Cisco

How search works in the Security Help Center:

  • The most relevant topics (based on weighting and matching to search terms) are listed first in the search results by default
  • Common Boolean operations are supported
  • Use double quotes to find a phrase (“specific phrase”)
  • Apply facets on the Search Results page to further scope search results by category
Login

Log In to the Cisco Security Documentation Portal

Search

Cisco Security Cloud Control: Secure Firewall Management

  • Introduction
    • Get started with Security Cloud Control Firewall Management
      • Overview of Cisco Security Cloud Control
        • Products and Solutions Supported by Security Cloud Control
      • Overview of Security Cloud Control Firewall Management
        • Security Cloud Control Firewall Management Platform Maintenance Schedule
        • Security Cloud Control Firewall Management licenses
        • More Supported Devices and Licenses
      • Overview of Cloud-Delivered Firewall Management Center
        • Enable Cloud-Delivered Firewall Management Center
        • Determine the Cloud-Delivered Firewall Management Center Version in Security Cloud Control Firewall Management
        • Cloud-Delivered Firewall Management Center licensing and registration
        • Cloud-Delivered Firewall Management Center Maintenance Schedule
      • Provision Security Cloud Control Firewall Management
      • Open Security Cloud Control Firewall Management
      • The Firewall Management dashboard
  • Configure basic settings
    • Manage Firewall administration in Security Cloud Control Firewall Management
      • Configure general settings
        • Enable AI Assistant for Firewall
        • Enable the option to auto-accept device changes
        • Enable Multicloud Defense SCC features
        • Enable object sharing with Multicloud Defense
        • Enable ASA health monitoring
        • Set the default conflict detection interval
        • Enable scheduled automatic deployments
        • Manage web analytics
        • Set the FDM Default recurring backup schedule
        • Auto onboard On-Prem FMCs from Cisco Security Cloud
        • Enable event data sharing with Talos
        • View firewall management instance details
        • Use the Security Cloud Control Firewall Management platform navigator
      • Manage users and groups within Security Cloud Control organization
      • Manage API-Only users for Security Cloud Control Firewall Management
      • View Security Cloud Control notifications
        • Manage user notification preferences
      • View logging settings
      • Understand user roles in Security Cloud Control Firewall Management
        • Read-only role
        • Edit-Only role
        • Deploy-Only role
        • VPN Sessions Manager role
        • Admin role
        • Super Admin role
      • Filters on security devices, policies, and objects page
    • Onboard devices in Security Cloud Control Firewall Management
      • Introduction to Secure Connectors
        • About Secure Device Connector
          • Plan device connectivity
          • Allow inbound access for direct cloud connectivity
          • Plan SDC capacity and host requirements
          • Deploy a VM for Running the Secure Device Connector and Secure Event Connector
          • Deploy a Secure Device Connector On Your VM
          • Bootstrap a Secure Device Connector on the Deployed Host
          • Deploy a Secure Device Connector to vSphere Using Terraform
          • Deploy a Secure Device Connector on an AWS VPC Using a Terraform Module
          • Migrate an On-Premises Secure Device Connector and Secure Event Connector from a CentOS 7 Virtual Machine to an Ubuntu Virtual Machine
          • Change the IP Address of a Secure Device Connector
          • Rename a Secure Device Connector
          • Specify a default Secure Device Connector
          • Update a Secure Device Connector manually
          • Use multiple Secure Device Connectors on one organization
          • Find devices that sse the same Secure Device Connector
          • Remove a Secure Device Connector
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
    • Manage objects
      • Introduction to objects
        • Supported object types
        • Shared objects
        • Object Overrides
        • Unassociated objects
        • Compare objects
        • Object filters
          • Configure object filters
          • Exclude device filters when you need full relationships
        • Delete objects
          • Delete a single object
          • Delete a group of unused objects
        • Create an ASA IP address pool
      • Network objects
        • Create or Edit ASA Network Objects and Network Groups
          • Create an ASA Network Object
          • Create an ASA Network Group
          • Edit an ASA Network Object
          • Edit an ASA Network Group
          • Add Additional Values to a Shared Network Group in Security Cloud Control
          • Edit Additional Values in a Shared Network Group in Security Cloud Control
          • Deleting Network Objects and Groups in Security Cloud Control
        • Create or Edit a Firepower Network Object or Network Groups
          • Create a Firepower Network Object
          • Create a Firepower Network Group
          • Edit a Firepower Network Object
          • Edit a Firepower Network Group
          • Add an Object Override
          • Edit Object Overrides
          • Add Additional Values to a Shared Network Group
          • Edit Additional Values in a Shared Network Group
          • Deleting Network Objects and Groups in Security Cloud Control
        • Discover and manage On-Premises Firewall Management Center network objects
        • Objects Associated with Meraki Devices
        • Create a Local Meraki Network Object
        • Create or Edit a Meraki Network Object or Network Group
          • Create a Meraki Network Object
          • Create a Meraki Network Group
          • Edit a Firepower Network Object or Network Group
          • Deleting Network Objects and Groups in Security Cloud Control
      • URL objects
        • Create or Edit an FDM-Managed URL Object
        • Create a Firepower URL Group
          • Edit a Firepower URL Object or URL Group
      • Geolocation objects
        • Create and Edit a Firepower Geolocation Filter Object
          • Edit a Geolocation Object
      • DNS group objects
        • Create a DNS Group Object
        • Edit a DNS Group Object
        • Delete a DNS Group Object
      • Certificate objects
        • About certificates
        • Certificate Types Used by Feature
        • Configuring Certificates
        • Uploading Internal and Internal CA Certificates
          • Procedure
        • Uploading Trusted CA Certificates
          • Procedure
        • Generating Self-Signed Internal and Internal CA Certificates
          • Procedure
      • ASA trustpoint objects
        • Add an identity certificate object by using PKCS12
        • Create a self-signed ASA identity certificate object
        • Add an ASA identity certificate object for a Certificate Signing Request (CSR)
        • Add a trusted CA certificate object for ASA
        • Self-Signed and CSR certificate generation based on certificate contents
      • IPsec proposal and IKE policy objects
        • Create or edit an IKEv1 IPsec proposal object
        • Create or edit an IKEv2 IPsec proposal object
      • Global IKE policies
        • Create or edit an IKEv1 policy
        • Create or edit an IKEv2 policy
      • Remote access VPN objects
        • Identity sources for ASA
          • Determining the directory base DN
