04-03-2024 10:41 AM - edited 04-03-2024 10:42 AM
I migrated number of FTDs from on-prem FMC to cdFMC last week. The migration tasks were successfuly but not commit yet.
Certain FTDs are configured with Site-to-Site VPN and/or RA VPN. I can view the status and configuration within cdFMC but the CDO dashboard page shows nothing for the site-to-site VPN nor the RA VPN...
Wondering if there is any configuration steps I need to do in order to populate VPN info in the dashboard of CDO?
Solved! Go to Solution.
04-04-2024 09:36 AM - edited 04-04-2024 09:36 AM
Whether an FTD device is onboarded new into CDO or migrated from local management only into CDO is the same result. Those devices have a few visibility benefits (like the dashboards you inquired about) that cdFMC does not yet offer.
I was making the distinction of that management type as opposed to managed by cdFMC which is itself within CDO but doesn't currently have 1-1 feature parity.
It is a bit confusing and not well-documented by Cisco. I have provided this feedback to the product team in the past yet it remains...
04-04-2024 08:54 AM
I'm not positive but I believe you may need to go into the cdFMC dashboard as opposed to the one in the top level CDO GUI.
https://docs.defenseorchestrator.com/cdfmc/index.html#!c_about_s2s_vpns_monitoring.html
04-04-2024 09:04 AM
Within the cdFMC, I can still monitor the VPN tunnels similiar to when it was in on-prem FMC. But what would be the purpose of the CDO dashboard VPN sections then?
04-04-2024 09:19 AM
Those dashboards currently populate when devices are managed "directly" with CDO and not via the integrated cdFMC.
i.e., FTDs with FMC + CDO (no FMC, cd or otherwise) and ASAs.
I would expect the cdFMC managed VPNs will eventually get rolled up into those top level dashboards, but it's still a work in progress.
04-04-2024 09:25 AM
Okey, by "directly managed by CDO", do you mean the device is added manually into CDO instead of migrated into CDO? Or you mean FTD added/migrated into CDO but not managed by FMC?
04-04-2024 09:36 AM - edited 04-04-2024 09:36 AM
Whether an FTD device is onboarded new into CDO or migrated from local management only into CDO is the same result. Those devices have a few visibility benefits (like the dashboards you inquired about) that cdFMC does not yet offer.
I was making the distinction of that management type as opposed to managed by cdFMC which is itself within CDO but doesn't currently have 1-1 feature parity.
It is a bit confusing and not well-documented by Cisco. I have provided this feedback to the product team in the past yet it remains...
04-04-2024 09:54 AM
Thanks for the info!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide