CHAPTER 3
Firepower Threat Defense Deployment with CDO
Is This Chapter for You?
This chapter explains how to onboard your Firepower Threat Defense (FTD) device to Cisco Defense
Orchestrator (CDO) using CDO's onboarding wizard. Before you onboard your FTD device to CDO, you
need to complete the initial system configuration using the local Firepower Device Manager (FDM), which
is hosted directly on the device.
CDO is a cloud-based multi-device manager that facilitates management of security policies in highly distributed
environments to achieve consistent policy implementation. CDO helps you optimize your security policies
by identifying inconsistencies with them and by giving you tools to fix them. CDO gives you ways to share
objects and policies, as well as make configuration templates, to promote policy consistency across devices.
This document assumes the Firepower 1010 hardware has a pre-installed FTD image on it. The Firepower
1010 hardware can run either FTD software or ASA software. Switching between FTD and ASA requires
you to reimage the device. See Reimage the Cisco ASA or Firepower Threat Defense Device.
Note
The Firepower 1010 runs an underlying operating system called the Firepower eXtensible Operating System
(FXOS). The Firepower 1010 does not support the FXOS Firepower Chassis Manager; only a limited CLI is
supported for troubleshooting purposes. See the FXOS troubleshooting guide for more information.
Privacy Collection Statement—The Firepower 1010 Series does not require or actively collect
personally-identifiable information. However, you can use personally-identifiable information in the
configuration, for example for usernames. In this case, an administrator might be able to see this information
when working with the configuration or when using SNMP.
• End-to-End Procedure, on page 24
• How Cisco Defense Orchestrator Works with Firepower Threat Defense, on page 26
• Review the Network Deployment and Default Configuration, on page 27
• Cable the Device, on page 32
• Power On the Device, on page 33
• (Optional) Change Management Network Settings at the CLI, on page 34
• Log Into FDM, on page 36
• Complete the Initial Configuration, on page 36
• Log Into CDO, on page 38
• Onboard the FTD to CDO, on page 42
• Configure Licensing, on page 49
Cisco Firepower 1010 Getting Started Guide
23