          • RADIUS servers and groups
          • Create an ASA Active Directory realm object
            • Edit an ASA Active Directory realm object
          • Create an ASA RADIUS server object or group
            • Create an ASA RADIUS server object
            • Create an ASA RADIUS server group
            • Edit an ASA Radius server object or group
        • Create ASA RA VPN group policies
          • ASA RA VPN group policy attributes
        • Create a new RA VPN group policy
          • RA VPN group policy attributes
      • Service objects
        • Create and Edit ASA Service Objects
          • Create an ASA Service Group
          • Edit an ASA Service Object or Service Group
        • Create and edit Firepower service objects
          • Create a Firepower Service Group
          • Edit a Firepower service object or service group
        • Create or Edit a Meraki Service Object
          • Create a Service Object
          • Create a Service Group
          • Edit a Service Object or a Service Group
      • Security group tag group
        • Security Group Tags
        • Create an SGT Group
        • Edit an SGT Group
        • Add an SGT Group to an Access Control Rule
      • ASA time range objects
        • Create an ASA time range object
        • Edit an ASA time range object
    • Dynamic Attributes Connector
      • About the Dynamic Attributes Connector
        • How It Works
      • About the dashboard
        • Dashboard of an unconfigured system
        • Dashboard of a configured system
        • Add, edit, or delete connectors
        • Add, edit, or delete dynamic attributes filters
        • Add, edit, or delete adapters
      • Create a connector
        • Amazon Web Services connector—About user permissions and imported data
          • Create an AWS user with minimal permissions for the dynamic attributes connector
          • Create an AWS connector
        • Amazon Web Services Security Groups connector—About user permissions
          • Create an AWS Security Groups connector
        • Create an AWS service tags connector
        • Azure connector—About user permissions and imported data
          • Create an Azure user with minimal permissions for the dynamic attributes connector
          • Create an Azure connector
        • Create an Azure Service Tags connector
        • Create a Multicloud Defense connector
        • Create a Cisco Cyber Vision connector
        • Create a generic text connector
          • Manually get a certificate authority (CA) chain
        • Create a GitHub connector
        • Google Cloud connector—About user permissions and imported data
          • Create a Google Cloud user with minimal permissions for the dynamic attributes connector
          • Create a Google Cloud connector
        • Create an Office 365 connector
        • Tenable connector
          • About the Tenable connector
          • Get the Tenable API key and secret
          • Create a Tenable connector
          • About Tenable dynamic objects in IDS, IPS, and access control policies
        • Create a Webex connector
        • Create a Zoom Connector
      • Create an adapter
        • How to create an On-Premises Firewall Management Center adapter
        • How to create a Cloud-Delivered Firewall Management Center adapter
      • Create dynamic attributes filters
        • Dynamic attribute filter examples
      • Dynamic firewall
        • About the dynamic firewall
        • How to configure the dynamic firewall
          • Enable the dynamic attributes connector
          • Get required information for Identity Intelligence
          • Create an identity source and realm for the dynamic firewall
          • Create a dynamic firewall instance
          • Associate an identity source with Identity Intelligence
          • Configure Identity Intelligence
          • View system-defined filters
          • View system-defined access control rules
          • Edit the user exclusion list
          • View and edit the system-created access control policy
        • Create dynamic attributes filters
      • Use Dynamic Objects in Access Control Policies
        • About dynamic objects in access control rules
        • Create dynamic attributes filters
        • Dynamic attributes rule conditions
        • Create access control rules or DNS rules using dynamic attributes filters
        • Use dynamic objects in DNS policies
      • Troubleshoot the Dynamic Attributes Connector
        • Troubleshoot error messages
        • Get Your Tenant ID
        • Manually get a certificate authority (CA) chain
  • Manage Secure Firewall ASA
    • Onboard Secure Firewall ASA
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
      • Onboard Secure Firewall ASA
      • Onboard ASA device to Security Cloud Control Firewall Management
      • Onboard a high availability pair of ASA devices to Security Cloud Control Firewall Management
      • Onboard an ASA in multi-context mode to Security Cloud Control Firewall Management
      • Onboard multiple ASAs to Security Cloud Control Firewall Management
        • Pause and resume onboarding multiple ASA devices
      • Create and import an ASA model to Security Cloud Control Firewall Management
        • Import ASA configuration
    • Configure Secure Firewall ASA
      • Managing Secure Firewall ASA with Security Cloud Control Firewall Management
      • Update ASA connection credentials in Security Cloud Control Firewall Management
        • Move an ASA from one SDC to Another
      • ASA interface configuration
        • Configure an ASA Physical Interface
          • Configure IPv4 Addressing for ASA Physical Interface
          • Configure IPv6 Addressing for ASA Physical Interface
          • Configure Advanced ASA Physical Interface Options
          • Enable the ASA Physical Interface
        • Add an ASA VLAN Subinterface
          • Configure ASA VLAN Subinterfaces
          • Configure IPv4 Addressing for ASA Subinterface
          • Configure IPv6 Addressing for ASA Subinterface
          • Configure Advanced ASA Subinterface Options
          • Enable the Subinterface
          • Remove ASA Subinterface
        • About ASA EtherChannel Interfaces
          • Configure ASA EtherChannel
            • Edit ASA EtherChannel
            • Remove ASA EtherChannel Interface
      • ASA system settings policy in Security Cloud Control Firewall Management
        • Create an ASA Shared System Settings Policy
          • Configure Basic DNS Settings
          • Configure HTTP Settings
          • Set the Date and Time Using an NTP Server
          • Configure SSH Access
          • Configure System Logging
          • Enable Sysopt Settings
          • Assign a Policy from the Shared System Settings Page
        • Configure or Modify Device Specific System Settings
          • Assign a Policy from Device-Specific Settings Page
        • Auto Assignment of ASA Devices to a Shared System Settings Policy
        • Filter ASA Shared System Settings Policy
        • Disassociate Devices from Shared System Settings Policy
        • Delete Shared Settings Policy
      • ASA routing in Security Cloud Control Firewall Management
        • About ASA Static Route
          • Configure ASA Static Route
          • Edit ASA Static Route
          • Delete a Static Route
      • Manage security policies in Security Cloud Control Firewall Management
      • Manage ASA network security policy
        • About ASA Access Control Lists and Access Groups
        • Create an ASA Access List
        • Add a Rule to an ASA Access List
          • About System Log Activity
