Cisco

How search works in the Security Help Center:

  • The most relevant topics (based on weighting and matching to search terms) are listed first in the search results by default
  • Common Boolean operations are supported
  • Use double quotes to find a phrase (“specific phrase”)
  • Apply facets on the Search Results page to further scope search results by category
Login

Log In to the Cisco Security Documentation Portal

Search

Cisco Security Cloud Control: Secure Firewall Management

  • Introduction
    • Get started with Security Cloud Control Firewall Management
      • Overview of Cisco Security Cloud Control
        • Products and Solutions Supported by Security Cloud Control
      • Overview of Security Cloud Control Firewall Management
        • Security Cloud Control Firewall Management Platform Maintenance Schedule
        • Security Cloud Control Firewall Management licenses
        • More Supported Devices and Licenses
      • Overview of Cloud-Delivered Firewall Management Center
        • Enable Cloud-Delivered Firewall Management Center
        • Determine the Cloud-Delivered Firewall Management Center Version in Security Cloud Control Firewall Management
        • Cloud-Delivered Firewall Management Center licensing and registration
        • Cloud-Delivered Firewall Management Center Maintenance Schedule
      • Provision Security Cloud Control Firewall Management
      • Open Security Cloud Control Firewall Management
      • The Firewall Management dashboard
  • Configure Basic Settings
    • Manage Firewall administration in Security Cloud Control Firewall Management
      • Configure general settings
        • Enable AI Assistant for Firewall
        • Enable the option to auto-accept device changes
        • Enable Multicloud Defense SCC features
        • Enable object sharing with Multicloud Defense
        • Enable ASA health monitoring
        • Set the default conflict detection interval
        • Enable scheduled automatic deployments
        • Manage web analytics
        • Set the FDM Default recurring backup schedule
        • Auto onboard On-Prem FMCs from Cisco Security Cloud
        • Enable event data sharing with Talos
        • View firewall management instance details
        • Use the Security Cloud Control Firewall Management platform navigator
      • Manage users and groups within Security Cloud Control organization
      • Manage API-Only users for Security Cloud Control Firewall Management
      • View Security Cloud Control notifications
        • Manage user notification preferences
      • View logging settings
      • Understand user roles in Security Cloud Control Firewall Management
        • Read-only role
        • Edit-Only role
        • Deploy-Only role
        • VPN Sessions Manager role
        • Admin role
        • Super Admin role
      • Filters on security devices, policies, and objects page
    • Onboard devices in Security Cloud Control Firewall Management
      • Introduction to Secure Connectors
        • About Secure Device Connector
          • Plan device connectivity
          • Allow inbound access for direct cloud connectivity
          • Plan SDC capacity and host requirements
          • Deploy a VM for Running the Secure Device Connector and Secure Event Connector
          • Deploy a Secure Device Connector On Your VM
          • Bootstrap a Secure Device Connector on the Deployed Host
          • Deploy a Secure Device Connector to vSphere Using Terraform
          • Deploy a Secure Device Connector on an AWS VPC Using a Terraform Module
          • Migrate an On-Premises Secure Device Connector and Secure Event Connector from a CentOS 7 Virtual Machine to an Ubuntu Virtual Machine
          • Change the IP Address of a Secure Device Connector
          • Rename a Secure Device Connector
          • Specify a default Secure Device Connector
          • Update a Secure Device Connector manually
          • Use multiple Secure Device Connectors on one organization
          • Find devices that sse the same Secure Device Connector
          • Remove a Secure Device Connector
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
    • Manage objects
      • Introduction to objects
        • Supported object types
        • Shared objects
        • Object Overrides
        • Unassociated objects
        • Compare objects
        • Object filters
          • Configure object filters
          • Exclude device filters when you need full relationships
        • Delete objects
          • Delete a single object
          • Delete a group of unused objects
        • Create an ASA IP address pool
      • Network objects
        • Create or Edit ASA Network Objects and Network Groups
          • Create an ASA Network Object
          • Create an ASA Network Group
          • Edit an ASA Network Object
          • Edit an ASA Network Group
          • Add Additional Values to a Shared Network Group in Security Cloud Control
          • Edit Additional Values in a Shared Network Group in Security Cloud Control
          • Deleting Network Objects and Groups in Security Cloud Control
        • Create or Edit a Firepower Network Object or Network Groups
          • Create a Firepower Network Object
          • Create a Firepower Network Group
          • Edit a Firepower Network Object
          • Edit a Firepower Network Group
          • Add an Object Override
          • Edit Object Overrides
          • Add Additional Values to a Shared Network Group
          • Edit Additional Values in a Shared Network Group
          • Deleting Network Objects and Groups in Security Cloud Control
        • Discover and manage On-Premises Firewall Management Center network objects
        • Objects Associated with Meraki Devices
        • Create a Local Meraki Network Object
        • Create or Edit a Meraki Network Object or Network Group
          • Create a Meraki Network Object
          • Create a Meraki Network Group
          • Edit a Firepower Network Object or Network Group
          • Deleting Network Objects and Groups in Security Cloud Control
      • URL objects
        • Create or Edit an FDM-Managed URL Object
        • Create a Firepower URL Group
          • Edit a Firepower URL Object or URL Group
      • Geolocation objects
        • Create and Edit a Firepower Geolocation Filter Object
          • Edit a Geolocation Object
      • DNS group objects
        • Create a DNS Group Object
        • Edit a DNS Group Object
        • Delete a DNS Group Object
      • Certificate objects
        • About certificates
        • Certificate Types Used by Feature
        • Configuring Certificates
        • Uploading Internal and Internal CA Certificates
          • Procedure
        • Uploading Trusted CA Certificates
          • Procedure
        • Generating Self-Signed Internal and Internal CA Certificates
          • Procedure
      • ASA trustpoint objects
        • Add an identity certificate object by using PKCS12
        • Create a self-signed ASA identity certificate object
        • Add an ASA identity certificate object for a Certificate Signing Request (CSR)
        • Add a trusted CA certificate object for ASA
        • Self-Signed and CSR certificate generation based on certificate contents
      • IPsec proposal and IKE policy objects
        • Create or edit an IKEv1 IPsec proposal object
