CHAPTER 5
Threat Defense Deployment with CDO
Is This Chapter for You?
To see all available applications and managers, see Which Application and Manager is Right for You?, on
page 1. This chapter applies to the threat defense using Cisco Defense Orchestrator (CDO)'s cloud-delivered
Firewall Management Center.
CDO supports threat defense 7.2 and later.
Note
About the Firewall
The hardware can run either threat defense software or ASA software. Switching between threat defense and
ASA requires you to reimage the device. You should also reimage if you need a different software version
than is currently installed. See Cisco Secure Firewall ASA and Secure Firewall Threat Defense Reimage
Guide.
The firewall runs an underlying operating system called the Secure Firewall eXtensible Operating System
(FXOS). The firewall does not support the FXOS Secure Firewall chassis manager; only a limited CLI is
supported for troubleshooting purposes. See the Cisco FXOS Troubleshooting Guide for the Firepower
1000/2100 and Secure Firewall 3100/4200 with Firepower Threat Defense for more information.
Privacy Collection Statement—The firewall does not require or actively collect personally identifiable
information. However, you can use personally identifiable information in the configuration, for example for
usernames. In this case, an administrator might be able to see this information when working with the
configuration or when using SNMP.
• About Threat Defense Management by CDO, on page 126
• End-to-End Tasks: Low-Touch Provisioning, on page 127
• End-to-End Tasks: Onboarding Wizard, on page 129
• Central Administrator Pre-Configuration, on page 130
• Deploy the Firewall With Low-Touch Provisioning, on page 133
• Deploy the Firewall With the Onboarding Wizard, on page 139
• Configure a Basic Security Policy, on page 152
• Troubleshooting and Maintenance, on page 165
• What's Next, on page 172
Cisco Firepower 2100 Getting Started Guide
125