          • Deactivate Rules in an Access Control List
          • About Security Group Tags in ASA Policies
        • Assign Interfaces to ASA Access Control List
        • Create an ASA Global Access List
        • Share an ASA Access Control List with Multiple ASA Devices
        • Copy an ASA Access Control List to Another ASA
        • Copy a Rule Within or Across ASA Access Lists and Devices
        • Unshare a Shared ASA Access Control List
        • View ASA Access Policies Listing Page
        • Global Search of ASA Access Lists
        • Rename an ASA Access Control List
        • Delete a Rule from an ASA Access Control List
        • Delete an ASA Access Control List
      • Compare ASA network policies
      • Hit rates
        • View Hit Rates of ASA Policies
      • Search and filter ASA network rules in the access list
      • Shadowed rules
        • Find Network Policies with Shadowed Rules
        • Resolve Issues with Shadowed Rules
      • API tokens
      • ASA file management
        • Upload File to a Single ASA Device
        • Upload File to Multiple ASA Devices
        • Remove Files from ASA
      • Managing ASAs with pre-existing High Availability configuration
        • Configuration Changes Made to ASAs in Active-Active Failover Mode
      • Manage ASA configuration files
        • View a Device's Configuration File
      • Configure DNS on ASA
        • Procedure
      • ASA command line interface
        • Configure ASA Using Security Cloud Control CLI
        • ASA Bulk CLI Use Cases
          • Show all users in the running configuration of an ASA and then delete one of the users
          • Find all SNMP configurations on selected ASAs
        • ASA Command Line Interface Documentation
        • Manage the Device Configuration
          • Compare ASA Configurations Using Security Cloud Control
          • Restore an ASA Configuration
            • How to Restore an ASA Configuration
            • Troubleshooting
          • View a Device's Configuration File
          • Edit a Complete Device Configuration File
      • Manage security policies in Security Cloud Control Firewall Management
      • Manage ASA network security policy
        • About ASA Access Control Lists and Access Groups
        • Create an ASA Access List
        • Add a Rule to an ASA Access List
          • About System Log Activity
          • Deactivate Rules in an Access Control List
          • About Security Group Tags in ASA Policies
        • Assign Interfaces to ASA Access Control List
        • Create an ASA Global Access List
        • Share an ASA Access Control List with Multiple ASA Devices
        • Copy an ASA Access Control List to Another ASA
        • Copy a Rule Within or Across ASA Access Lists and Devices
        • Unshare a Shared ASA Access Control List
        • View ASA Access Policies Listing Page
        • Global Search of ASA Access Lists
        • Rename an ASA Access Control List
        • Delete a Rule from an ASA Access Control List
        • Delete an ASA Access Control List
      • Compare ASA network policies
      • Hit rates
        • View Hit Rates of ASA Policies
      • Search and filter ASA network rules in the access list
      • Shadowed rules
        • Find Network Policies with Shadowed Rules
        • Resolve Issues with Shadowed Rules
    • Monitor Secure Firewall ASA Events
      • About Security Analytics and Logging (SAL SaaS) for ASA devices
        • How ASA Events are Displayed in Security Cloud Control
      • Implementing Secure Logging Analytics (SaaS) for ASA devices
      • Send ASA syslog events to the Cisco Cloud using a Security Cloud Control Macro
        • Creating an ASA Security Analytics and Logging (SaaS) Macro
      • Send ASA syslog events to the Cisco Cloud using the command line interface
        • Security Cloud Control Command Line Interface for ASA
        • Forward ASA Syslog Events to the Secure Event Connector
        • Send ASA Syslog Events to the Cisco Cloud Using CLI
        • Create a Custom Event List
        • Include the Device ID in Non-EMBLEM Format Syslog Messages
      • NetFlow Secure Event Logging (NSEL) for ASA devices
        • Configuring NSEL for ASA Devices by Using a Security Cloud Control Macro
          • Open the Configuring NSEL Macro
          • Define the Destination of NSEL Messages and the Interval at Which They Are Sent to the SEC
          • Create a Class-Map that Defines which NSEL Events Will Be Sent to the SEC
          • Define a Policy-Map for NSEL Events
          • Disable Redundant Syslog Messages
          • Review and Send the Macro
        • Delete NetFlow Secure Event Logging (NSEL) Configuration from an ASA
          • Open the DELETE-NSEL Macro
          • Enter the Values in the Macro to Complete the No Commands
        • Determine the Name of an ASA Global Policy
        • Troubleshooting NSEL Data Flows
          • Verify that NSEL Events are Being Sent to the SEC
          • Use the "capture" Command to Capture NSEL Packets Sent from the ASA to the SEC
          • Verify that NetFlow Packets are Being Received by the Cisco Cloud
          • Check for Live NSEL Events
          • Check for Historical NSEL Events
      • Parsed ASA syslog events
    • Monitor device health metrics
      • About device health metrics
      • Enable ASA health monitoring
      • Bulk opt in or opt out of device health metrics
      • View the device health metrics dashboard
      • Troubleshooting device health metrics
    • Upgrade Secure Firewall ASA
      • Prerequisites for ASA and ASDM Upgrade in Security Cloud Control Firewall Management
      • Upgrade bulk ASA and ASDM in Security Cloud Control Firewall Management
        • Upgrade Multiple ASAs with Images from your own Repository
      • Upgrade ASA and ASDM images on a single ASA
      • Upgrade ASA and ASDM images in a high availability pair
        • Workflow for upgrading an ASA high availability pair
        • Workflow
        • Upgrade ASA and ASDM Images in a high availability pair
      • Upgrade an ASA or ASDM using your own image
    • Troubleshoot Secure Firewall ASA
      • Troubleshoot a Secure Firewall ASA device
        • ASA Fails to Reconnect to Security Cloud Control After Reboot
        • Cannot onboard ASA due to certificate error
          • Determine the OpenSSL Cipher Suite Used by your ASA
          • Cipher Suites Supported by Security Cloud Control's Secure Device Connector
          • Updating your ASA's Cipher Suite
        • Troubleshoot ASA using CLI commands
        • Troubleshoot ASA Remote Access VPN
        • ASA Real-time Logging
          • View ASA Real-time Logs
        • ASA Packet Tracer
          • Troubleshoot an ASA Device Security Policy
          • Troubleshoot an Access Rule
          • Troubleshoot a NAT Rule
          • Troubleshoot a Twice NAT Rule
          • Analyze Packet Tracer Results
        • Cisco ASA Advisory cisco-sa-20180129-asa1
        • Confirming ASA Running Configuration Size
        • Container Privilege Escalation Vulnerability Affecting Secure Device Connector: cisco-sa-20190215-runc
          • Updating a Security Cloud Control-Standard SDC Host
          • Updating a Custom SDC Host
          • Bug Tracking
        • Large ASA Running Configuration Files
  • Manage Secure Firewall Threat Defense with Cloud-Delivered Firewall Management Center
    • Onboard a Firewall Threat Defense Device
      • Onboarding Overview
      • Maximum Firewall Threat Defense devices supported in Cloud-Delivered Firewall Management Center
      • Prerequisites to Onboard a Device to Cloud-Delivered Firewall Management Center
