Guidelines and limitations for change management
When operating in change management mode, users can make changes to supported policies, but they cannot save the changes. For example, you could go through the dialog box to create a new platform settings policy without an open ticket, but when you click OK to actually create the policy, you will get an error and the policy will not be created.
The following activities require that all tickets be in a terminal state, that is, approved or discarded: backup/restore.
Deleting a device from the inventory requires that all tickets involving that device be approved or discarded.
Some system processes prevent you from enabling or disabling change management. Wait until the following processes complete before you enable or disable change management:
-
critical management center processes, including SRU updates, LSP updates, VDB updates, and management center upgrades
-
pending or running background activities, including device registration; cluster auto-registration; Firewall Threat Defense high availability operations; high availability auto-registration; FlexConfig migration; cluster creation, break, edit, reconcile, or node changes; device-template creation or application; device-model migration; and EPM join or breakout
-
system jobs, including backup or restore, device import or export, general import, and domain movement.
Your ability to create objects while configuring a feature is constrained based on whether the feature and objects are all supported by change management. For example, importing a configuration is not supported by change management. Therefore, you cannot create security zone objects, which are supported, during the import. On the other hand, you can create new objects while configuring access control rules, because both are supported.
When you create an object from Security Cloud Control, the system automatically creates a ticket internally and allows the object to be associated with the Cloud-Delivered Firewall Management Center. You do not have to create or have an open ticket to do this. However, when you want to create an object from the Cloud-Delivered Firewall Management Center, you need an existing ticket or create one. The object is synchronized to Security Cloud Control only after the ticket is approved.
When using Cloud-Delivered Firewall Management Center, a user defined in Security Cloud Control is available to be assigned tickets only after the user cross-launches cdFMC at least once. Until the first cross-launch, the user does not exist in cdFMC.