{"type":"api","title":"(cdFMC-managed FTDs only) Deploy changes to multiple FTD devices","meta":{"id":"/apps/pubhub/media/cdo-api-documentation/241e37f202cf9838405f7ca5ed9f7d31d807d7bd/9b0e4c9a-48cb-3530-a00a-1f32fbf2438c","info":{"title":"Cisco Security Cloud Control Firewall Manager API","version":"1.22.0","description":"Use the documentation to explore the endpoints Security Cloud Control Firewall Manager has to offer","contact":{"name":"Cisco Security Cloud Control TAC","email":"cdo.tac@cisco.com"}},"openapi":"3.0.1","servers":[{"url":"https://api.us.security.cisco.com/firewall","description":"US"},{"url":"https://api.eu.security.cisco.com/firewall","description":"EU"},{"url":"https://api.apj.security.cisco.com/firewall","description":"APJ"},{"url":"https://api.au.security.cisco.com/firewall","description":"AUS"},{"url":"https://api.in.security.cisco.com/firewall","description":"IN"},{"url":"https://api.uae.security.cisco.com/firewall","description":"UAE"},{"url":"https://api.int.security.cisco.com/firewall","description":"Staging"},{"url":"https://scale.manage.security.cisco.com/api/rest","description":"Scale"},{"url":"https://ci.manage.security.cisco.com/api/rest","description":"CI"},{"url":"https://devfed.cdo.cisco.com/api/rest","description":"Devfed"},{"url":"https://manage.dev.secure.cisco/api/rest","description":"Devf9"},{"url":"https://manage.stg.secure.cisco/api/rest","description":"Stgf9"},{"url":"https://manage.secure.cisco/api/rest","description":"ProdF9"},{"url":"https://manage.securitydod.cisco/api/rest","description":"IL5"}],"securitySchemes":{"bearerAuth":{"bearerFormat":"JWT","scheme":"bearer","type":"http"}}},"spec":{"description":"This is an asynchronous operation to deploy changes made to the configurations of multiple cdFMC-managed FTD devices on Security Cloud Control. This operation returns a link to a transaction object that can be used to monitor the progress of the operation.\n\nNotes:\n\n- This operation is only supported for cdFMC-managed FTD devices.\n\n- This operation will only deploy changes to the device if there are pending changes to deploy.\n\n\n","operationId":"deployChangesToMultipleFtdDevices","requestBody":{"content":{"application/json":{"schema":{"properties":{"deploymentNotes":{"description":"Specify notes, if any, for the deployment.","example":"This deployment addresses ticket #12345.","type":"string"},"description":{"description":"Specify a human-readable description for the deployment.","example":"This deployment is for the branch office in San Francisco.","type":"string"},"deviceUids":{"deprecated":true,"description":"Deprecated. Use `devices` instead. The set of unique identifiers, represented as UUIDs, of the devices to deploy in Security Cloud Control.","example":["256461f6-bd60-11ef-8beb-6cf1610cf55d"],"items":{"deprecated":true,"description":"Deprecated. Use `devices` instead. The set of unique identifiers, represented as UUIDs, of the devices to deploy in Security Cloud Control.","format":"uuid","type":"string"},"maxItems":50,"minItems":1,"type":"array","uniqueItems":true},"devices":{"description":"Per-device deployment configuration. Cannot be combined with the deprecated `deviceUids` field. Each entry identifies a device and optionally selects which policy types to deploy. Set `selectedPolicyTypes` to null or include FULL_DEPLOY to perform a full deployment for that device. Each entry must have a unique uid.","items":{"description":"Per-device deployment configuration. Cannot be combined with the deprecated `deviceUids` field. Each entry identifies a device and optionally selects which policy types to deploy. Set `selectedPolicyTypes` to null or include FULL_DEPLOY to perform a full deployment for that device. Each entry must have a unique uid.","properties":{"selectedPolicyTypes":{"description":"(Optional) The policy types to deploy to this device. Use this to only deploy selected policies to the device, while skipping deployment of other parts of the device's configuration on SCC Firewall Management. Use individual policy types or group shortcuts (ACCESS_GROUP, UZTNA_GROUP). Set to null, or include FULL_DEPLOY, to perform a full deployment for this