      • Onboard a Device with a CLI Registration Key
      • Onboard a Firewall Threat Defense Device to Cloud-Delivered Firewall Management Center using Zero-Touch Provisioning
      • Onboard a Firewall Threat Defense Device to On-Prem Firewall Management Center using Zero-Touch Provisioning
      • Onboard Firewall Threat Defense Devices using Device Templates to Cloud-Delivered Firewall Management Center using Zero-Touch Provisioning
      • Cloud Deployment
        • Configure FTDv enforcement point
        • Configure Multicloud Defense enforcement point
      • Onboard a Secure Firewall Threat Defense Cluster
      • Onboard a Chassis
      • Complete the initial configuration of a Secure Firewall Threat Defense device using the CLI
      • Delete Devices from Cloud-Delivered Firewall Management Center
      • Troubleshooting
        • Troubleshoot Cloud-Delivered Firewall Management Center Connectivity with TCP
        • Troubleshoot Firewall Threat Defense Device Connectivity
        • Troubleshoot Device Connectivity Loss After Cloud-Delivered Firewall Management Center Update
        • Troubleshoot Onboarding a Device to the Cloud-Delivered Firewall Management Center Using the CLI Registration Key
          • Error: Device Remains in Pending Setup State After Onboarding
        • Troubleshoot Onboarding a Device to Cloud-Delivered Firewall Management Center Using the Serial Number
          • Device is Offline or Unreachable
          • Error: Serial Number Already Claimed
          • Error: Claim Error
          • Error: Failed to Claim
          • Error: Provisional Error
    • Migrate Threat Defense to Cloud-Delivered Firewall Management Center
      • Overview of Firewall Threat Defense to Cloud-Delivered Firewall Management Center migration
        • How Firewall Threat Defense Migration to Cloud-Delivered Firewall Management Center Works
        • About 14-day evaluation period
        • How Firewall Threat Defense licenses are handled during migration to Cloud-Delivered Firewall Management Center
      • End-to-End Workflow for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • Event and Analytics Management options during Firewall Threat Defense migration
      • Supported features
      • Unsupported features
      • Migration guidelines and limitations for VPN configuration
      • Supported On-Premises Firewall Management Center and Firewall Threat Defense software versions for migration
      • Prerequisites for Migrating Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • Migrate Firewall Threat Defense to Cloud-Delivered Firewall Management Center
      • View a Firewall Threat Defense Migration Job
        • Proceed Migration Process
        • Commit Migration Changes Manually to Cloud-Delivered Firewall Management Center
        • Revert the Firewall Threat Defense Management to On-Premises Firewall Management Center
        • View Migrated Devices
        • Generate a Firewall Threat Defense Migration Report
        • Delete a Migration Job
      • Enable Notification Settings
      • Verify Firewall Threat Defense Connectivity with Cloud-Delivered Firewall Management Center
      • Use the Troubleshoot Feature for Failed Migrations
        • Resolving Firewall Threat Defense Migration to Cloud-Delivered Firewall Management Center Issues
    • Configure Cloud-Delivered Firewall Management Center-Managed Secure Firewall Threat Defense
      • Security Cloud Control Firewall Management Integrations Page
      • Navigate to the Cloud-Delivered Firewall Management Center in your Security Cloud Control Tenant
      • Enable Cloud-Delivered Firewall Management Center
    • Introduction to AIOps insights
      • About AIOps insights
        • AIOps licensing requirements
        • Prerequisites to use AIOps
        • View summary dashboard
        • View AIOps insights
      • About capacity and traffic insights
        • Analyze capacity trends and forecast resource usage
      • About application insights
        • Detect application outages
      • About compliance insights
        • Generate compliance reports
      • About best practices and ecommendations
        • Implement best practices and recommendations
      • About feature adoption insights
        • Assess and improve feature adoption
      • About software upgrade insights
        • Manage software upgrades
      • Manage insight preferences
        • Enable AIOps insights
        • Disable AIOps insights
        • Best practices and recommendations insights
        • Feature adoption insights
        • Application insights
        • Capacity and traffic insights
        • Operational insights
      • Frequently asked questions about AIOps
      • Additional resources
    • Introduction to Agent Workforce
      • About Agent Workforce
        • Available agents in Agent Workforce
        • Manage Conversations in Agent Workforce
        • Limitations and considerations
      • Troubleshoot site-to-site VPN issues with VPN agent
        • Benefits
        • How VPN agent works
        • Best practices
        • Example prompts and expected outcomes
      • Remediate traffic congestion with Elephant flow agent
        • Benefits
        • How Elephant flow remediation works
        • Best practices
      • Optimize firewall policies with Policy Copilot
        • Benefits
        • How Policy Copilot works
        • Best practices
        • Example prompts and expected outcomes
    • Monitor Cloud-Delivered Firewall Management Center -Managed Threat Defense Device Events
      • About Security Analytics and Logging(SaaS) for Firewall Threat Defense
      • Implementing SAL (SaaS) for Cloud-Delivered Firewall Management Center -Managed Devices
      • Requirements and Guidelines
      • How Firewall Threat Defense Events are Displayed in Security Cloud Control Using a Direct Connection
      • Send Cloud-Delivered Firewall Management Center -Managed Event Logs to SAL (SaaS) Using a Direct Connection
      • Send Cloud-Delivered Firewall Management Center -Managed Events to SAL (SaaS) Using Syslog
      • Enable Individual Threat Defense Devices to Send Events to SAL (SaaS) Using a Direct Connection
      • View AI Defense Events in Security Cloud Control
    • FTD Dashboard
      • About the FTD Dashboard
      • View the FTD Dashboard
      • FTD Dashboard Widgets
        • Top Intrusion Rules Widget
        • Top Intrusion Attackers Widget
        • Top Intrusion Targets Widget
        • Top Malware Signatures Widget
        • Top Malware Senders Widget
        • Top Malware Receivers Widget
        • Malware Events by Disposition Widget
        • Network Activity Widget
        • Event Activity Widget
        • Access Control Actions Widget
        • Top Access Control Policies Widget
        • Top Access Control Rules Widget
        • Top Devices Widget
        • Top Users Widget
        • Top Users by Blocked Connections Widget
        • Top Devices with Health Alerts Widget
        • Top Loaded Devices Widget
        • Top Web Applications Widget
        • Top Client Applications Widget
        • Top Blocked Web Applications Widget
      • Modify Time Settings for the FTD Dashboard
    • Analyze and Remediate Security Policy Anomalies with Policy Analyzer and Optimizer
      • About Policy Analyzer and Optimizer
      • Prerequisites to use Policy Analyzer and Optimizer
      • Enable Policy Analyzer and Optimizer for Security Cloud Control-managed On-Premises Firewall Management Center
      • Policy Analyzer and Optimizer licensing requirements
      • Open Policy Analyzer and Optimizer and select a data source
