Configure a Template for Firewall Threat Defense Devices Managed Using the Data Interface
This task configures a template for Firewall Threat Defense devices that are managed using a data interface, ensuring proper connectivity parameters match between the device and template to maintain Cloud-Delivered Firewall Management Center connectivity after template deployment.
To configure a template for a Firewall Threat Defense device that is managed using a data interface for Cloud-Delivered Firewall Management Center connectivity, ensure that the connectivity parameters of the device match the template. This ensures that the Threat Defense device does not lose connectivity with the Cloud-Delivered Firewall Management Center after application of the template. A template that you configure for Firewall Threat Defense devices managed using the data interface cannot be applied on devices that are not managed by the data interface.
These are the connectivity parameters:
-
Data interface used to the manage the Firewall Threat Defense device. For example, Ethernet1/1.
-
Name of the interface. For example, outside.
-
IP address configured on the data interface. For example, DHCP or static IP.
-
Route configured for the data interface. This can be a default or specific route defined on the data interface used for connectivity between the Firewall Threat Defense device and the Cloud-Delivered Firewall Management Center.
-
DDNS hostname configuration on the data interface.
If the template connectivity parameters do not match those on the device, validation fails and the template is not applied on the device. Validation does not require an exact match for some parameters, such as IP address or DDNS hostname. However, configure these parameters appropriately to maintain connectivity between the Firewall Threat Defense device and the Cloud-Delivered Firewall Management Center after deployment.
These template validation checks are done to ensure sanity of configurations that are required to manage the Firewall Threat Defense device using the data interface:
-
You cannot apply a template in which manager access to the device is configured with the management interface to a device in which manager access to the device is configured with the data interface.
-
You cannot apply a template in which manager access to the device is configured with the data interface to a device in which manager access to the device is configured with the management interface.
-
You cannot apply a template in which manager access to the device is configured with the single WAN data interface to a device in which manager access to the device is configured with the dual WAN data interface.
-
If any of the connectivity parameters do not match, you cannot apply a template in which manager access to the device is configured with the data interface to a device in which manager access to the device is configured with the data interface.
Before you begin
Follow these steps to configure a template for Firewall Threat Defense devices managed using the data interface:
Procedure
Step 1 | Choose . |
Step 2 | Click the Edit ( |
Step 3 | Click the Template Settings tab.
|
Step 4 | Click the Interfaces tab.
|
Step 5 | Click the DHCP tab. |
Step 6 | Click the DDNS Update Methods tab.
|
Step 7 | Click the DDNS Interface Settings tab. |
Step 8 | To configure the model mapping to ensure that the data interface set for manager access in the template matches the data interface selected for manager access on the device, click the Template Settings tab and click Model Mapping.
|