Workflows
Device licenses
Firewall in Security Cloud Control cannot update the security databases if there is no license. We recommend that your FDM-managed device has at least an license.
If you are onboarding a device that has no license, this does not inhibit Security Cloud Control from onboarding the device. Instead, the device will experience a Connectivity status of "insufficient licenses". To resolve this issue, you must apply the correct licenses through the FDM-managed device UI.
|
If you onboard an FDM-managed device and opt in to schedule future security database updates and the device does not have a registered license, Security Cloud Control still creates the scheduled task but does not trigger the task until the appropriate licenses have been applied and the device is successfully synchronized. |
Security database updates are pending in FDM
If you update the security databases through the FDM-managed device UI, and you have conflict detection enabled on your device, Security Cloud Control detects the pending update as a conflict.
|
If you onboard your FDM-managed device and opt to schedule the updates, Security Cloud Control automatically updates the security databases as well as any other pending changes to the stored configuration during the next deploy. does not have to be a configuration deploy |
Device has OOB changes, or staged changes, during a security database update
If you schedule a security database update for an FDM-managed device that has out of band (OOB) changes, or staged changes that have not been deployed, Security Cloud Control only checks and updates the security databases. Security Cloud Control does not deploy OOB or staged changes.
Device already has a scheduled task to update the security databases
Each device can only have one scheduled task. If the device already has a scheduled task to update the security databases, creating a new one overwrites it. This applies to tasks that are created in either Security Cloud Control or an FDM-managed device.
No security database updates available
If there are no updates available, Security Cloud Control does not deploy anything to the device.
Security database updates for FDM-managed High Availability (HA) pair
Security database updates are applied only to the primary device of an HA pair.