        • Create or edit an IKEv2 IPsec proposal object
      • Global IKE policies
        • Create or edit an IKEv1 policy
        • Create or edit an IKEv2 policy
      • Remote access VPN objects
        • Identity sources for ASA
          • Determining the directory base DN
          • RADIUS servers and groups
          • Create an ASA Active Directory realm object
            • Edit an ASA Active Directory realm object
          • Create an ASA RADIUS server object or group
            • Create an ASA RADIUS server object
            • Create an ASA RADIUS server group
            • Edit an ASA Radius server object or group
        • Create ASA RA VPN group policies
          • ASA RA VPN group policy attributes
        • Create a new RA VPN group policy
          • RA VPN group policy attributes
      • Service objects
        • Create and Edit ASA Service Objects
          • Create an ASA Service Group
          • Edit an ASA Service Object or Service Group
        • Create and edit Firepower service objects
          • Create a Firepower Service Group
          • Edit a Firepower service object or service group
        • Create or Edit a Meraki Service Object
          • Create a Service Object
          • Create a Service Group
          • Edit a Service Object or a Service Group
      • Security group tag group
        • Security Group Tags
        • Create an SGT Group
        • Edit an SGT Group
        • Add an SGT Group to an Access Control Rule
      • ASA time range objects
        • Create an ASA time range object
        • Edit an ASA time range object
    • Dynamic Attributes Connector
      • About the Dynamic Attributes Connector
        • How It Works
      • About the dashboard
        • Dashboard of an unconfigured system
        • Dashboard of a configured system
        • Add, edit, or delete connectors
        • Add, edit, or delete dynamic attributes filters
        • Add, edit, or delete adapters
      • Create a connector
        • Amazon Web Services connector—About user permissions and imported data
          • Create an AWS user with minimal permissions for the dynamic attributes connector
          • Create an AWS connector
        • Amazon Web Services Security Groups connector—About user permissions
          • Create an AWS Security Groups connector
        • Create an AWS service tags connector
        • Azure connector—About user permissions and imported data
          • Create an Azure user with minimal permissions for the dynamic attributes connector
          • Create an Azure connector
        • Create an Azure Service Tags connector
        • Create a Multicloud Defense connector
        • Create a Cisco Cyber Vision connector
        • Create a generic text connector
          • Manually get a certificate authority (CA) chain
        • Create a GitHub connector
        • Google Cloud connector—About user permissions and imported data
          • Create a Google Cloud user with minimal permissions for the dynamic attributes connector
          • Create a Google Cloud connector
        • Create an Office 365 connector
        • Tenable connector
          • About the Tenable connector
          • Get the Tenable API key and secret
          • Create a Tenable connector
          • About Tenable dynamic objects in IDS, IPS, and access control policies
        • Create a Webex connector
        • Create a Zoom Connector
      • Create an adapter
        • How to create an On-Premises Firewall Management Center adapter
        • How to create a Cloud-Delivered Firewall Management Center adapter
      • Create dynamic attributes filters
        • Dynamic attribute filter examples
      • Dynamic firewall
        • About the dynamic firewall
        • How to configure the dynamic firewall
          • Enable the dynamic attributes connector
          • Get required information for Identity Intelligence
          • Create an identity source and realm for the dynamic firewall
          • Create a dynamic firewall instance
          • Associate an identity source with Identity Intelligence
          • Configure Identity Intelligence
          • View system-defined filters
          • View system-defined access control rules
          • Edit the user exclusion list
          • View and edit the system-created access control policy
        • Create dynamic attributes filters
      • Use Dynamic Objects in Access Control Policies
        • About dynamic objects in access control rules
        • Create dynamic attributes filters
        • Dynamic attributes rule conditions
        • Create access control rules or DNS rules using dynamic attributes filters
        • Use dynamic objects in DNS policies
      • Troubleshoot the Dynamic Attributes Connector
        • Troubleshoot error messages
        • Get Your Tenant ID
        • Manually get a certificate authority (CA) chain
  • Manage Secure Firewall ASA
    • Onboard Secure Firewall ASA
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
      • Onboard Secure Firewall ASA
      • Onboard ASA device to Security Cloud Control Firewall Management
      • Onboard a high availability pair of ASA devices to Security Cloud Control Firewall Management
      • Onboard an ASA in multi-context mode to Security Cloud Control Firewall Management
      • Onboard multiple ASAs to Security Cloud Control Firewall Management
        • Pause and resume onboarding multiple ASA devices
      • Create and import an ASA model to Security Cloud Control Firewall Management
        • Import ASA configuration
    • Configure Secure Firewall ASA
      • Managing Secure Firewall ASA with Security Cloud Control Firewall Management
      • Update ASA connection credentials in Security Cloud Control Firewall Management
        • Move an ASA from one SDC to Another
      • ASA interface configuration
        • Configure an ASA Physical Interface
          • Configure IPv4 Addressing for ASA Physical Interface
          • Configure IPv6 Addressing for ASA Physical Interface
          • Configure Advanced ASA Physical Interface Options
          • Enable the ASA Physical Interface
        • Add an ASA VLAN Subinterface
          • Configure ASA VLAN Subinterfaces
          • Configure IPv4 Addressing for ASA Subinterface
          • Configure IPv6 Addressing for ASA Subinterface
          • Configure Advanced ASA Subinterface Options
          • Enable the Subinterface
          • Remove ASA Subinterface
        • About ASA EtherChannel Interfaces
          • Configure ASA EtherChannel
            • Edit ASA EtherChannel
            • Remove ASA EtherChannel Interface
      • ASA system settings policy in Security Cloud Control Firewall Management
        • Create an ASA Shared System Settings Policy
          • Configure Basic DNS Settings
          • Configure HTTP Settings
          • Set the Date and Time Using an NTP Server
          • Configure SSH Access
          • Configure System Logging
          • Enable Sysopt Settings
          • Assign a Policy from the Shared System Settings Page
        • Configure or Modify Device Specific System Settings
          • Assign a Policy from Device-Specific Settings Page
        • Auto Assignment of ASA Devices to a Shared System Settings Policy
        • Filter ASA Shared System Settings Policy
        • Disassociate Devices from Shared System Settings Policy
