrator) Cloud-Delivered Firewall Management Center

Security Cloud Control's Cloud-Delivered Firewall Management Center has all of the configuration functionality of an on-premises management center. For the analytics functionality, you can use a cloud solution or an on-prem management center. Security Cloud Control also manages other security devices, such as ASAs.

See Firewall Threat Defense Deployment with Security Cloud Control.

Secure Firewall Device Manager (formerly Firepower Device Manager)

The Firewall Device Manager is a simplified, on-device manager. Some Firewall Threat Defense features are not supported using the Firewall Device Manager.

See Firewall Threat Defense Deployment with the Firewall Device Manager.

Secure Firewall Threat Defense REST API

The threat defense REST API lets you automate direct configuration of the Firewall Threat Defense. You cannot use this API if you are managing the Firewall Threat Defense using the Firewall Management Center or Security Cloud Control.

The threat defense REST API is not covered in this guide. For more information, see the Cisco Secure Firewall Threat Defense REST API Guide.

Secure Firewall Management Center REST API

The management center REST API lets you automate configuration of Firewall Management Center policies that can then be applied to managed Firewall Threat Defenses. This API does not manage the Firewall Threat Defense directly.

The management center REST API is not covered in this guide. For more information, see the Secure Firewall Management Center REST API Quick Start Guide.

ASA Managers

Table 2. ASA Managers

Manager

Description

CLI

You can use the CLI to configure all ASA functionality.

The CLI is not covered in this guide. For more information, see the ASA configuration guides.

Adaptive Security Device Manager (ASDM)

ASDM is a Java-based, on-device manager that provides full ASA functionality.

See ASA Appliance Mode Deployment with ASDM. If you know you want to use the ASA in Platform mode, see ASA Platform Mode Deployment with ASDM and Firewall Chassis Manager

Security Cloud Control

Security Cloud Control is a cloud-based, multi-device manager. Security Cloud Control also manages other security devices, such as Firewall Threat Defenses.

Security Cloud Control for ASA is not covered in this guide. To get started with Security Cloud Control, see the Security Cloud Control home page.

Cisco Security Manager (CSM)

CSM is a multi-device manager that runs on its own server hardware. CSM does not support managing the Firewall Threat Defenses.

CSM is not covered in this guide. For more information, see the CSM user guide.

ASA HTTP Interface

Using HTTP, an automation tool can execute commands on the ASAs by accessing specifically formatted URLs.

The ASA HTTP interface is not covered in this guide. For more information, see the Cisco Secure Firewall ASA HTTP Interface for Automation.