Skip to main content



Cisco Defense Orchestrator

Onboard a Firepower Threat Defense Device with a Registration Token

This procedure describes how to onboard a Firepower Threat Defense (FTD) device using a registration token. This method is the recommended way of onboarding the FTD device to CDO and is beneficial if your FTD is assigned an IP address using DHCP. If that IP address changes for some reason, your FTD remains connected to CDO. Additionally, your FTD can have an address on your local area network, and as long as it can access the outside network, it can be onboarded to CDO using this method.

Before Onboarding

  • This method of onboarding is currently available for FTD 6.4 and later releases and to customers connecting to 
    Note: This method is also available to customers connecting to only from FTD 6.5 and later releases. 
  • Make sure your device is managed by Firepower Device Manager, not Firepower Management Center. 
  • Make sure the licenses installed on the device are not registered with Cisco Smart Software Manager. You will need to un-register the FTD if it is already smart-licensed.
  • The device may be using a 90-day evaluation license.
  • Log in to the FTD's, Firepower Device Manager and make sure that there are no pending changes waiting on the device.
  • Make sure DNS is configured properly on your FTD device.
  • Make sure the time services are configured properly on the FTD device.
  • Make sure the FTD device shows the correct date and time otherwise the onboarding will fail.
  • Review Connect to Cisco Defense Orchestrator using Secure Device Connector.

Note: For FTD 6.4, if you connect to, you must onboard an FTD using username, password, and IP address. You cannot use this method.

Unregistering a Smart-Licensed FTD

If the FTD is already smart-licensed, the device is likely to be registered with Cisco Smart Software Manager. You will need to unregister the device from Cisco Smart Software Manager before you onboard it to CDO with a registration token. When you unregister, the base license and all optional licenses associated with the device, are freed in your virtual account. 

After unregistering the device, the current configuration and policies on the device continue to work as-is, but you cannot make or deploy any changes.

  1. Log on to the FTD using Firepower Device Manager (FDM).
  2. Click the name of the device in the FDM menu, then click View Configuration in the Smart License summary area.
  3. From the gear drop-down menu, select Unregister Device.
  4. Read the warning and click Unregister to unregister the device.

Onboarding Procedure

To onboard a Firepower Threat Defense Device using a registration token, follow this procedure: 

  1. Log in to CDO.
  2. In the navigation pane, click Devices & Services page and click the blue plus button blue_cross_button.png to Onboard a device.
  3. Click the Firepower Threat Defense Device card.
  4. On the Onboard FTD Device screen, click Use Token.
  5. In step 1 of the onboarding wizard, give the device a name. This could be the hostname of the device or any other name you choose.
  6. Click Next.
  7. Click Generate Token. CDO generates a registration token.

Note: If you move away from the onboarding screen after the token is generated and before the device is fully onboarded, you will not be able to return to the onboarding screen; however, CDO creates a placeholder for that device on the Device & Services page. When you select the device's placeholder, you will be able to see the token for that device, on that page. 

  1. Click the Copy icon copy_icon.png to copy the registration token. 

Note: You can skip copying the registration token and click Next to complete the place holder entry for the device and later, register the device. This option is useful when you're attempting to create the device first and later register it or if you're a Cisco partner installing a Proof of Value (POV) device in a customer network. 
The device is now in the connectivity state, "Unprovisioned". Copy the registration key appearing under Unprovisioned to Firepower Defense Manager to complete the onboarding process.

  1. Log into the Firepower Device Manager (FDM) for the Firepower Threat Defense device you want to onboard to CDO. 
  2. Under System Settings, click Cloud Services.
  3. In the Cisco Defense Orchestrator area, expand Get Started.
  4. In the Registration Key field, paste the registration token that you generated in CDO.
  5. Click Register and then Accept the Cisco Disclosure. FDM sends the registration request to CDO.
  6. Click the Task List link to see the progress of the device enrollment.
  7. When the Task List displays the Cloud Service message, "Device has been enrolled," return to the Onboard FTD Device page in CDO.
  8. In step 2 of the onboarding wizard, CDO polls for the device. 

Note: After an hour of polling, if the device is not found, you will be given a link to click to refresh the polling for another hour. 

  1. When you see "The device connected successfully" in step 2 of the onboarding wizard, click Next.

You can apply a smart-license to the FTD device. For more information, see Applying or Updating a Smart-License.


Related Topics