        • Delete Shared Settings Policy
      • ASA routing in Security Cloud Control Firewall Management
        • About ASA Static Route
          • Configure ASA Static Route
          • Edit ASA Static Route
          • Delete a Static Route
      • Manage security policies in Security Cloud Control Firewall Management
      • Manage ASA network security policy
        • About ASA Access Control Lists and Access Groups
        • Create an ASA Access List
        • Add a Rule to an ASA Access List
          • About System Log Activity
          • Deactivate Rules in an Access Control List
          • About Security Group Tags in ASA Policies
        • Assign Interfaces to ASA Access Control List
        • Create an ASA Global Access List
        • Share an ASA Access Control List with Multiple ASA Devices
        • Copy an ASA Access Control List to Another ASA
        • Copy a Rule Within or Across ASA Access Lists and Devices
        • Unshare a Shared ASA Access Control List
        • View ASA Access Policies Listing Page
        • Global Search of ASA Access Lists
        • Rename an ASA Access Control List
        • Delete a Rule from an ASA Access Control List
        • Delete an ASA Access Control List
      • Compare ASA network policies
      • Hit rates
        • View Hit Rates of ASA Policies
      • Search and filter ASA network rules in the access list
      • Shadowed rules
        • Find Network Policies with Shadowed Rules
        • Resolve Issues with Shadowed Rules
      • API tokens
      • ASA file management
        • Upload File to a Single ASA Device
        • Upload File to Multiple ASA Devices
        • Remove Files from ASA
      • Managing ASAs with pre-existing High Availability configuration
        • Configuration Changes Made to ASAs in Active-Active Failover Mode
      • Manage ASA configuration files
        • View a Device's Configuration File
      • Configure DNS on ASA
        • Procedure
      • ASA command line interface
        • Configure ASA Using Security Cloud Control CLI
        • ASA Bulk CLI Use Cases
          • Show all users in the running configuration of an ASA and then delete one of the users
          • Find all SNMP configurations on selected ASAs
        • ASA Command Line Interface Documentation
        • Manage the Device Configuration
          • Compare ASA Configurations Using Security Cloud Control
          • Restore an ASA Configuration
            • How to Restore an ASA Configuration
            • Troubleshooting
          • View a Device's Configuration File
          • Edit a Complete Device Configuration File
    • Monitor Secure Firewall ASA Events
      • About Security Analytics and Logging (SAL SaaS) for ASA devices
        • How ASA Events are Displayed in Security Cloud Control
      • Implementing Secure Logging Analytics (SaaS) for ASA devices
      • Send ASA syslog events to the Cisco Cloud using a Security Cloud Control Macro
        • Creating an ASA Security Analytics and Logging (SaaS) Macro
      • Send ASA syslog events to the Cisco Cloud using the command line interface
        • Security Cloud Control Command Line Interface for ASA
        • Forward ASA Syslog Events to the Secure Event Connector
        • Send ASA Syslog Events to the Cisco Cloud Using CLI
        • Create a Custom Event List
        • Include the Device ID in Non-EMBLEM Format Syslog Messages
      • NetFlow Secure Event Logging (NSEL) for ASA devices
        • Configuring NSEL for ASA Devices by Using a Security Cloud Control Macro
          • Open the Configuring NSEL Macro
          • Define the Destination of NSEL Messages and the Interval at Which They Are Sent to the SEC
          • Create a Class-Map that Defines which NSEL Events Will Be Sent to the SEC
          • Define a Policy-Map for NSEL Events
          • Disable Redundant Syslog Messages
          • Review and Send the Macro
        • Delete NetFlow Secure Event Logging (NSEL) Configuration from an ASA
          • Open the DELETE-NSEL Macro
          • Enter the Values in the Macro to Complete the No Commands
        • Determine the Name of an ASA Global Policy
        • Troubleshooting NSEL Data Flows
          • Verify that NSEL Events are Being Sent to the SEC
          • Use the "capture" Command to Capture NSEL Packets Sent from the ASA to the SEC
          • Verify that NetFlow Packets are Being Received by the Cisco Cloud
          • Check for Live NSEL Events
          • Check for Historical NSEL Events
      • Parsed ASA syslog events
    • Monitor device health metrics
      • About device health metrics
      • Enable ASA health monitoring
      • Bulk opt in or opt out of device health metrics
      • View the device health metrics dashboard
      • Troubleshooting device health metrics
    • Upgrade Secure Firewall ASA
    • Troubleshoot Secure Firewall ASA
      • Troubleshoot a Secure Firewall ASA device
        • ASA Fails to Reconnect to Security Cloud Control After Reboot
        • Cannot onboard ASA due to certificate error
          • Determine the OpenSSL Cipher Suite Used by your ASA
          • Cipher Suites Supported by Security Cloud Control's Secure Device Connector
          • Updating your ASA's Cipher Suite
        • Troubleshoot ASA using CLI commands
        • Troubleshoot ASA Remote Access VPN
        • ASA Real-time Logging
          • View ASA Real-time Logs
        • ASA Packet Tracer
          • Troubleshoot an ASA Device Security Policy
          • Troubleshoot an Access Rule
          • Troubleshoot a NAT Rule
          • Troubleshoot a Twice NAT Rule
          • Analyze Packet Tracer Results
        • Cisco ASA Advisory cisco-sa-20180129-asa1
        • Confirming ASA Running Configuration Size
        • Container Privilege Escalation Vulnerability Affecting Secure Device Connector: cisco-sa-20190215-runc
          • Updating a Security Cloud Control-Standard SDC Host
          • Updating a Custom SDC Host
          • Bug Tracking
        • Large ASA Running Configuration Files
  • Manage Secure Firewall Threat Defense with Cloud-Delivered Firewall Management Center
    • Onboard a Firewall Threat Defense Device
      • Onboarding Overview
      • Maximum Firewall Threat Defense devices supported in Cloud-Delivered Firewall Management Center
      • Prerequisites to Onboard a Device to Cloud-Delivered Firewall Management Center
      • Onboard a Device with a CLI Registration Key
      • Onboard a Firewall Threat Defense Device to Cloud-Delivered Firewall Management Center using Zero-Touch Provisioning
      • Onboard a Firewall Threat Defense Device to On-Prem Firewall Management Center using Zero-Touch Provisioning
      • Onboard Firewall Threat Defense Devices using Device Templates to Cloud-Delivered Firewall Management Center using Zero-Touch Provisioning
      • Cloud Deployment
        • Configure FTDv enforcement point
        • Configure Multicloud Defense enforcement point
      • Onboard a Secure Firewall Threat Defense Cluster
      • Onboard a Chassis
      • Complete the initial configuration of a Secure Firewall Threat Defense device using the CLI
      • Delete Devices from Cloud-Delivered Firewall Management Center
      • Troubleshooting
        • Troubleshoot Cloud-Delivered Firewall Management Center Connectivity with TCP
        • Troubleshoot Firewall Threat Defense Device Connectivity
