Read Configuration Changes from an ASA to Firewall Manager

Why Does Firewall Manager "Read" ASA Configurations?

In order to manage an ASA, Firewall Manager must have it's own stored copy of the ASA's running configuration file. The first time Firewall Manager reads and saves a copy of the device's configuration file is when the device is onboarded. Subsequently, when Firewall Manager reads a configuration from an ASA, you are opting to either Check for Changes, Accept without Review, or Read Configuration. See Reading, Discarding, Checking for, and Deploying Configuration Changes for more information.

Firewall Manager also needs to read an ASA configuration in these circumstances:

  • Deploying configuration changes to the ASA has failed and the device state is not listed or Not Synced.

  • Onboarding a device has failed and the device state is No Config.

  • You have made changes to the device configuration outside of Firewall Manager and the changes have not been polled or detected. THe device state would be either Synced or Conflict Detected.

In these cases, Firewall Manager needs a copy of the last known configuration stored on the device.