Skip to main content



Cisco Defense Orchestrator

Onboard an AWS VPC

Before Onboarding your AWS VPC

Note: CDO does not support peered AWS VPCs. If you attempt to onboard a peered VPC referencing a security group that is defined on the peer VPC, the onboarding process fails. 

Before onboarding your Amazon Web Services (AWS) Virtual Private Cloud (VPC) to CDO, review these prerequisites:

  • The Secure Device Connector (SDC) has to be able to reach your AWS VPC, whether you use an on-premises SDC or a Cloud SDC before you can onboard the AWS VPC to Cisco Defense Orchestrator (CDO).
  • To onboard an AWS VPC, you will need the AWS VPC's access key and secret access key both of which are generated using the Identity and Access Management (IAM) console. See Understanding and Getting Your Security Credentials for more information. 
  • Configure the permissions to allow CDO to communicate with your AWS VPC. See Changing Permissions for an IAM User for more information. See the following example for the required permissions:
    "Version": "2012-10-17",
    "Statement": [
            "Effect": "Allow",
            "Action": [
            "Resource": "*"


Onboarding Procedure

To onboard an AWS VPC to CDO, follow this procedure:

  1. From the CDO Navigation Bar, click Devices & Services. 
  2. Click the blue plus button blue_cross_button.png to begin onboarding the device.
  3. Click the AWS VPC tile.
  4. Select the Secure Device Connector (SDC) that this device will communicate with. The default SDC is displayed but you can change it by clicking the SDC name.
  5. Enter the Access Key ID and Secret Access Key credential to connect to the AWS account. The generated list of names are retrieved from the AWS VPC you supplied login credentials to.
  6. Click Connect
  7. Select a Region From the drop-down menu. The region selected should be where the VPC is local to. 
  8. Click Select
  9. Use the drop-down menu to select the correct AWS name. The generated list of names are retrieved from the AWS VPC you supplied login credentials to. Select the desired AWS VPC from the drop-down menu. Note that AWS VPC IDs names are unique, and there cannot be two or more instances with the same ID. 
  10. Click Select
  11. Enter a name to be shown in the CDO UI. 
  12. Click Continue
  13. (Optional) Enter a label for the device. Note that if you create labels for an AWS VPC, the tables are not automatically synchronized to your device. You must manually recreate the labels as tags in the AWS console. See Labels and Label Groups for more information.
  14. Click Continue
  15. Return to the Devices & Services page. After the device has been successfully onboarded, you will see that the Configuration Status is "Synced" and the Connectivity state is "Online." 

Related Articles:

  • Was this article helpful?