Cisco Firepower Threat Defense Initial Setup Guide - 夜莺博客

Cisco Firepower Threat Defense Initial Setup Guide

Cisco Secure Firewall Threat Defense (FTD, still widely called Firepower Threat Defense) is provisioned differently from a classic ASA: the device has a management-plane CLI, a Linux-based platform layer on the larger appliances, and a policy engine that only becomes useful once an access control policy is applied. Most first-deployment delays come from getting the management interface and manager choice wrong, not from rule design. This walkthrough covers the console CLI setup script, the interface decision between FDM and FMC management, and the first access control policy that makes the firewall pass traffic deliberately.

Before you start

  • Console access to the device (the FTD console, or connect ftd from the FXOS console on 4100/9300 appliances).
  • Data interfaces cabled as inside and outside — one is often enough at first.
  • A decision: manage this device with on-box Firewall Device Manager (FDM) or with a central Firepower Management Center (FMC/FMC).

Step 1: run the CLI setup script

On first login you must accept the EULA and change the admin password. The setup assistant then collects the management address, gateway, DNS and the manager

> show network
> configure network ipv4 manual 10.10.10.20 255.255.255.0 10.10.10.1
> configure network dns servers 10.10.10.53
> configure network dns searchdomains corp.example.net
> show managers
> configure manager add 10.10.10.60 <registration_key>

Omit configure manager add if you intend to use FDM locally. If you register to FMC, note the registration key; the same key is entered in FMC under Devices > Device Management > Add Device.

Step 2: verify management reachability

firepower# show network
firepower# show managers
firepower# show dns
firepower# ping system 10.10.10.60
firepower# show interface ip brief

From FTD/FMC 7.4 onward the management and diagnostic interfaces are merged into a single converged management interface (CMI) on some models, so the management address may live on Management0/0 rather than a dedicated diagnostic port. Check show interface ip brief before assuming the port layout from an older diagram.

Step 3: choose and configure the manager

Manager Best for Notes
Firewall Device Manager (on-box) Single device, small branch Interface config created in FDM is retained when you later move to FMC, but the access control policy and zones are not
Firepower Management Center Multiple devices, shared policy HTTPS to the device is only used for viewing packet captures in this mode

Moving from FDM to FMC later is supported, but assume you will rebuild policy rather than inherit it.

Step 4: register the device and confirm health

firepower# show managers
firepower# show sftunnel status
firepower# show managers stats

Successful registration shows Registration: Completed. If the sftunnel stays in connecting, the usual causes are a stale registration key, NAT between device and FMC, or the management interface being reachable only one way — FMC must initiate the channel back to the device.

Step 5: build a deliberate first access control policy

The default policy trusts inside-to-outside without inspection, which is a poor baseline. Replace it with an explicit policy:

Objects > Object Management   -> create network objects for INSIDE_NET and any servers
Policies > Access Control     -> create policy "Edge-ACP"
  Rule 1  INSIDE_NET -> outside  (application: any, ports 80/443)  Action: Allow with Intrusion Prevention
  Rule 2  INSIDE_NET -> outside  Action: Allow (logging at end of connection)
  Rule 3  any -> any            Action: Block with reset  (default deny, logged)

Deploy the policy and watch the deployment status; a failed deploy returns to the last good policy automatically and prints the reason under Deploy > Deployment History.

Step 6: enable remote management safely

Devices > Platform Settings > Secure Shell   -> allow SSH from 10.10.10.0/24 only
Devices > Platform Settings > HTTP          -> allow HTTPS from the management subnet
> configure ssh-access-list 10.10.10.0/24
> configure ssh version 2

SSH is enabled on the management interface by default; platform settings control access to data and diagnostic interfaces. Never expose the management interface to the internet — use the data path for any access rules that must reach the device.

Related reading: Cisco ASA CLI basics and configuration, SPAN, RSPAN and ERSPAN mirroring transport, and Palo Alto PAN-OS security zones and basic security policy.

原文链接:https://docs.defenseorchestrator.com/t_complete_initial_FTD_config_CLI_for_CDO.html