cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1689
Views
15
Helpful
10
Replies

Export Firepower policies to another Firepower

mikemanz83
Level 1
Level 1

Greetings my friends,

 

I have 3 Cisco firepowers

Model : Cisco Firepower 1150 Threat Defense

Software: 7.1.0-90
 
In one of them i configured nearly 50 policies and i want to replicate the same policies and objects to the other two, is there an easy way to do that??
M.M.
2 Accepted Solutions

Accepted Solutions

@mikemanz83 CDO is Cisco Defense Orchestrator - it the cloud management tool, it can manage multiple FTD's.

 

Get a trial (see link below) then onboard the devices, you can then share the configuration and deploy the same settings to multiple devices..

 

https://www.cisco.com/c/en_uk/products/security/defense-orchestrator/index.html

 

View solution in original post

@Rob Ingram is on track here. I would take it a step further and recommend if you want to keep the policies and objects in sync going forward that CDO (Cisco Defense Orchestrator - the cloud-based firewall management platform from Cisco) would be the way to go.

You can buy three device licenses relatively inexpensively for these small firewalls. The list price for one is US$750 per year (part number L-FPR1150-P= with subscription SKU L-FPR1150-P-1Y). Once they are CDO managed you can do just about everything from the cloud-based web interface - manage all policies, object, upgrades etc. from one place.

View solution in original post

10 Replies 10

@mikemanz83 I assume these FTD's are managed locally using FDM and not FMC? If using FMC it's easy as the objects are shared, but less so with FDM management. A couple of options:

 

Get a eval of CDO, onboard the FTD's and import the configuration policies, objects etc from the working FTD and deploy the required objects and policies to the other FTDs.

Alternatively I had a customer backup a working FTD and restore the configuration on another FTD.

Or write a python script to export the objects and polices and then re-import.

 

I think the CDO option is probably the easiest option.

Hi Rob, thanks for your answer!

 

Im new with the firepowers world, so, yes, im managing the firepower locally with FDM, could you explain to me what is CDO? 

 

Thanks for your patience 

M.M.

@mikemanz83 CDO is Cisco Defense Orchestrator - it the cloud management tool, it can manage multiple FTD's.

 

Get a trial (see link below) then onboard the devices, you can then share the configuration and deploy the same settings to multiple devices..

 

https://www.cisco.com/c/en_uk/products/security/defense-orchestrator/index.html

 

Ok, and without this CDO, what option i got left?

M.M.

@mikemanz83 the options are listed above....though not ideal.

Without CDO your only other option to automate this would be to script it.  Depending on how savvy you are with programming this might be an easy or hard task.  I personally find it interesting and challenging creating such scripts.

--
Please remember to select a correct answer and rate helpful posts


@Rob Ingram написал:

@mikemanz83CDO — это Cisco Defense Orchestrator — это инструмент управления облаком, он может управлять несколькими FTD.

 

Получите пробную версию (см. ниже), затем подключите устройство, затем выберите большую плотность и разверните несколько отдельных участков и тех же на некоторых участках.

 

https://ziare.com/afaceri/stiri-afaceri/masuri-anticriza-modul-in-care-imm-urile-sunt-mentinute-pe-linia-de-plutire-in-finlanda-1669649

 


Thank you! And for how long is the trial version given?

30 Days

M.M.

@Rob Ingram is on track here. I would take it a step further and recommend if you want to keep the policies and objects in sync going forward that CDO (Cisco Defense Orchestrator - the cloud-based firewall management platform from Cisco) would be the way to go.

You can buy three device licenses relatively inexpensively for these small firewalls. The list price for one is US$750 per year (part number L-FPR1150-P= with subscription SKU L-FPR1150-P-1Y). Once they are CDO managed you can do just about everything from the cloud-based web interface - manage all policies, object, upgrades etc. from one place.

mikemanz83
Level 1
Level 1

Wow! i didnt know that. Im going to present this idea to my suprevisor, is an amazing tool.

 

In the meantime, im going to try to backup and download the config of the device im working up and upload it to the other two.

 

Thanks both @Rob Ingram @Marvin Rhoads 

M.M.
Review Cisco Networking products for a $25 gift card