        • Sync and analysis behavior
      • Search and filter policies in Policy Analyzer and Optimizer
      • Access control policy analysis and optimization
        • Analyze access control policies
        • Access control policy analysis summary
        • Analyze duplicate rules in access control policy
        • Analyze expired rules in access control policy
        • Analyze mergeable rules in access control policy
        • Analyze overlapping objects in access control policy
        • Analyze policy insights in access control policy
        • Access control policy remediation
        • Download access control analysis report
      • Troubleshooting Policy Analyzer and Optimizer
        • Policy Analyzer and Optimizer Does Not Analyze Policies
        • Policy Analyzer and Optimizer Does Not Fetch Policies
      • Frequently Asked Questions About Policy Analyzer and Optimizer
  • Manage Catalyst SD-WAN Manager Firewall Capabilities
    • Integrate Catalyst SD-WAN Manager with Security Cloud Control
      • Overview of Catalyst SD-WAN integration with Security Cloud Control Firewall Management
      • System topology diagram
      • End-to-end workflow to manage Catalyst SD-WAN Manager using Security Cloud Control
      • Minimum software requirements
      • Additional resources
    • Onboard Catalyst SD-WAN Manager
      • Onboard Catalyst SD-WAN Manager to Security Cloud Control
      • Deboard Catalyst SD-WAN Manager from Security Cloud Control
      • Alignment of RBAC models of Security Cloud Control Firewall Management and Catalyst SD-WAN Manager
      • How Security Cloud Control Firewall Management manages Catalyst SD-WAN NGFW capabilities
      • View intrusion events
      • View malware events
    • Configure Next-Generation Firewall Capabilities of Catalyst SD-WAN Manager
      • Overview of Catalyst SD-WAN devices
      • Supported operations on Catalyst SD-WAN devices
      • View configuration of Catalyst SD-WAN devices
      • Cross-launch policy groups from Security Cloud Control Firewall Management
      • Overview of Catalyst SD-WAN security objects and security profiles
      • Create new Catalyst SD-WAN security objects and security profiles
        • Application List
        • Data Prefix
        • FQDN
        • Geolocation
        • Identity
        • Port
        • Protocol
        • Security Group Tag
        • IPS Signature
        • Allow URL
        • Block URL
        • Zone
        • Advanced Inspection Profile
        • Advanced Malware Protection
        • Intrusion Prevention
        • TLS/SSL Decryption
        • TLS/SSL Profile
        • URL Filtering
      • Modify Catalyst SD-WAN security objects and security profiles
      • Delete Catalyst SD-WAN security objects
      • Filter Catalyst SD-WAN security objects
      • An introduction to Catalyst SD-WAN NGFW security policies
      • Manage existing Catalyst SD-WAN NGFW security policies
      • Create Catalyst SD-WAN security policies
      • Associate a policy group to Catalyst SD-WAN NGFW policy
      • Deploy policy group from Catalyst SD-WAN Manager
    • Monitor Catalyst SD-WAN Events
      • Overview of Security Analytics and Logging for Catalyst SD-WAN
      • How Catalyst SD-WAN router shares events with Security Cloud Control Firewall Management
      • Requirements and guidelines
      • View Catalyst SD-WAN events in Security Cloud Control Firewall Management
  • Manage On-Premises Firewall Management Center
    • Onboard an On-Premises Firewall Management Center
      • Onboard an On-Premises Firewall Management Center to Security Cloud Control Firewall Management
        • Auto onboard an On-Premises Firewall Management Center integrated with Cisco Security Cloud
          • Integrate an On-Premises Firewall Management Center With Cisco Security Cloud
          • Auto onboard On-Prem FMCs from Cisco Security Cloud
        • Onboard an On-Premises Firewall Management Center to Security Cloud Control with Credentials
        • Redirect Security Cloud Control to an On-Premises Firewall Management Center
      • Remove an On-Premises Firewall Management Center from Security Cloud Control
    • Configure On-Premises Firewall Management Center-Managed Threat Defense Devices
      • Manage On-Premises Firewall Management Center with Security Cloud Control
      • View onboarded On-Premises Firewall Management Center
      • Discover and manage On-Premises Firewall Management Center network objects
      • Preview and deploy On-Premises Firewall Management Center configurations
      • Discard On-Premises Firewall Management Center configuration changes
  • Manage Cisco Umbrella
    • Onboard an Umbrella Organization
      • Onboarding an Umbrella organization
        • Umbrella license requirements
        • Generate an API key and secret
        • Umbrella organization ID
        • Onboard an Umbrella organization
        • Reconnect an Umbrella organization to Security Cloud Control
        • Cross-launch to the Umbrella dashboard
        • Delete a device from Security Cloud Control Firewall Management
    • Configure an Umbrella Organization
      • Read Umbrella tunnel configuration
      • Cross-launch to the Umbrella tunnels page
      • Configure a SASE tunnel for Umbrella
      • Edit a SASE tunnel
      • Delete a SASE tunnel from Umbrella
  • Manage Cisco Meraki
    • Onboard Cisco Meraki MX devices
      • Onboard Cisco Meraki MX devices
        • Onboard Meraki MX to Security Cloud Control
          • Generate and Retrieve Meraki API Key
          • Onboard an MX Device to Security Cloud Control
        • Onboard Meraki templates to Security Cloud Control
          • Generate and Retrieve Meraki API Key
          • Onboard an Meraki Template to Security Cloud Control
        • Update Meraki MX connection credentials
        • Delete a device from Security Cloud Control Firewall Management
    • Configure Cisco Meraki
      • Managing Meraki with Security Cloud Control
      • How does Security Cloud Control communicate with Meraki
      • Meraki Access Control Policy
      • Meraki templates
  • Manage AWS VPC
    • Onboard AWS VPC
      • Supported devices, software, and hardware for Security Cloud Control Firewall Management
        • ASA support specifics
        • Cloud Device Support Specifics
        • Switching and Routing Support Specifics
      • Onboard an AWS VPC
    • Configure AWS VPC
      • Manage AWS VPCs with Security Cloud Control Firewall Management
      • Update AWS VPC connection credentials
      • Monitor AWS VPC tunnels using AWS transit gateway
      • Search and filter site-to-site VPN tunnels
      • View AWS VPC tunnel history
      • AWS VPC Policy
        • AWS VPC Security Groups Rules
        • Create a Security Group Rule
        • Edit a Security Group Rule
        • Delete a Security Group Rule
  • Manage Cisco IOS
    • Onboard Cisco IOS Devices
      • Onboard a Cisco IOS Device
        • Onboard a Cisco IOS Device
          • Create and Import an ASR or ISR Model
            • Download ASR or ISR Configuration
            • Import ASR or ISR Configuration
        • Import Configuration for Offline Device Management
        • Delete a device from Security Cloud Control Firewall Management
    • Configure Cisco IOS
      • Manage IOS Devices with Security Cloud Control
      • Object filters
      • Use the Security Cloud Control Command Line Interface Tool
        • View Device Configuration File
  • Manage Network Devices with Generic SSH Access
    • Onboard an SSH Device
      • Onboard an SSH Device
        • Onboard an SSH Device
        • Delete a device from Security Cloud Control Firewall Management
