Skip to main content
Connect your Cisco Firepower (Firepower Threat Defense) firewall so Myrmex can read its configuration, audit its hardening, help you clean up policies, and — with approval — apply changes. Myrmex reaches the device over SSH through a Collector on your network, on demand — nothing is stored on the Myrmex side.

What Myrmex Can Do

Read & troubleshoot

Inspect system status, interfaces, routing, connections, access control policy, NAT, and VPNs — read-only diagnostics, pulled live.

Hardening audit

Run a Security Posture audit against the device’s hardening controls.

Policy hygiene

Find shadowed, unused, or overly-permissive access control rules and propose cleanups.

Backup & diff

Back up the configuration on demand and compare revisions over time; with approval, apply rule and VPN changes.

Before You Start

  • A Collector deployed on a network that can reach the device’s management IP over SSH. See Deploying the agent.
  • SSH management access enabled on the Firepower device.
  • An administrator account Myrmex can use to log in (a read-only user is enough for analysis; a config-level user is required to apply changes).

Step 1 — Create the Access Account on Cisco Firepower

1

Enable SSH management access

Allow SSH on the management interface and permit the Collector’s network. On FDM-managed devices use Device → System Settings → Management Access / SSH Access; on FMC-managed devices use Devices → Platform Settings → SSH Access.
2

Choose the privilege level (optional, recommended)

Decide what Myrmex should do — a read-only user for analysis, or a user with Config privilege to allow changes.
3

Create the local user

Add a local user with a strong password and CLI access at the privilege level above (or configure external authentication). Note the username and password — you’ll enter them in Myrmex.
Prefer least privilege: start with a read-only account, and only grant config privilege once you want the agents to apply changes for you.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Cisco Firepower, then fill in:

Connect

Click Connect to validate the SSH connection and finish. The device then appears under Environment → Integrations, and you can start asking the AI about it in the Workspace.
This integration is operated by the Integration Specialist agent, which runs the Firepower CLI on your behalf. Browse more connectors in the Integrations directory.