        • Troubleshoot Device Connectivity Loss After Cloud-Delivered Firewall Management Center Update
        • Troubleshoot Onboarding a Device to the Cloud-Delivered Firewall Management Center Using the CLI Registration Key
          • Error: Device Remains in Pending Setup State After Onboarding
        • Troubleshoot Onboarding a Device to Cloud-Delivered Firewall Management Center Using the Serial Number
          • Device is Offline or Unreachable
          • Error: Serial Number Already Claimed
          • Error: Claim Error
          • Error: Failed to Claim
          • Error: Provisional Error
    • Migrate Threat Defense to Cloud-Delivered Firewall Management Center
      • Overview of Firewall Threat Defense to Cloud-Delivered Firewall Management Center migration
        • How Firewall Threat Defense Migration to Cloud-Delivered Firewall Management Center Works
        • About 14-day evaluation period
        • How Firewall Threat Defense licenses are handled during migration to Cloud-Delivered Firewall Management Center
      • End-to-End Workflow for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • Event and Analytics Management options during Firewall Threat Defense migration
      • Supported features
      • Unsupported features
      • Migration guidelines and limitations for VPN configuration
      • Supported On-Premises Firewall Management Center and Firewall Threat Defense software versions for migration
      • Prerequisites for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • Migrate Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • View a Firewall Threat Defense Migration Job
        • Proceed Migration Process
        • Commit Migration Changes Manually to Cloud-Delivered Firewall Management Center
        • Revert the Firewall Threat Defense Management to On-Premises Firewall Management Center
        • View Migrated Devices
        • Generate a Firewall Threat Defense Migration Report
        • Delete a Migration Job
      • Enable Notification Settings
      • Verify Firewall Threat Defense Connectivity with Cloud-Delivered Firewall Management Center
      • Use the Troubleshoot Feature for Failed Migrations
        • Resolving Firewall Threat Defense Migration to Cloud-Delivered Firewall Management Center Issues
    • Configure Cloud-Delivered Firewall Management Center-Managed Secure Firewall Threat Defense
      • Security Cloud Control Firewall Management Integrations Page
      • Navigate to the Cloud-Delivered Firewall Management Center in your Security Cloud Control Tenant
      • Enable Cloud-Delivered Firewall Management Center
    • Introduction to AIOps insights
      • About AIOps insights
        • AIOps licensing requirements
        • Prerequisites to use AIOps
        • View summary dashboard
        • View AIOps insights
      • About capacity and traffic insights
        • Analyze capacity trends and forecast resource usage
      • About application insights
        • Detect application outages
      • About compliance insights
        • Generate compliance reports
      • About best practices and ecommendations
        • Implement best practices and recommendations
      • About feature adoption insights
        • Assess and improve feature adoption
      • About software upgrade insights
        • Manage software upgrades
      • Manage insight preferences
        • Enable AIOps insights
        • Disable AIOps insights
        • Best practices and recommendations insights
        • Feature adoption insights
        • Application insights
        • Capacity and traffic insights
        • Operational insights
      • Frequently asked questions about AIOps
      • Additional resources
    • Introduction to Agent Workforce
      • About Agent Workforce
        • Available agents in Agent Workforce
        • Manage Conversations in Agent Workforce
        • Limitations and considerations
      • Troubleshoot site-to-site VPN issues with VPN agent
        • Benefits
        • How VPN agent works
        • Best practices
        • Example prompts and expected outcomes
      • Remediate traffic congestion with Elephant flow agent
        • Benefits
        • How Elephant flow remediation works
        • Best practices
      • Optimize firewall policies with Policy Copilot
        • Benefits
        • How Policy Copilot works
        • Best practices
        • Example prompts and expected outcomes
    • Monitor Cloud-Delivered Firewall Management Center-Managed Threat Defense Device Events
      • About Security Analytics and Logging(SaaS) for Firewall Threat Defense
      • Implementing SAL (SaaS) for Cloud-Delivered Firewall Management Center-Managed Devices
      • Requirements and Guidelines
      • How Firewall Threat Defense Events are Displayed in Security Cloud Control Using a Direct Connection
      • Send Cloud-Delivered Firewall Management Center-Managed Event Logs to SAL (SaaS) Using a Direct Connection
      • Send Cloud-Delivered Firewall Management Center-Managed Events to SAL (SaaS) Using Syslog
      • Enable Individual Threat Defense Devices to Send Events to SAL (SaaS) Using a Direct Connection
      • View AI Defense Events in Security Cloud Control
    • FTD Dashboard
      • About the FTD Dashboard
      • View the FTD Dashboard
      • FTD Dashboard Widgets
        • Top Intrusion Rules Widget
        • Top Intrusion Attackers Widget
        • Top Intrusion Targets Widget
        • Top Malware Signatures Widget
        • Top Malware Senders Widget
        • Top Malware Receivers Widget
        • Malware Events by Disposition Widget
        • Network Activity Widget
        • Event Activity Widget
        • Access Control Actions Widget
        • Top Access Control Policies Widget
        • Top Access Control Rules Widget
        • Top Devices Widget
        • Top Users Widget
        • Top Users by Blocked Connections Widget
        • Top Devices with Health Alerts Widget
        • Top Loaded Devices Widget
        • Top Web Applications Widget
        • Top Client Applications Widget
        • Top Blocked Web Applications Widget
      • Modify Time Settings for the FTD Dashboard
    • Analyze and Remediate Security Policy Anomalies with Policy Analyzer and Optimizer
      • About Policy Analyzer and Optimizer
      • Prerequisites to use Policy Analyzer and Optimizer
      • Enable Policy Analyzer and Optimizer for Security Cloud Control-managed On-Premises Firewall Management Center
      • Policy Analyzer and Optimizer licensing requirements
      • Open Policy Analyzer and Optimizer and select a data source
        • Sync and analysis behavior
      • Search and filter policies in Policy Analyzer and Optimizer
      • Access control policy analysis and optimization
        • Analyze access control policies
        • Access control policy analysis summary
        • Analyze duplicate rules in access control policy
        • Analyze expired rules in access control policy
        • Analyze mergeable rules in access control policy
        • Analyze overlapping objects in access control policy
        • Analyze policy insights in access control policy
        • Access control policy remediation
        • Download access control analysis report
      • Troubleshooting Policy Analyzer and Optimizer
        • Policy Analyzer and Optimizer Does Not Analyze Policies
