FlexConfig policy overview

A FlexConfig policy is a container of an ordered list of FlexConfig objects that

  • includes a series of Apache Velocity scripting language commands, ASA software configuration commands, and variables that you define

  • contains FlexConfig objects that are essentially programs that generate a sequence of ASA commands that will then be deployed to the assigned devices, and

  • configures the related feature on the Firewall Threat Defense device.

FlexConfig policy usage and limitations

Firewall Threat Defense uses ASA configuration commands to implement some features, but not all features. There is no unique set of Firewall Threat Defense configuration commands. Instead, the point of FlexConfig is to allow you to configure features that are not yet directly supported through Cloud-Delivered Firewall Management Center policies and settings.

Caution

We recommend using FlexConfig policies only if you are an advanced user with a strong ASA background and at your own risk. You may configure any commands that are not prohibited. Enabling features through FlexConfig policies may cause unintended results with other configured features.

Contact the Cisco Technical Assistance Center for support concerning FlexConfig policies that you have configured. The Cisco Technical Assistance Center does not design or write custom configurations on any customer's behalf. Cisco expresses no guarantees for correct operation or interoperability with other features. FlexConfig features may become deprecated at any time. For fully guaranteed feature support, you must wait for the Cloud-Delivered Firewall Management Center support. When in doubt, do not use FlexConfig policies.