Configure a Template for Firewall Threat Defense Devices Managed Using the Data Interface

This task configures a template for Firewall Threat Defense devices that are managed using a data interface, ensuring proper connectivity parameters match between the device and template to maintain Cloud-Delivered Firewall Management Center connectivity after template deployment.

To configure a template for a Firewall Threat Defense device that is managed using a data interface for Cloud-Delivered Firewall Management Center connectivity, ensure that the connectivity parameters of the device match the template. This ensures that the Threat Defense device does not lose connectivity with the Cloud-Delivered Firewall Management Center after application of the template. A template that you configure for Firewall Threat Defense devices managed using the data interface cannot be applied on devices that are not managed by the data interface.

These are the connectivity parameters:

  • Data interface used to the manage the Firewall Threat Defense device. For example, Ethernet1/1.

  • Name of the interface. For example, outside.

  • IP address configured on the data interface. For example, DHCP or static IP.

  • Route configured for the data interface. This can be a default or specific route defined on the data interface used for connectivity between the Firewall Threat Defense device and the Cloud-Delivered Firewall Management Center.

  • DDNS hostname configuration on the data interface.

If the template connectivity parameters do not match those on the device, validation fails and the template is not applied on the device. Validation does not require an exact match for some parameters, such as IP address or DDNS hostname. However, configure these parameters appropriately to maintain connectivity between the Firewall Threat Defense device and the Cloud-Delivered Firewall Management Center after deployment.

These template validation checks are done to ensure sanity of configurations that are required to manage the Firewall Threat Defense device using the data interface:

  • You cannot apply a template in which manager access to the device is configured with the management interface to a device in which manager access to the device is configured with the data interface.

  • You cannot apply a template in which manager access to the device is configured with the data interface to a device in which manager access to the device is configured with the management interface.

  • You cannot apply a template in which manager access to the device is configured with the single WAN data interface to a device in which manager access to the device is configured with the dual WAN data interface.

  • If any of the connectivity parameters do not match, you cannot apply a template in which manager access to the device is configured with the data interface to a device in which manager access to the device is configured with the data interface.

Before you begin

Follow these steps to configure a template for Firewall Threat Defense devices managed using the data interface:

Procedure


Step 1

Choose Devices > Template Management.

Step 2

Click the Edit (edit icon) icon of the template that you want to configure to manage Firewall Threat Defense devices using the data interface.

Step 3

Click the Template Settings tab.

  1. In the General tile, toggle the Manage device by Data Interface button.

  2. You will see a popup asking you to pick a data interface for manager access. Click OK.

Step 4

Click the Interfaces tab.

  1. Click the Edit icon of the data interface that you want to use for manager access. The first data interface – Ethernet1/1 (outside interface), is the data interface that is most commonly used for manager access.

  2. In the Edit Physical Interface window, click the Manager Access tab.

  3. Check the Enable management access checkbox.

  4. Click OK. You will see that the interface that you selected for manager access has been marked with Manager Access.

Step 5

Click the DHCP tab.

Step 6

Click the DDNS Update Methods tab.

  1. Click +Add to add a DDNS update method.

  2. In the Add DDNS Update Method window, enter a Method Name and choose FMC only.

  3. Set the Update Interval as per your requirement.

  4. Click OK. You will see the method that you created in the DDNS Update Methods table.

Step 7

Click the DDNS Interface Settings tab.

  1. Click +Add to add dynamic DNS configuration.

  2. In the Add Dynamic DNS configuration window, choose values for these fields:

    • Interface – Choose the interface enabled for manager access

    • Method Name – Choose the method that you created.

    • Host Name – Choose a variable for the hostname.

    Do not edit the rest of the fields in this window.

  3. Click OK. The DDNS Interface Settings table is populated with the entry that you created.

Step 8

To configure the model mapping to ensure that the data interface set for manager access in the template matches the data interface selected for manager access on the device, click the Template Settings tab and click Model Mapping.

  1. Click Add Model Mapping.

  2. Choose the Device Model from the drop-down list.

  3. Map the date interface that is set for manager access in the template to the appropriate data interface on the device by choosing the interface from the Model Interface drop-down list.

  4. Click Save. The interface mappings are listed along with the device model and mapping status on the Model Mapping window. You can now apply the template on a device that is managed using the data interface.