device.","example":["ACCESS_CONTROL_POLICY","SSL_POLICY"],"items":{"description":"(Optional) The policy types to deploy to this device. Use this to only deploy selected policies to the device, while skipping deployment of other parts of the device's configuration on SCC Firewall Management. Use individual policy types or group shortcuts (ACCESS_GROUP, UZTNA_GROUP). Set to null, or include FULL_DEPLOY, to perform a full deployment for this device.","enum":["ACCESS_CONTROL_POLICY","PREFILTER_POLICY","QOS_POLICY","ZTNA_POLICY","UNIVERSAL_ZERO_TRUST_POLICY","HYBRID_ZERO_TRUST_POLICY","FILE_POLICY","INTRUSION_POLICY","SSL_POLICY","IDENTITY_POLICY","NETWORK_ANALYSIS_POLICY","SNORT3_NETWORK_ANALYSIS_POLICY","DNS_POLICY","NETWORK_DISCOVERY","SNORT3_INTRUSION_POLICY","ACCESS_GROUP","UZTNA_GROUP","FULL_DEPLOY"],"example":"[\"ACCESS_CONTROL_POLICY\",\"SSL_POLICY\"]","type":"string"},"maxItems":2147483647,"minItems":1,"type":"array"},"uid":{"description":"The unique identifier, represented as a UUID, of the device to deploy to.","example":"256461f6-bd60-11ef-8beb-6cf1610cf55d","format":"uuid","type":"string"}},"required":["uid"],"type":"object","$$ref":"#/components/schemas/FtdSingleDeviceDeploymentInput"},"maxItems":50,"minItems":1,"type":"array"},"effectiveDeviceUids":{"items":{"format":"uuid","type":"string"},"type":"array","uniqueItems":true},"ignoreWarnings":{"default":false,"description":"Specify whether to ignore warnings generated during the pre-validation of the deployment job and proceed with the deployment regardless. **Warning**: Do not set this to `true` unless you know what you are doing.","type":"boolean"}},"type":"object","$$ref":"#/components/schemas/FtdMultiDeviceDeploymentInput"}}},"required":true},"responses":{"202":{"content":{"application/json":{"schema":{"properties":{"cancellable":{"type":"boolean"},"cdoTransactionStatus":{"description":"Status of the transaction.","enum":["PENDING","IN_PROGRESS","CANCELLED","DONE","ERROR"],"example":"IN_PROGRESS","type":"string"},"entityUid":{"description":"Unique identifier of the entity that the transaction is triggered on. This can be empty, for a transaction that is not tied to an entity, such as transactions which refresh RA VPN sessions.","example":"f5f660d4-4b81-4374-877d-fbc4bee894e2","format":"uuid","type":"string"},"entityUrl":{"description":"URL to access the entity that the transaction is triggered on. This can be empty, for a transaction that is not tied to an entity, such as transactions which refresh RA VPN sessions.","example":"https://edge.us.cdo.cisco.com/platform/public-api/v1/inventory/devices/f5f660d4-4b81-4374-877d-fbc4bee894e2","type":"string"},"errorDetails":{"additionalProperties":{"description":"Transaction error details, if any.","type":"string"},"description":"Transaction error details, if any.","type":"object"},"errorMessage":{"description":"Transaction error message, if any.","type":"string"},"lastUpdatedTime":{"description":"Time (UTC; represented using the RFC-3339 standard) at which the transaction status was last updated.","example":"2023-12-13T08:15:44Z","format":"date-time","type":"string"},"submissionTime":{"description":"Time (UTC; represented using the RFC-3339 standard) at which the transaction was triggered.","example":"2023-12-13T05:15:44Z","format":"date-time","type":"string"},"tenantUid":{"description":"Unique identifier of the tenant that the transaction was triggered on.","example":"5131daad-e813-4b8f-8f42-be1e241e2cdb","format":"uuid","type":"string"},"transactionDetails":{"additionalProperties":{"description":"Transaction details, if any.","type":"string"},"description":"Transaction details, if any.","type":"object"},"transactionPollingUrl":{"description":"Polling URL to track the progress of the transaction.","example":"https://edge.us.cdo.cisco.com/platform/v1/transactions/7131daad-e813-4b8f-8f42-be1e241e8cdb","type":"string"},"transactionType":{"description":"Type of the