        • Policy Analyzer and Optimizer Does Not Fetch Policies
      • Frequently Asked Questions About Policy Analyzer and Optimizer
  • Manage Catalyst SD-WAN Manager Firewall Capabilities
    • Integrate Catalyst SD-WAN Manager with Security Cloud Control
      • Overview of Catalyst SD-WAN integration with Security Cloud Control Firewall Management
      • System topology diagram
      • End-to-end workflow to manage Catalyst SD-WAN Manager using Security Cloud Control
      • Minimum software requirements
      • Additional resources
    • Onboard Catalyst SD-WAN Manager
      • Onboard Catalyst SD-WAN Manager to Security Cloud Control
      • Deboard Catalyst SD-WAN Manager from Security Cloud Control
      • Alignment of RBAC models of Security Cloud Control Firewall Management and Catalyst SD-WAN Manager
      • How Security Cloud Control Firewall Management manages Catalyst SD-WAN NGFW capabilities
      • View intrusion events
      • View malware events
    • Configure Next-Generation Firewall Capabilities of Catalyst SD-WAN Manager
      • Overview of Catalyst SD-WAN devices
      • Supported operations on Catalyst SD-WAN devices
      • View configuration of Catalyst SD-WAN devices
      • Cross-launch policy groups from Security Cloud Control Firewall Management
      • Overview of Catalyst SD-WAN security objects and security profiles
      • Create new Catalyst SD-WAN security objects and security profiles
        • Application List
        • Data Prefix
        • FQDN
        • Geolocation
        • Identity
        • Port
        • Protocol
        • Security Group Tag
        • IPS Signature
        • Allow URL
        • Block URL
        • Zone
        • Advanced Inspection Profile
        • Advanced Malware Protection
        • Intrusion Prevention
        • TLS/SSL Decryption
        • TLS/SSL Profile
        • URL Filtering
      • Modify Catalyst SD-WAN security objects and security profiles
      • Delete Catalyst SD-WAN security objects
      • Filter Catalyst SD-WAN security objects
      • An introduction to Catalyst SD-WAN NGFW security policies
      • Manage existing Catalyst SD-WAN NGFW security policies
      • Create Catalyst SD-WAN security policies
      • Associate a policy group to Catalyst SD-WAN NGFW policy
      • Deploy policy group from Catalyst SD-WAN Manager
    • Monitor Catalyst SD-WAN Events
      • Overview of Security Analytics and Logging for Catalyst SD-WAN
      • How Catalyst SD-WAN router shares events with Security Cloud Control Firewall Management
      • Requirements and guidelines
      • View Catalyst SD-WAN events in Security Cloud Control Firewall Management
  • Manage On-Premises Firewall Management Center
    • Onboard an On-Premises Firewall Management Center
      • Onboard an On-Premises Firewall Management Center to Security Cloud Control Firewall Management
        • Auto onboard an On-Premises Firewall Management Center integrated with Cisco Security Cloud
          • Integrate an On-Premises Firewall Management Center With Cisco Security Cloud
          • Auto onboard On-Prem FMCs from Cisco Security Cloud
        • Onboard an On-Premises Firewall Management Center to Security Cloud Control with Credentials
        • Redirect Security Cloud Control to an On-Premises Firewall Management Center
      • Remove an On-Premises Firewall Management Center from Security Cloud Control
    • Configure On-Premises Firewall Management Center-Managed Threat Defense Devices
      • Manage On-Premises Firewall Management Center with Security Cloud Control
      • View onboarded On-Premises Firewall Management Center
      • Discover and manage On-Premises Firewall Management Center network objects
      • Preview and deploy On-Premises Firewall Management Center configurations
      • Discard On-Premises Firewall Management Center configuration changes
  • Manage Cisco Umbrella
    • Onboard an Umbrella Organization
      • Onboarding an Umbrella organization
        • Umbrella license requirements
        • Generate an API key and secret
        • Umbrella organization ID
        • Onboard an Umbrella organization
        • Reconnect an Umbrella organization to Security Cloud Control
        • Cross-launch to the Umbrella dashboard
        • Delete a device from Security Cloud Control Firewall Management
    • Configure an Umbrella Organization
      • Read Umbrella tunnel configuration
      • Cross-launch to the Umbrella tunnels page
      • Configure a SASE tunnel for Umbrella
      • Edit a SASE tunnel
      • Delete a SASE tunnel from Umbrella
  • Manage Cisco Meraki
    • Onboard Cisco Meraki MX Devices
      • Onboard Cisco Meraki MX Devices
        • Onboard Meraki MX to Security Cloud Control
          • Generate and Retrieve Meraki API Key
          • Onboard an MX Device to Security Cloud Control
        • Onboard Meraki Templates to Security Cloud Control
          • Generate and Retrieve Meraki API Key
          • Onboard an Meraki Template to Security Cloud Control
        • Update Meraki MX Connection Credentials
        • Delete a device from Security Cloud Control Firewall Management
    • Configure Cisco Meraki
      • Managing Meraki with Security Cloud Control
      • How Does Security Cloud Control Communicate With Meraki
      • Meraki Access Control Policy
      • Meraki Templates
  • Manage AWS VPC
    • Onboard AWS VPC
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
      • Onboard an AWS VPC
    • Configure AWS VPC
      • Manage AWS VPCs with Security Cloud Control Firewall Management
      • Update AWS VPC connection credentials
      • Monitor AWS VPC tunnels using AWS transit gateway
      • Search and filter site-to-site VPN tunnels
      • View AWS VPC tunnel history
      • AWS VPC Policy
        • AWS VPC Security Groups Rules
        • Create a Security Group Rule
        • Edit a Security Group Rule
        • Delete a Security Group Rule
  • Manage Cisco IOS
    • Onboard Cisco IOS Devices
      • Onboard a Cisco IOS Device
        • Onboard a Cisco IOS Device
          • Create and Import an ASR or ISR Model
            • Download ASR or ISR Configuration
            • Import ASR or ISR Configuration
        • Import Configuration for Offline Device Management
        • Delete a device from Security Cloud Control Firewall Management
    • Configure Cisco IOS
      • Manage IOS Devices with Security Cloud Control
      • Use the Security Cloud Control Command Line Interface Tool
        • View Device Configuration File
  • Manage Network Devices with Generic SSH Access
    • Onboard an SSH Device
      • Onboard an SSH Device
        • Onboard an SSH Device
        • Delete a device from Security Cloud Control Firewall Management
    • Configure SSH Devices
      • Managing SSH Devices with Security Cloud Control
      • Use the Security Cloud Control Command Line Interface Tool
        • View a Device's Configuration File
  • Establish Secure Connections
    • Virtual Private Network Management
      • Configure Virtual Private Network Management
        • Introduction to Site-to-Site Virtual Private Network
        • Site-to-Site VPN concepts
          • Global IKE policies
            • Managing IKEv1 Policies
            • Create an IKEv1 Policy
            • Managing IKEv2 Policies
            • Create an IKEv2 Policy
          • IPsec proposal and IKE policy objects
