Onboard a Device with a Serial Number
Only the Firepower 1000, Firepower 2100, and Secure Firewall 3100 devices can be onboarded with the serial number onboarding method.
Before you begin
Be sure the following is completed prior to onboarding:
Cloud-delivered Firewall Management Center is enabled for your tenant.
Confirm the device's CLI configuration is successfully completed. See Complete the Initial Configuration of a Secure Firewall Threat Defense Device Using the CLI for more information.
Review the prerequesites and limitations before you onboard the device. See "Prerequesites to Onboard a Device to Cloud-delivered Firewall Management Center" in Managing Firewall Threat Defense with Cloud-Delivered Firewall Management Center in Cisco Defense Orchestrator for more information.
Deregister any existing smart licenses the device may have enabled prior to onboarding.
Confirm the device is configured for local management and is currently managed by Secure Firewall device manager.
The device is running version 7.2 and later. Version 7.0.3 does not support onbarding with serial numbers.
In the Secure Firewall device manager UI, navigate to and select the Auto-enroll with Tenancy from Cisco Defense Orchestrator option and click Register.
Log in to CDO.
In the navigation pane, click Inventory and click the blue plus button.
Click the FTD tile.
Under Management Mode, be sure FTD is selected. By selecting FTD under Management Mode, you will not be able to manage the device using the previous mangement platform. All existing policy configurations except for interface configurations will be reset. You must re-configure policies after you onboard the device.
Select Use Serial Number.
Enter the Device Serial Number and the Device Name. Click Next.
Password Reset. Select No, this device has been logged into and configured for a manager. This implies that the device has already been registered to a device manager and the default password was changed as part of that configuration.
If your device is brand new and has never been configured for a manager, see Onboard a Device with Low-Touch Provisioning.
In the Policy Assignment step, use the drop-down menu to select an access control policy to deploy once the device is onboarded. If you have no policies configured, select the Default Access Control Policy.
Select the subscription licenses you want to apply to the device. Click Next.
What to do next
If you did not already, create a custom access control policy to customize the security for your environment. See Access Control Overview in Managing Firewall Threat Defense with Cloud-Delivered Firewall Management Center in Cisco Defense Orchestrator for more information.
Enable Cisco Security Analytics and Logging (SAL) to view events in the CDO dashboard or register the device to an Secure Firewall Management Center for security analytics. See Cisco Security Analytics and Logging in Managing Firewall Threat Defense with Cloud-Delivered Firewall Management Center in Cisco Defense Orchestrator for more information.