        • Use the Security Cloud Control Command Line Interface Tool
          • View a Device's Configuration File
    • Configure SSH Devices
      • Managing SSH Devices with Security Cloud Control
      • Use the Security Cloud Control Command Line Interface Tool
        • View a Device's Configuration File
  • Establish Secure Connections
    • Virtual Private Network Management
      • Configure Virtual Private Network Management
        • Introduction to Site-to-Site Virtual Private Network
        • Site-to-Site VPN concepts
          • Global IKE policies
            • Managing IKEv1 Policies
            • Create an IKEv1 Policy
            • Managing IKEv2 Policies
            • Create an IKEv2 Policy
          • IPsec proposal and IKE policy objects
            • Managing an IKEv1 IPsec Proposal Object
              • Create an IKEv1 IPsec Proposal Object
            • Managing an IKEv2 IPsec Proposal Object
              • Create or Edit an IKEv2 IPsec Proposal Object
          • Encryption and Hash Algorithms Used in VPN
        • Site-to-Site VPN configuration for FDM-Managed
          • Create a Site-To-Site VPN Tunnel Between FDM-managed Devices
          • Configure Networking for Protected Traffic Between the Site-To-Site Peers
          • Edit an Existing Security Cloud Control Site-To-Site VPN
            • Delete a Security Cloud Control Firewall Management Site-To-Site VPN Tunnel
          • Exempt Site-to-Site VPN Traffic from NAT
        • Site-to-Site VPN Configuration for Cloud-Delivered Firewall Management Center -managed Firewall Threat Defense
          • Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center -managed Firewall Threat Defense Devices
          • Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center -Managed Firewall Threat Defense and Multicloud Defense
          • Create a Site-to-Site VPN Between Cloud-Delivered Firewall Management Center -managed Firewall Threat Defense and Secure Firewall ASA
        • Site-to-Site VPN for Secure Firewall ASA
          • Create a Site-to-Site VPN Tunnel Between Secure Firewall ASA
          • Create a Site-to-Site VPN Between ASA and Multicloud Defense Gateway
          • Exempt Site-to-Site VPN Traffic from NAT
        • Monitor ASA Site-to-Site Virtual Private Networks
          • Check Site-to-Site VPN Tunnel Connectivity
          • Site-To-Site VPN Dashboard
          • Identify VPN Issues
            • Find VPN Tunnels with Missing Peers
            • Find VPN Peers with Encryption Key Issues
            • Find Incomplete or Misconfigured Access Lists Defined for a Tunnel
            • Find Issues in Tunnel Configuration
            • Resolve Tunnel Configuration Issues
          • Search and filter site-to-site VPN tunnels
          • Onboard an Unmanaged Site-to-Site VPN Peer
          • Viewing AWS Site-to-Site VPN Tunnels
          • View IKE Object Details of Site-To-Site VPN Tunnels
          • View Last Successful Site-to-Site VPN Tunnel Establishment Date
          • View Site-to-Site VPN Tunnel Information
            • Site-to-Site VPN Global View
            • Site-to-Site VPN Tunnels Pane
        • Delete a Security Cloud Control Firewall Management Site-To-Site VPN Tunnel
        • Introduction to Remote Access Virtual Private Network
          • Introduction to Remote Access Virtual Private Network
          • Configure Remote Access Virtual Private Network for ASA
            • End-to-End Remote Access VPN Configuration Process for ASA
              • Create ASA Remote Access VPN Configuration
                • Modify ASA Remote Access VPN Configuration
              • Configure ASA Remote Access VPN Connection Profile
                • Configure AAA for a Connection Profile
              • Manage AnyConnect Software Packages on ASA Devices
                • Upload an AnyConnect Package from Security Cloud Control Repository
                • Upload an AnyConnect Package to ASA from Server
                • Upload new AnyConnect Packages to ASA
                • Upload AnyConnect Packages using File Management Wizard
                • Replace an AnyConnect Package
                • Delete an AnyConnect Package
            • Manage and Deploy Pre-existing ASA Remote Access VPN Configuration
              • Device Settings
              • Connection Profile
              • Primary Identity Source
              • AAA Server Groups
              • RADIUS Server Group
              • RADIUS Server
              • Group Policy
            • Remote Access VPN Certificate-Based Authentication
            • Exempt Remote Access VPN Traffic from NAT
            • Install the AnyConnect Client Software on ASA
            • Modify ASA Remote Access VPN Configuration
            • Modify ASA Connection Profile
            • Upload RA VPN AnyConnect Client Profile
            • Verify ASA Remote Access VPN Configuration
            • View ASA Remote Access VPN Configuration Details
    • Configuring Firewall for Universal Zero Trust Network Access
      • Universal Zero Trust Network Access
      • Onboard Applications in Security Cloud Control
      • Enable Cloud-Delivered Firewall Management Center in Security Cloud Control
      • Configure Security Devices
  • Device Operations
    • Manage device configuration
      • Read, discard, and deploy configuration changes
        • Read All Device Configurations
        • Read configuration changes from an ASA to Security Cloud Control
          • Read configuration changes on ASA device
        • Read changes from Firewalls
        • Preview and deploy configuration changes for all devices
        • Deploy configuration changes from Security Cloud Control to ASA
          • Deploy configuration changes
          • Deploy configuration changes made using the Security Cloud Control GUI
          • Schedule automatic deployments
          • Deploy configuration changes using Security Cloud Control's CLI interface
          • Deploy configuration changes by editing the device configuration
          • Deploy Configuration Changes for a Shared Object on Multiple Devices
        • Deploy Changes to a Device
          • Cancelling Changes
          • Discarding Changes
        • Bulk Deploy Device Configurations
        • Preview and deploy On-Premises Firewall Management Center configurations
        • About Scheduled Automatic Deployments
          • Schedule an Automatic Deployment
          • Edit a Scheduled Deployment
          • Delete a Scheduled Deployment
        • Check for Configuration Changes
        • Discard Configuration Changes
        • Discard On-Premises Firewall Management Center configuration changes
        • Out-of-Band Changes on Devices
      • Synchronizing configurations between Security Cloud Control and device
        • Conflict Detection
          • Enable Conflict Detection
          • Enable conflict detection for an On-Premises Firewall Management Center
        • Automatically Accept Out-of-Band Changes from your Device
          • Configure Auto-Accept Changes
          • Disabling Auto-Accept Changes for All Devices on the Tenant
        • Resolve configuration conflicts
          • Resolve the Not Synced Status
          • Resolve the conflict detected status
        • Schedule polling for device changes
        • Schedule a Security Database Update
          • Create a Scheduled Security Database Update
          • Edit a Scheduled Security Database Update
      • Synchronizing configurations between Security Cloud Control and device
        • Conflict Detection
          • Enable Conflict Detection