            • Managing an IKEv1 IPsec Proposal Object
              • Create an IKEv1 IPsec Proposal Object
            • Managing an IKEv2 IPsec Proposal Object
              • Create or Edit an IKEv2 IPsec Proposal Object
          • Encryption and Hash Algorithms Used in VPN
        • Site-to-Site VPN configuration for FDM-Managed
          • Create a Site-To-Site VPN Tunnel Between FDM-managed Devices
          • Configure Networking for Protected Traffic Between the Site-To-Site Peers
          • Edit an Existing Security Cloud Control Site-To-Site VPN
            • Delete a Security Cloud Control Firewall Management Site-To-Site VPN Tunnel
          • Exempt Site-to-Site VPN Traffic from NAT
        • Site-to-Site VPN Configuration for Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense
          • Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense Devices
          • Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center-Managed Firewall Threat Defense and Multicloud Defense
          • Create a Site-to-Site VPN Between Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense and Secure Firewall ASA
        • Site-to-Site VPN for Secure Firewall ASA
          • Create a Site-to-Site VPN Tunnel Between Secure Firewall ASA
          • Create a Site-to-Site VPN Between ASA and Multicloud Defense Gateway
          • Exempt Site-to-Site VPN Traffic from NAT
        • Monitor ASA Site-to-Site Virtual Private Networks
          • Check Site-to-Site VPN Tunnel Connectivity
          • Site-To-Site VPN Dashboard
          • Identify VPN Issues
            • Find VPN Tunnels with Missing Peers
            • Find VPN Peers with Encryption Key Issues
            • Find Incomplete or Misconfigured Access Lists Defined for a Tunnel
            • Find Issues in Tunnel Configuration
            • Resolve Tunnel Configuration Issues
          • Search and filter site-to-site VPN tunnels
          • Onboard an Unmanaged Site-to-Site VPN Peer
          • Viewing AWS Site-to-Site VPN Tunnels
          • View IKE Object Details of Site-To-Site VPN Tunnels
          • View Last Successful Site-to-Site VPN Tunnel Establishment Date
          • View Site-to-Site VPN Tunnel Information
            • Site-to-Site VPN Global View
            • Site-to-Site VPN Tunnels Pane
        • Delete a Security Cloud Control Firewall Management Site-To-Site VPN Tunnel
        • Introduction to Remote Access Virtual Private Network
          • Introduction to Remote Access Virtual Private Network
          • Configure Remote Access Virtual Private Network for ASA
            • End-to-End Remote Access VPN Configuration Process for ASA
              • Create ASA Remote Access VPN Configuration
                • Modify ASA Remote Access VPN Configuration
              • Configure ASA Remote Access VPN Connection Profile
                • Configure AAA for a Connection Profile
              • Manage AnyConnect Software Packages on ASA Devices
                • Upload an AnyConnect Package from Security Cloud Control Repository
                • Upload an AnyConnect Package to ASA from Server
                • Upload new AnyConnect Packages to ASA
                • Upload AnyConnect Packages using File Management Wizard
                • Replace an AnyConnect Package
                • Delete an AnyConnect Package
            • Manage and Deploy Pre-existing ASA Remote Access VPN Configuration
              • Device Settings
              • Connection Profile
              • Primary Identity Source
              • AAA Server Groups
              • RADIUS Server Group
              • RADIUS Server
              • Group Policy
            • Remote Access VPN Certificate-Based Authentication
            • Exempt Remote Access VPN Traffic from NAT
            • Install the AnyConnect Client Software on ASA
            • Modify ASA Remote Access VPN Configuration
            • Modify ASA Connection Profile
            • Upload RA VPN AnyConnect Client Profile
            • Verify ASA Remote Access VPN Configuration
            • View ASA Remote Access VPN Configuration Details
    • Configuring Firewall for Universal Zero Trust Network Access
      • Universal Zero Trust Network Access
      • Onboard Applications in Security Cloud Control
      • Enable Cloud-Delivered Firewall Management Center in Security Cloud Control
      • Configure Security Devices
  • Device Operations
    • Manage Device Configuration
      • Read, discard, and deploy configuration changes
        • Read All Device Configurations
        • Read configuration changes from an ASA to Security Cloud Control
          • Read configuration changes on ASA device
        • Read changes from Firewalls
        • Preview and deploy configuration changes for all devices
        • Deploy configuration changes from Security Cloud Control to ASA
          • Deploy configuration changes
          • Deploy configuration changes made using the Security Cloud Control GUI
          • Schedule automatic deployments
          • Deploy configuration changes using Security Cloud Control's CLI interface
          • Deploy configuration changes by editing the device configuration
          • Deploy Configuration Changes for a Shared Object on Multiple Devices
        • Deploy Changes to a Device
          • Cancelling Changes
          • Discarding Changes
        • Bulk Deploy Device Configurations
        • Preview and deploy On-Premises Firewall Management Center configurations
        • About Scheduled Automatic Deployments
          • Schedule an Automatic Deployment
          • Edit a Scheduled Deployment
          • Delete a Scheduled Deployment
        • Check for Configuration Changes
        • Discard Configuration Changes
        • Discard On-Premises Firewall Management Center configuration changes
        • Out-of-Band Changes on Devices
      • Synchronizing configurations between Security Cloud Control and device
        • Conflict Detection
          • Enable Conflict Detection
          • Enable conflict detection for an On-Premises Firewall Management Center
        • Automatically Accept Out-of-Band Changes from your Device
          • Configure Auto-Accept Changes
          • Disabling Auto-Accept Changes for All Devices on the Tenant
        • Resolve configuration conflicts
          • Resolve the Not Synced Status
          • Resolve the conflict detected status
        • Schedule polling for device changes
        • Schedule a Security Database Update
          • Create a Scheduled Security Database Update
          • Edit a Scheduled Security Database Update
      • Synchronizing configurations between Security Cloud Control and device
        • Conflict Detection
          • Enable Conflict Detection
          • Enable conflict detection for an On-Premises Firewall Management Center
        • Automatically Accept Out-of-Band Changes from your Device
          • Configure Auto-Accept Changes
          • Disabling Auto-Accept Changes for All Devices on the Tenant
        • Resolve configuration conflicts
          • Resolve the Not Synced Status
          • Resolve the conflict detected status
        • Schedule polling for device changes
        • Schedule a Security Database Update
          • Create a Scheduled Security Database Update
          • Edit a Scheduled Security Database Update
    • Manage onboarded device settings
