Integrate Management Center with the Cisco Security Cloud
Cisco Security Cloud connects your Secure Firewall deployment to the breadth of Cisco's integrated security cloud services for a consistent experience that unifies visibility, enables automation, and strengthens your security across network, endpoints, and applications. Cisco Security Cloud offers a platform approach with simpler, more integrated cloud services that reduce the complexity of managing multiple products.
Use your Cisco Defense Orchestrator (CDO) account to authorize the management center to register to the Cisco Security Cloud and bring your Secure Firewall deployment onboard to the Cisco cloud tenancy. Registering your management center to the CDO enables you to do the following:
-
Establish consistent policy across management centers using shared object management.
-
Zero-Touch Provisioning of the threat defense devices.
-
Send events to the cloud and use various Cisco Security Cloud services to enrich your threat hunts and investigations.
-
Get a centralized view of inventory across management centers.
For more information about onboarding a management center to CDO, see Onboard an On-Prem Management Center.
To integrate the Secure Firewall Management Center with Cisco XDR, see the Cisco Secure Firewall Management Center and Cisco XDR Integration Guide.
Enable SecureX Integration
Integrate the management center with SecureX to onboard both the management center and its managed devices to a CDO tenant. This integration connects the management center to a suite of Cisco cloud services. When the management center is onboarded to CDO, you can view its managed devices, view managed network objects, and cross-launch to the management center UI to manage associated devices and objects.
Before you begin
-
CDO uses Cisco Security Cloud Sign On as its identity provider and Duo for multifactor authentication. Ensure that you have your Cisco Security Cloud Sign On credentials and can sign in to the Cisco regional cloud where your account was created.
-
This task requires a CDO tenant to integrate the management center with Cisco Security Cloud. If you do not already have a CDO tenant, request for a tenant or create one during this workflow. For more information, see Request a CDO Tenant.
-
Link your CDO tenant, the one you want to use for onboarding the management center, to your Security Services Exchange (SSE) account. For more information, see Link Your Cisco Defense Orchestrator and Cisco XDR Tenant Accounts.
-
Your management center must be between version 7.0.2 and 7.0.x, or version 7.2 and later to perform this task.
Procedure
Step 1 |
In the management center, choose . |
||
Step 2 |
Choose a Cisco regional cloud from the Current Region drop-down list.
|
||
Step 3 |
Click Enable SecureX. A separate browser tab opens to log you in to your CDO account. Make sure this page is not blocked by a pop-up blocker. |
||
Step 4 |
Click Continue to Cisco SSO. |
||
Step 5 |
Log in to your CDO account. If you do not have a Security Cloud Sign On account to log in to CDO and you want to create one, click Sign up now in the Security Cloud Sign On page. See Create a New Cisco Security Cloud Sign On Account. |
||
Step 6 |
Choose a CDO tenant that you want to use for this integration. The management center and the managed devices get onboarded to the CDO tenant that you choose here. If you do not already have a CDO tenant or if you want to use a new tenant for this integration, create a new tenant. See Request a CDO Tenant for more information. |
||
Step 7 |
Verify that the code displayed in the CDO login page matches the code provided by the management center. |
||
Step 8 |
Click Authorize FMC. |
||
Step 9 |
In the management center, configure the following:
|
||
Step 10 |
Click Save. |
Configure Management Center to Share Usage Metrics and Statistics with Cisco
Cisco Success Network is a cloud service that enables the management center to establish a secure connection to Cisco cloud and stream usage information and statistics. Streaming this telemetry provides a mechanism to select data of interest from the threat defense device and send it in a structured format to remote management stations for the following reasons:
-
To inform you of available, but unused features that can improve the effectiveness of the product in your network.
-
To inform you of additional technical support services and monitoring that are available for your product.
-
To help Cisco improve its products.
To know more about the telemetry data that Cisco collects, see Cisco Success Network Telemetry Data Collected from Cisco Secure Firewall Management Center Devices.
The management center establishes and maintains a secure connection with Cisco cloud at all times when either Cisco Support Diagnostics or Cisco Success Network is enabled. However, the management center and the threat defense devices establish and maintain secure connections with the Cisco cloud when Cisco Support Diagnostics is enabled. You can turn off this connection at any time by disabling both Cisco Success Network and Cisco Support Diagnostics, which disconnects the management center from the Cisco cloud.
You can enable Cisco Success Network when you register the management center with the Smart Software Manager.
Note |
|
Before you begin
Enable SecureX integration or register your management center with the Smart License to perform this task.
Procedure
Step 1 |
Click . |
||
Step 2 |
Under Cisco Cloud Support, check the Enable Cisco Success Network check box to enable this service.
|
||
Step 3 |
Click Save. |
Configure Management Center to Share Device Health Data with Cisco
Cisco Support Diagnostics is a user-enabled cloud-based TAC support service. When enabled, the management center and the managed devices establish a secure connection with the Cisco cloud to stream system health-related information.
Cisco Support Diagnostics provides an enhanced user experience during troubleshooting by allowing Cisco TAC to securely collect essential data from your device during the resolution of a TAC case. Moreover, Cisco periodically collects health data, and processes this data using an automated problem-detection system to notify you of issues if any. While data collection service during the resolution of a TAC case is available for all users with support contracts, the notification service is available only to users with specific service contracts.
Cisco Support Diagnostics allows both threat defense devices and the management center to establish and maintain secure connections with the Cisco cloud. The management center sends the collected data to the regional cloud selected on the SecureX Integration page.
You can turn off this connection at any time by disabling both Cisco Success Network and Cisco Support Diagnostics, which disconnect these features from the Cisco cloud.
Administrators can view a sample data set collected from the management center by following the steps in Producing Troubleshooting Files for Specific System Functions.
Before you begin
Enable SecureX integration or register your management center with the Smart License to perform this task.
Procedure
Step 1 |
Click . |
||
Step 2 |
Under Cisco Cloud Support, check the Enable Cisco Support Diagnostics check box to enable this service.
|
||
Step 3 |
Click Save. |