          • Enable conflict detection for an On-Premises Firewall Management Center
        • Automatically Accept Out-of-Band Changes from your Device
          • Configure Auto-Accept Changes
          • Disabling Auto-Accept Changes for All Devices on the Tenant
        • Resolve configuration conflicts
          • Resolve the Not Synced Status
          • Resolve the conflict detected status
        • Schedule polling for device changes
        • Schedule a Security Database Update
          • Create a Scheduled Security Database Update
          • Edit a Scheduled Security Database Update
    • Manage onboarded device settings
      • Changing a device's IP address in Security Cloud Control Firewall Management
      • Changing a device's name in Security Cloud Control Firewall Management
      • Export a list of devices and services
      • Export device configuration
      • External links for devices
        • Create an External Link from your Device
        • Create an External Link to ASDMFDM
        • Create an External Link for Multiple Devices
        • Edit or Delete External Links
        • Edit or Delete External Links for Multiple Devices
      • Bulk reconnect devices to Security Cloud Control Firewall Management
      • Moving devices between organizations
      • Device certificate expiry detection
      • Update Meraki MX connection credentials
      • Write a device note
      • Delete a device from Security Cloud Control Firewall Management
      • Manage security devices
      • Back up Firewall Threat Defense devices
      • Manage Firewall Threat Defense devices through Security Cloud Control Firewall Management
      • Security devices overview
      • Security Cloud Control Firewall Management labels and filtering
        • Apply Labels to Devices and Objects
        • Labels and Tags in AWS VPC
        • Filters on security devices, policies, and objects page
      • Use Security Cloud Control Firewall Management search functionality
        • Page Level Search
        • Global Search
          • Initiate Full Indexing
          • Perform a Global Search
      • Security devices overview
      • Security Cloud Control Firewall Management labels and filtering
        • Apply Labels to Devices and Objects
        • Labels and Tags in AWS VPC
        • Filters on security devices, policies, and objects page
      • Use Security Cloud Control Firewall Management search functionality
        • Page Level Search
        • Global Search
          • Initiate Full Indexing
          • Perform a Global Search
    • Use the Security Cloud Control Command Line Interface Tool
      • Use the Command Line Interface on a single device
      • Use the bulk Command Line Interface
      • Run a CLI macro
      • Export Command Line Interface results
    • Manage CLI Templates
      • CLI Templates
      • Create a CLI Template
      • Edit a CLI Template
      • Export a CLI Template
      • Delete a CLI Template
    • Migrate Firewalls with the Migration Tool in Security Cloud Control
      • Is This Guide for You?
      • Get Started with the Firewall Migration Tool in Security Cloud Control
        • Supported Configurations
        • Licenses
        • Initialize a New Migration Instance
        • Delete a Migration Instance
        • Using the Demo Mode in the Secure Firewall Migration Tool
      • Migrate Secure Firewall ASA to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrating Microsoft Azure Native Firewall with the Firewall Migration Tool in Security Cloud Control
      • Migrate FDM-Managed Device to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Check Point Firewall to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrating Check Point Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Fortinet Firewall with the Firewall Migration Tool in Security Cloud Control
      • Migrating Fortinet Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Palo Alto Networks Firewall to Secure Firewall Threat Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Secure Firewall ASA to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Migrate Palo Alto Networks Firewall to Multicloud Defense with the Firewall Migration Tool in Security Cloud Control
      • Related Documentation
  • Monitor and Analyze
    • Events in Security Cloud Control
      • About Security Analytics and Logging (SaaS) in Security Cloud Control
      • Event types in Security Cloud Control
      • Troubleshooting network problems using Security and Analytics Logging events
      • Deprovisioning Cisco Security Analytics and Logging (SaaS)
    • Security Analytics and Logging Licenses
      • Security Analytics and Logging licenses
        • Subscribe to a Security Analytics and Logging license
        • View Security Analytics and Logging license information
        • View Security Analytics and Logging Storage usage and event ingest rate
        • Monitor Security Analytics and Logging service availability
        • Extend event storage duration and increase event storage capacity
        • View Security Analytics and Logging alerts
        • Frequently asked questions about Security Analytics and Logging license
    • Secure Event Connectors
      • About Secure Event Connectors
      • Installing Secure Event Connectors
        • Install a Secure Event Connector on an SDC Virtual Machine
        • Installing an SEC Using a Security Cloud Control Image
          • Install a Security Cloud Control Connector, to Support a Secure Event Connector, Using a Security Cloud Control VM Image
          • Install the Secure Event Connector on the Security Cloud Control Connector VM
        • Deploy Secure Event Connector on Ubuntu Virtual Machine
        • Install an SEC Using Your VM Image
          • Install a Security Cloud Control Connector to Support an SEC Using Your VM Image
          • Additional Configuration for SDCs and Security Cloud Control Connectors Installed on a VM You Created
          • Install the Secure Event Connector on your Security Cloud Control Connector Virtual Machine
        • Install a Secure Event Connector on an AWS VPC Using a Terraform Module
      • Remove the Secure Event Connector
        • Remove an SEC from Security Cloud Control
        • Remove a Secure Event Connector from the Secure Device Connector VM
      • Finding your device's TCP, UDP, and NSEL port used for Secure Logging Analytics (SaaS)
    • View Events in Security Cloud Control Firewall Management
      • View live events
        • Play/Pause Live Events
      • View historical events
      • Customize the events view
        • Correlate Firewall Threat Defense Event Fields and Column Names
      • Show and hide columns on the event logging page
      • Change the time zone for the event timestamps
      • Customizable event filters
      • Search and filter events using the event logging page
        • Filter Live or Historical Events
        • Filter Only NetFlow Events
        • Filter for ASA or FDM-Managed Device Syslog Events but not ASA NetFlow Events
        • Combine Filter Elements
        • Search Events Using the Events Logging Page
          • Use Sample Filters to Search Events
          • Search Historical Events in the Background
            • Schedule to Generate a Search Report in the Background
            • Download a Search Report
      • Event attributes in Security Analytics and Logging
        • EventGroup and EventGroupDefinition Attributes for Some Syslog Messages
        • EventName Attributes for Syslog Events
        • Time Attributes in a Syslog Event
    • Monitor Remote Access Virtual Private Network Sessions from Secure Firewall ASA and Firewall Threat Defense