      • Changing a device's IP address in Security Cloud Control Firewall Management
      • Changing a device's name in Security Cloud Control Firewall Management
      • Export a list of devices and services
      • Export device configuration
      • External links for devices
        • Create an External Link from your Device
        • Create an External Link to ASDMFDM
        • Create an External Link for Multiple Devices
        • Edit or Delete External Links
        • Edit or Delete External Links for Multiple Devices
      • Bulk reconnect devices to Security Cloud Control Firewall Management
      • Moving devices between organizations
      • Device certificate expiry detection
      • Update Meraki MX Connection Credentials
      • Write a device note
      • Delete a device from Security Cloud Control Firewall Management
      • Manage security devices
      • Back up Firewall Threat Defense devices
      • Manage Firewall Threat Defense devices through Security Cloud Control Firewall Management
      • Security devices overview
      • Security Cloud Control Firewall Management labels and filtering
        • Apply Labels to Devices and Objects
        • Labels and Tags in AWS VPC
        • Filters on security devices, policies, and objects page
      • Use Security Cloud Control Firewall Management search functionality
        • Page Level Search
        • Global Search
          • Initiate Full Indexing
          • Perform a Global Search
      • Security devices overview
      • Security Cloud Control Firewall Management labels and filtering
        • Apply Labels to Devices and Objects
        • Labels and Tags in AWS VPC
        • Filters on security devices, policies, and objects page
      • Use Security Cloud Control Firewall Management search functionality
        • Page Level Search
        • Global Search
          • Initiate Full Indexing
          • Perform a Global Search
    • Use the Security Cloud Control Command Line Interface Tool
      • Use the Command Line Interface on a single device
      • Use the bulk Command Line Interface
      • Run a CLI macro
      • Export Command Line Interface results
    • Manage CLI Templates
      • CLI Templates
      • Create a CLI Template
      • Edit a CLI Template
      • Export a CLI Template
      • Delete a CLI Template
    • Migrate Firewalls with the Migration Tool in Security Cloud Control
      • Is This Guide for You?
      • Get Started with the Firewall Migration Tool in Security Cloud Control
        • Supported Configurations
        • Licenses
        • Initialize a New Migration Instance
        • Delete a Migration Instance
        • Using the Demo Mode in the Secure Firewall Migration Tool
      • Migrate Secure Firewall ASA to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrating Microsoft Azure Native Firewall with the Firewall Migration Tool in Security Cloud Control
      • Migrate FDM-Managed Device to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Check Point Firewall to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrating Check Point Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Fortinet Firewall with the Firewall Migration Tool in Security Cloud Control
      • Migrating Fortinet Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Palo Alto Networks Firewall to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Secure Firewall ASA to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Palo Alto Networks Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Related Documentation
  • Monitor and Analyze
    • Events in Security Cloud Control
      • About Security Analytics and Logging (SaaS) in Security Cloud Control
      • Event types in Security Cloud Control
      • Troubleshooting network problems using Security and Analytics Logging events
      • Deprovisioning Cisco Security Analytics and Logging (SaaS)
    • Security Analytics and Logging Licenses
      • Security Analytics and Logging licenses
        • Subscribe to a Security Analytics and Logging license
        • View Security Analytics and Logging license information
        • View Security Analytics and Logging Storage usage and event ingest rate
        • Extend event storage duration and increase event storage capacity
        • View Security Analytics and Logging alerts
        • Frequently asked questions about Security Analytics and Logging license
    • Secure Event Connectors
      • About Secure Event Connectors
      • Installing Secure Event Connectors
        • Install a Secure Event Connector on an SDC Virtual Machine
        • Installing an SEC Using a Security Cloud Control Image
          • Install a Security Cloud Control Connector, to Support a Secure Event Connector, Using a Security Cloud Control VM Image
          • Install the Secure Event Connector on the Security Cloud Control Connector VM
        • Deploy Secure Event Connector on Ubuntu Virtual Machine
        • Install an SEC Using Your VM Image
          • Install a Security Cloud Control Connector to Support an SEC Using Your VM Image
          • Additional Configuration for SDCs and Security Cloud Control Connectors Installed on a VM You Created
          • Install the Secure Event Connector on your Security Cloud Control Connector Virtual Machine
        • Install a Secure Event Connector on an AWS VPC Using a Terraform Module
      • Remove the Secure Event Connector
        • Remove an SEC from Security Cloud Control
        • Remove a Secure Event Connector from the Secure Device Connector VM
      • Finding your device's TCP, UDP, and NSEL port used for Secure Logging Analytics (SaaS)
    • View Events in Security Cloud Control Firewall Management
      • View live events
        • Play/Pause Live Events
      • View historical events
      • Customize the events view
        • Correlate Firewall Threat Defense Event Fields and Column Names
      • Show and hide columns on the event logging page
      • Change the time zone for the event timestamps
      • Customizable event filters
      • Search and filter events using the event logging page
        • Filter Live or Historical Events
        • Filter Only NetFlow Events
        • Filter for ASA or FDM-Managed Device Syslog Events but not ASA NetFlow Events
        • Combine Filter Elements
        • Search Events Using the Events Logging Page
          • Use Sample Filters to Search Events
          • Search Historical Events in the Background
            • Schedule to Generate a Search Report in the Background
            • Download a Search Report
      • Event attributes in Security Analytics and Logging
        • EventGroup and EventGroupDefinition Attributes for Some Syslog Messages
        • EventName Attributes for Syslog Events
        • Time Attributes in a Syslog Event
    • Monitor Remote Access Virtual Private Network Sessions from Secure Firewall ASA and Firewall Threat Defense
      • Monitor Remote Access Virtual Private Network Sessions
        • Monitor Live AnyConnect Remote Access VPN Sessions
          • View Live Remote Access VPN Data
        • Monitor Historical AnyConnect Remote Access VPN Sessions
          • View Historical Remote Access VPN Data
        • Search and Filter Remote Access VPN Sessions
        • Customize the Remote Access VPN Monitoring View
        • Export Remote Access VPN Sessions to a CSV File
