Skip to main content



Cisco Defense Orchestrator

Read Umbrella Tunnel Configuration

Once an Umbrella organization is onboarded to CDO, you can manually force CDO to request and update the tunnels configuration from Umbrella. This includes tunnels that were added, deleted, or modified. 

Warning: If a tunnel is deleted from CDO while the Umbrella organization credentials are considered invalid, or have changed since you onboarded the organization, CDO can only deploy the tunnel configuration to the ASA devices associated with the organization. Upon updating the credentials, CDO reads the Umbrella configuration and repopulates any tunnels that were deleted. Due to the tunnel existing in the Umbrella organization but not any of the ASA devices, there will be a synchronization issue and the ASA devices may not appear as peers to organization. 

Use the following procedure to manually update tunnel configurations in CDO:

  1. Log into CDO. 
  2. Navigate to the Devices & Services page. 
  3. Select the Umbrella organization so it is highlighted. 
  4. In the Actions pane, select Read Tunnels

Related Information:

  • Was this article helpful?