Software Secure Firewall Threat Defense
Platform Secure Firewall Threat Defense Virtual
Activity Onboard

Device Operations Transparent or Routed Firewall Mode Set the Firewall Mode

Last updated: Jul 29, 2025

Set the Firewall Mode

You can set the firewall mode when you perform the initial system setup at the CLI. We recommend setting the firewall mode during setup because changing the firewall mode erases your configuration to ensure you do not have incompatible settings. If you need to change the firewall mode later, you must do so from the CLI.

Procedure

1

Unregister the Firewall Threat Defense device from the Firewall Management Center.

You cannot change the mode until you unregister the device.

  1. Performance profiles are retained across firewall mode changes and can't be changed after you re-register. You must set the performance profile to Default. See the Performance Profile page in your platform settings policy (choose Devices > Platform Settings, and then click Edit (edit icon) for your policy).

    Deploy the configuration to make these changes.

  2. Choose Devices > Device Management.

  3. Next to the device you want to unregister, click More (more icon), and then click Delete.

2

Access the Firewall Threat Defense device CLI, preferably from the console port.

3

Change the firewall mode:

configure firewall [routed | transparent]


> configure firewall transparent
This will destroy the current interface configurations, are you sure that you want to proceed? [y/N] y
The firewall mode was changed successfully.


4

Re-register with the Firewall Management Center.