        • Remote Access VPN Dashboard
        • Disconnect Remote Access VPN Sessions of an ASA User
          • Disconnect all Active RA VPN Sessions of a User
        • Disconnect Remote Access VPN Sessions on FDM-Managed Device
        • Disconnect Remote Access VPN Sessions on FTD
    • Smart Licensing Dashboard
      • Overview of Smart Licensing Dashboard
      • View Smart Licensing Dashboard
    • Monitor and report change logs, workflows, and jobs
      • Monitor and report change logs, workflows, and jobs
      • Manage change logs in Security Cloud Control
      • Change log entries after deploying to an ASA
      • Change log entries after reading changes from an ASA
      • View change log differences
      • Change request management
        • Enable Change Request Management
        • Create a Change Request
        • Associate a Change Request with a Change Log Event
        • Search for Change Log Events with Change Requests
        • Search for a Change Request
        • Filter Change Requests
        • Clear the Change Request Toolbar
        • Clear a Change Request Associated with a Change Log Event
        • Delete a Change Request
        • Disable Change Request Management
        • Change Request Management Use Cases
      • Export the change log
        • Differences Between Change Log Capacity in Security Cloud Control and Size of an Exported Change Log
      • Monitor jobs in Security Cloud Control
        • Reinitiate a Bulk Action
        • Cancel a Bulk Action
      • Monitor workflows in Security Cloud Control
  • Troubleshoot
    • Troubleshooting
      • Troubleshoot a Secure Firewall ASA device
        • ASA Fails to Reconnect to Security Cloud Control After Reboot
        • Cannot onboard ASA due to certificate error
          • Determine the OpenSSL Cipher Suite Used by your ASA
          • Cipher Suites Supported by Security Cloud Control's Secure Device Connector
          • Updating your ASA's Cipher Suite
        • Troubleshoot ASA using CLI commands
        • Troubleshoot ASA Remote Access VPN
        • ASA Real-time Logging
          • View ASA Real-time Logs
        • ASA Packet Tracer
          • Troubleshoot an ASA Device Security Policy
          • Troubleshoot an Access Rule
          • Troubleshoot a NAT Rule
          • Troubleshoot a Twice NAT Rule
          • Analyze Packet Tracer Results
        • Cisco ASA Advisory cisco-sa-20180129-asa1
        • Confirming ASA Running Configuration Size
        • Container Privilege Escalation Vulnerability Affecting Secure Device Connector: cisco-sa-20190215-runc
          • Updating a Security Cloud Control-Standard SDC Host
          • Updating a Custom SDC Host
          • Bug Tracking
        • Large ASA Running Configuration Files
      • Troubleshoot a Secure Device Connector
        • SDC is Unreachable
        • SDC Status not Active on Security Cloud Control After Deployment
        • Changed IP Address of the SDC is not Reflected in Security Cloud Control
        • Troubleshoot Device Connectivity with the SDC
        • Intermittent or No Connectivity with SDC
        • Container Privilege Escalation Vulnerability Affecting Secure Device Connector: cisco-sa-20190215-runc
          • Updating a Security Cloud Control-Standard SDC Host
          • Updating a Custom SDC Host
          • Bug Tracking
        • Invalid System Time
        • SDC version is lower than 202311****
        • Certificate or Connection errors with AWS servers
      • Troubleshoot a Secure Event Connector
        • Troubleshoot SEC Onboarding Failures
        • Troubleshoot Secure Event Connector Registration Failure
        • Troubleshooting NSEL Data Flows
        • Event Logging Troubleshooting Log Files
        • SEC Status is Inactive in Security Cloud Control
        • The SEC is online, but there are no events in Security Cloud Control Event Logging Page
        • Remove an SEC from Your Host
        • Use Health Check to Learn the State of your Secure Event Connector
      • Troubleshoot Security Cloud Control
        • Troubleshooting Access and Certificates
          • Troubleshoot User Access with Security Cloud Control
          • Resolve New Fingerprint Detected State
          • Troubleshooting SSL Decryption Issues
        • Troubleshooting Objects
          • Resolve Duplicate Object Issues
          • Resolving Inconsistent or Unused Security Zone Objects
          • Resolve Unused Object Issues
            • Resolve an Unused Object Issue
            • Remove Unused Objects in Bulk
          • Resolve Inconsistent Object Issues
          • Resolve Object Issues in Bulk
          • Unignore objects
      • Device connectivity states
        • Troubleshoot Device Unregistered
        • Troubleshoot Insufficient Licenses
        • Troubleshoot Invalid Credentials
        • Troubleshoot New Certificate Issues
          • New Certificate Detected
        • Troubleshoot Onboarding Error
        • Resolve the conflict detected status
        • Resolve the Not Synced Status
    • FAQ and Support
      • Security Cloud Control
      • FAQ about onboarding devices to Security Cloud Control
        • FAQs About Onboarding Secure Firewall ASA to Security Cloud Control
        • FAQs About Onboarding Secure Firewall Threat Defense to Cloud-Delivered Firewall Management Center
        • FAQs About on-premises Firewall Management Center
        • FAQs About Onboarding Meraki Devices to Security Cloud Control
        • FAQs About Onboarding SSH Devices to Security Cloud Control
        • FAQs About Onboarding IOS Devices to Security Cloud Control
      • Device types
      • Security
      • End-of-Support for management of Secure Firewall Threat Defense devices, Version 7.0.x, managed by Cloud-Delivered Firewall Management Center
      • Troubleshooting
      • Terminologies and definitions used in Zero-Touch Provisioning
      • Policy optimization
      • Connectivity
      • Complete the initial configuration of a Secure Firewall Threat Defense device using the CLI
      • About Data Interfaces
      • How Security Cloud Control processes personal information
      • Contact Security Cloud Control support
        • Export The Workflow
        • Open a Support Ticket with TAC
          • How Security Cloud Control Customers Open a Support Ticket with TAC
          • How Security Cloud Control Trial Customers Open a Support Ticket with TAC
        • Security Cloud Control Service Status Page
  • Appendix
    • Security and Internet Access
      • Security requirements
      • Internet access requirements
    • Terraform
      • About Terraform
    • Open Source and 3rd Party License Attribution
      • Open Source and Third-Party License in SDC
    • Cisco AI Assistant User Guide
      • Onboard with Cisco AI Assistant
      • Prompt Guide for Cisco AI Assistant
      • Online Help Documentation
      • Policy Insights
      • Policy Analyzer and Optimizer
      • Automate Policy Rule Creation
      • Contact Support
      • Notifications Center
      • Cisco AI Assistant Frequently Asked Questions (FAQ)

Manage Secure Firewall ASA Onboard Secure Firewall ASA

Last updated: Jul 06, 2026

Previous topic Manually get a certificate authority (CA) chain Next topic Supported devices, software, and hardware for Security Cloud Control Firewall Management
© 2026 Cisco System, Inc.
Privacy policyTerms of Service