      • Monitor Remote Access Virtual Private Network Sessions
        • Monitor Live AnyConnect Remote Access VPN Sessions
          • View Live Remote Access VPN Data
        • Monitor Historical AnyConnect Remote Access VPN Sessions
          • View Historical Remote Access VPN Data
        • Search and Filter Remote Access VPN Sessions
        • Customize the Remote Access VPN Monitoring View
        • Export Remote Access VPN Sessions to a CSV File
        • Remote Access VPN Dashboard
        • Disconnect Remote Access VPN Sessions of an ASA User
          • Disconnect all Active RA VPN Sessions of a User
        • Disconnect Remote Access VPN Sessions on FDM-Managed Device
        • Disconnect Remote Access VPN Sessions on FTD
    • Smart Licensing Dashboard
      • Overview of Smart Licensing Dashboard
      • View Smart Licensing Dashboard
    • Monitor and report change logs, workflows, and jobs
      • Monitor and report change logs, workflows, and jobs
      • Manage change logs in Security Cloud Control
      • Change log entries after deploying to an ASA
      • Change log entries after reading changes from an ASA
      • View change log differences
      • Change request management
        • Enable Change Request Management
        • Create a Change Request
        • Associate a Change Request with a Change Log Event
        • Search for Change Log Events with Change Requests
        • Search for a Change Request
        • Filter Change Requests
        • Clear the Change Request Toolbar
        • Clear a Change Request Associated with a Change Log Event
        • Delete a Change Request
        • Disable Change Request Management
        • Change Request Management Use Cases
      • Export the change log
        • Differences Between Change Log Capacity in Security Cloud Control and Size of an Exported Change Log
      • Monitor jobs in Security Cloud Control
        • Reinitiate a Bulk Action
        • Cancel a Bulk Action
      • Monitor workflows in Security Cloud Control
  • Troubleshoot
    • Troubleshooting
      • Troubleshoot a Secure Firewall ASA device
        • ASA Fails to Reconnect to Security Cloud Control After Reboot
        • Cannot onboard ASA due to certificate error
          • Determine the OpenSSL Cipher Suite Used by your ASA
          • Cipher Suites Supported by Security Cloud Control's Secure Device Connector
          • Updating your ASA's Cipher Suite
        • Troubleshoot ASA using CLI commands
        • Troubleshoot ASA Remote Access VPN
        • ASA Real-time Logging
          • View ASA Real-time Logs
        • ASA Packet Tracer
          • Troubleshoot an ASA Device Security Policy
          • Troubleshoot an Access Rule
          • Troubleshoot a NAT Rule
          • Troubleshoot a Twice NAT Rule
          • Analyze Packet Tracer Results
        • Confirming ASA Running Configuration Size
        • Large ASA Running Configuration Files
      • Troubleshoot a Secure Device Connector
        • SDC is Unreachable
        • SDC Status not Active on Security Cloud Control After Deployment
        • Changed IP Address of the SDC is not Reflected in Security Cloud Control
        • Troubleshoot Device Connectivity with the SDC
        • Intermittent or No Connectivity with SDC
        • Container Privilege Escalation Vulnerability Affecting Secure Device Connector: cisco-sa-20190215-runc
          • Updating a Security Cloud Control-Standard SDC Host
          • Updating a Custom SDC Host
          • Bug Tracking
        • Invalid System Time
        • SDC version is lower than 202311****
        • Certificate or Connection errors with AWS servers
      • Troubleshoot a Secure Event Connector
        • Troubleshoot SEC Onboarding Failures
        • Troubleshoot Secure Event Connector Registration Failure
        • Troubleshooting NSEL Data Flows
        • Event Logging Troubleshooting Log Files
        • SEC Status is Inactive in Security Cloud Control
        • The SEC is online, but there are no events in Security Cloud Control Event Logging Page
        • Remove an SEC from Your Host
        • Use Health Check to Learn the State of your Secure Event Connector
      • Troubleshoot Security Cloud Control
        • Troubleshooting Access and Certificates
          • Troubleshoot User Access with Security Cloud Control
          • Resolve New Fingerprint Detected State
          • Troubleshooting SSL Decryption Issues
        • Troubleshooting Objects
          • Resolve Duplicate Object Issues
          • Resolving Inconsistent or Unused Security Zone Objects
          • Resolve Unused Object Issues
            • Resolve an Unused Object Issue
            • Remove Unused Objects in Bulk
          • Resolve Inconsistent Object Issues
          • Resolve Object Issues in Bulk
          • Unignore objects
      • Device connectivity states
        • Troubleshoot Device Unregistered
        • Troubleshoot Insufficient Licenses
        • Troubleshoot Invalid Credentials
        • Troubleshoot New Certificate Issues
          • New Certificate Detected
        • Troubleshoot Onboarding Error
        • Resolve the conflict detected status
        • Resolve the Not Synced Status
    • FAQ and support
      • Security Cloud Control
      • FAQ about onboarding devices to Security Cloud Control
        • FAQs About Onboarding Secure Firewall ASA to Security Cloud Control
        • FAQs About Onboarding Secure Firewall Threat Defense to Cloud-Delivered Firewall Management Center
        • FAQs About on-premises Firewall Management Center
        • FAQs About Onboarding Meraki Devices to Security Cloud Control
        • FAQs About Onboarding SSH Devices to Security Cloud Control
        • FAQs About Onboarding IOS Devices to Security Cloud Control
      • Device types
      • Security
      • End-of-Support for management of Secure Firewall Threat Defense devices, Version 7.0.x, managed by Cloud-Delivered Firewall Management Center
      • Troubleshooting
      • Terminologies and definitions used in Zero-Touch Provisioning
      • Policy optimization
      • Connectivity
      • Complete the initial configuration of a Secure Firewall Threat Defense device using the CLI
      • About Data Interfaces
      • How Security Cloud Control processes personal information
      • Contact Security Cloud Control support
        • Export The Workflow
        • Open a Support Ticket with TAC
          • How Security Cloud Control Customers Open a Support Ticket with TAC
          • How Security Cloud Control Trial Customers Open a Support Ticket with TAC
        • Security Cloud Control Service Status Page
  • Appendix
    • Security and Internet Access
      • Security requirements
      • Internet access requirements
    • Terraform
      • About Terraform
    • Open Source and 3rd Party License Attribution
      • Open Source and Third-Party License in SDC
    • Cisco AI Assistant User Guide
      • Onboard with Cisco AI Assistant
      • Prompt Guide for Cisco AI Assistant
      • Online Help Documentation
      • Policy Insights
      • Policy Analyzer and Optimizer
      • Automate Policy Rule Creation
      • Contact Support
      • Notifications Center
      • Cisco AI Assistant Frequently Asked Questions (FAQ)

Manage Secure Firewall ASA Monitor Secure Firewall ASA Events Send ASA syslog events to the Cisco Cloud using the command line interface Include the Device ID in Non-EMBLEM Format Syslog Messages

Last updated: Jul 16, 2026

Previous topic Create a Custom Event List Next topic NetFlow Secure Event Logging (NSEL) for ASA devices
© 2026 Cisco System, Inc.
Privacy policyTerms of Service