Overview
Lists the prerequisites for deploying Cisco Umbrella SASE auto tunnel with Secure Firewall.
General Prerequisites
-
Complete the Threat Defense Initial Configuration Using the Device Manager
-
Add routes for internet access. See Add a Static Route.
-
Log into Umbrella at http://login.umbrella.com, and obtain the required information to establish a connection to Cisco Umbrella. Ensure the management center can reach management.api.umbrella.com.
-
Register your Cisco Umbrella organisation with the management center and configure the management key and the management secret in the Cisco Umbrella Connection advanced settings. This fetches the datacenter details from the Cisco Umbrella cloud. You must also configure the Organization ID, Network Device Key, Network Device Secret, and the Legacy Network Device Token in the Cisco Umbrella Connection general settings.
For more information, see:
-
Ensure that Umbrella data center is reachable from the threat defense.
-
Ensure the threat defense supports route-based VPN with local tunnel ID support (Version 7.1.0 and later). You can deploy a SASE tunnel with local tunnel ID support in management center version 7.3.0 and later.
License Prerequisites
-
You must have a Cisco Umbrella Secure Internet Gateway (SIG) Essentials subscription or a free SIG trial version.
-
You must enable your Smart License account with the export-controlled features to deploy tunnels on Umbrella from the management center.