
FTD Managers
Table 1: FTD Managers
DescriptionManager
FDM is a web-based, simplified, on-device manager. Because it is simplified, some
FTD features are not supported using FDM. You should use FDM if you are only
managing a small number of devices and don't need a multi-device manager.
Both FDM and CDO can discover the configuration on the device, so you
can use FDM and CDO to manage the same device. FMC is not compatible
with other managers.
Note
To get started with FDM, see Firepower Threat Defense Deployment with FDM, on
page 61.
Firepower Device Manager (FDM)
CDO is a simplified, cloud-based multi-device manager. Because it is simplified, some
FTD features are not supported using CDO. You should use CDO if you want a
multi-device manager that offers a simplified management experience (similar to FDM).
And because CDO is cloud-based, there is no overhead of running CDO on your own
servers. CDO also manages other security devices, such as ASAs, so you can use a
single manager for all of your security devices.
In 6.7 and later, CDO offers Low Touch Provisioning that lets branch offices plug in
their hardware and leave it alone: the device will automtically register with CDO.
Both FDM and CDO can discover the configuration on the device, so you
can use FDM and CDO to manage the same device. FMC is not compatible
with other managers.
Note
To get started with CDO provisioning, see Firepower Threat Defense Deployment with
CDO Provisioning, on page 25.
Cisco Defense Orchestrator (CDO)
FMC is a powerful, web-based, multi-device manager that runs on its own server
hardware, or as a virtual device on a hypervisor. You should use FMC if you want a
multi-device manager, and you require all features on the FTD. FMC also provides
powerful analysis and monitoring of traffic and events.
FMC is not compatible with other managers because the FMC owns the FTD
configuration, and you are not allowed to configure the FTD directly,
bypassing the FMC.
Note
To get started with FMC, see Firepower Threat Defense Deployment with FMC, on
page 89.
For a remote branch setup, we recommend that you use the standalone document specific
to that deployment.
Firepower Management Center (FMC)
The FTD REST API lets you automate direct configuration of the FTD. This API is
compatible with FDM and CDO use because they can both discover the configuration
on the device. You cannot use this API if you are managing the FTD using FMC.
The FTD REST API is not covered in this guide. For more information, see the FTD
REST API guide.
FTD REST API
Cisco Firepower 1010 Getting Started Guide
2
Which Operating System and Manager is Right for You?
FTD Managers