
• Cloud Secure Device Connector—The CDO support team deploys a cloud-based SDC for every tenant
when the tenant is created.
• On-Premises Secure Device Connector—An on-premises SDC is a virtual appliance installed in your
network. We recommended that you use an on-premises SDC if you use credentials-based onboarding.
If you use the cloud SDC instead, then you need to allow HTTPS access from the cloud SDC to the
interface used for CDO management. The typical network deployment would require you to enable
HTTPS access on the FTD outside interface, which can be a security risk and also prevents use of the
outside interface for VPN client termination.
For more information, including links for installing an on-premises SDC and cloud SDC IP addresses for
which you may need to grant access to your network (for credentials-based onboarding), see
.
CDO Onboarding Methods
You can onboard a device in the following ways:
• Registration key (recommended)—We recommend this method especially if your device uses DHCP to
obtain its IP address. If that IP address changes, your device remains connected to CDO.
• Credentials (username and password) and an IP address—You can onboard an FTD using the device
admin username and password as well as a static IP address or FQDN. We recommend using an
on-premises SDC connected to the inside interface for this method.
• (6.7+) Serial number—For Low-Touch Provisioning where you do not need to preconfigure the device
using FDM, see the Low-Touch Provisioning chapter in this guide. You can also onboard using a serial
number if you already started configuring the device in FDM, although that method is not covered in
this guide. See
Onboard an FTD using the Device's Serial Number
for more information.
Review the Network Deployment and Default Configuration
You can perform initial setup of the FTD using FDM from either the Management 1/1 interface or the inside
interface. The dedicated Management interface is a special interface that does not allow through traffic and
that has its own network settings.
See the following typical network deployments depending on your Secure Device Connector (SDC) type and
onboarding method.
Cloud SDC Network, Registration Key Onboarding
The following figure shows the recommended network deployment for registration key onboarding using the
cloud SDC. You can use an on-premises SDC with registration key onboarding, but this example shows the
more common cloud SDC use case. You can also use credentials-based onboarding with a cloud SDC, but
that method requires additional configuration in FDM, which may not be desirable.
If you connect the outside interface directly to a cable modem or DSL modem, we recommend that you put
the modem into bridge mode so the FTD performs all routing and NAT for your inside networks. If you need
to configure PPPoE for the outside interface to connect to your ISP, you can do so after you complete initial
setup in FDM.
Cisco Firepower 2100 Getting Started Guide
129
Firepower Threat Defense Deployment with CDO
Review the Network Deployment and Default Configuration
Содержание Firepower 2100
Страница 2: ......
Страница 30: ...Cisco Firepower 2100 Getting Started Guide 28 Firepower Threat Defense Deployment with FDM What s Next ...
Страница 64: ...Cisco Firepower 2100 Getting Started Guide 62 Firepower Threat Defense Deployment with FMC What s Next ...
Страница 108: ...Cisco Firepower 2100 Getting Started Guide 106 Firepower Threat Defense Deployment with a Remote FMC What s Next ...
Страница 164: ...Cisco Firepower 2100 Getting Started Guide 162 Firepower Threat Defense Deployment with CDO What s Next ...
Страница 166: ......
Страница 191: ...Cisco Firepower 2100 Getting Started Guide 189 ASA Deployment with ASDM End to End Procedure ...
Страница 220: ...Cisco Firepower 2100 Getting Started Guide 218 ASA Deployment with ASDM History for the Firepower 2100 in Platform Mode ...
Страница 221: ... 2021 Cisco Systems Inc All rights reserved ...
Страница 222: ......