transaction.","enum":["ONBOARD_ASA","ONBOARD_IOS","ONBOARD_DUO_ADMIN_PANEL","CREATE_FTD","ONBOARD_FTD_ZTP","REGISTER_FTD","DELETE_CDFMC_MANAGED_FTD","RECONNECT_ASA","READ_ASA","BULK_READ_ASA","EXECUTE_CLI_COMMAND","BULK_ACCEPT_ASA_CERTIFICATES","DEPLOY_ASA_DEVICE_CHANGES","DEPLOY_FTD_DEVICE_CHANGES","INDEX_TENANT","TERMINATE_DEVICE_RA_VPN_SESSIONS","REFRESH_RA_VPN_SESSIONS","TERMINATE_USER_RA_VPN_SESSIONS","UPGRADE_ASA","UPGRADE_FTD","UPGRADE_FTD_CACHE","UPGRADE_SECURE_CLIENT_PACKAGES","MSP_UPGRADE_ASAS","MSP_UPGRADE_FTDS","MSP_UPGRADE_SECURE_CLIENT_PACKAGES","MSP_GET_COMPATIBLE_FTD_UPGRADE_PACKAGES","MSP_GET_COMPATIBLE_SECURE_CLIENT_UPGRADE_PACKAGES","CREATE_SDC","SEND_AI_ASSISTANT_MESSAGE","MSP_CREATE_TENANT","MSP_REVOKE_TENANT_MSP_PORTAL_RELATIONSHIP","MSP_ADD_USERS_TO_TENANT","MSP_ADD_USER_GROUPS_TO_TENANT","MSP_DELETE_USERS_FROM_TENANT","MSP_DELETE_USER_GROUPS_FROM_TENANT","MSP_ADD_EXISTING_TENANT","MSP_ENABLE_MULTICLOUD_DEFENSE","MSP_PROVISION_CDFMC","MSP_UPDATE_TENANT_SETTINGS","CREATE_USERS","DELETE_USERS","EXECUTE_ASA_COMMAND","ANALYZE_POLICIES","TRIGGER_FMC_DATA_EXPORT","STAGE_POLICIES","SYNC_ACCESS_POLICIES","SYNC_POLICIES","EXPORT_DEVICES","EXPORT_CLOUD_SERVICES","EXPORT_MANAGERS","EXPORT_TEMPLATES","EXPORT_DEVICE_LICENSES","EXPORT_TENANT_LICENSES","EXPORT_TENANTS","PROVISION_SDWAN_SAL_RESOURCES","DEPROVISION_SDWAN_SAL_RESOURCES","PROVISION_FIREWALL_SAL_RESOURCES","DEPROVISION_FIREWALL_SAL_RESOURCES","RENEW_SAL_LICENSE","PAID_SAL_LICENSE","EXPIRE_SAL_LICENSE","REMOVE_SSX_SAL_SUBSCRIPTION","ASA_HEALTH_METRICS_TENANT_PROVISIONING","UPDATE_DEVICE_BULK","AGENTIC_JOB","IMPORT_FMC_OBJECTS","NAT_PAO_TRIGGER_PDF_GENERATION","NAT_PAO_APPLY_REMEDIATION","BIDIRECTIONAL_OBJECT_RECONCILIATION","CALCULATE_FTD_PENDING_CHANGES","CALCULATE_ASA_CONFIG_COMMANDS"],"example":"ONBOARD_ASA","type":"string"},"transactionUid":{"description":"Unique identifier of the transaction triggered.","example":"7131daad-e813-4b8f-8f42-be1e241e8cdb","format":"uuid","type":"string"}},"type":"object","$$ref":"#/components/schemas/CdoTransaction"}}},"description":"Security Cloud Control Transaction object that can be used to track the progress of the creation operation."},"400":{"content":{"application/json":{"schema":{"properties":{"details":{"additionalProperties":{"description":"Additional details, if any, about the error.","example":{},"type":"object"},"description":"Additional details, if any, about the error.","example":{},"type":"object"},"errorCode":{"description":"Unique code that describes the error.","enum":["INVALID_INPUT","UNAUTHORIZED","FORBIDDEN","NOT_FOUND","METHOD_NOT_ALLOWED","CONFLICT","TOO_MANY_REQUESTS","SERVER_ERROR","PROXY_ERROR","BAD_REQUEST","UNPROCESSABLE_ENTITY"],"example":"INVALID_INPUT","type":"string"},"errorMsg":{"description":"Human-readable error description in English.","example":"sample error","type":"string"}},"type":"object","$$ref":"#/components/schemas/CommonApiError"}}},"description":"Invalid input provided. Check the response for details.","$$ref":"#/components/responses/http400BadRequest"},"401":{"content":{"application/json":{"schema":{"properties":{"error":{"description":"A human-readable error description in English.","example":"invalid_token","type":"string"},"errorDescription":{"description":"A human-readable error description in English.","example":"Your token is invalid","type":"string"}},"type":"object","$$ref":"#/components/schemas/AuthenticationError"}}},"description":"Request not authorized.","$$ref":"#/components/responses/http401Unauthorised"},"403":{"content":{"application/json":{"schema":{"properties":{"details":{"additionalProperties":{"description":"Additional details, if any, about the error.","example":{},"type":"object"},"description":"Additional details, if any, about the error.","example":{},"type":"object"},"errorCode":{"description":"Unique code that describes the error.","enum":["INVALID_INPUT","UNAUTHORIZED","FORBIDDEN","NOT_FOUND","METHOD_NOT_ALLOWED","CONFLICT","TOO_MANY_REQUESTS","SERVER_ERROR","PROXY_ERROR","BAD_REQUEST","UNPROCESSABLE_ENTITY"],"example":"INVALID_INPUT","type":"string"},"errorMsg":{"description":"Human-readable error description in English.","example":"sample error","type":"string"}},"type":"object","$$ref":"#/components/schemas/CommonApiError"}}},"description":"User does not have sufficient privileges to perform this operation.","$$ref":"#/components/responses/http403Forbidden"},"500":{"content":{"application/json":{"schema":{"properties":{"details":{"additionalProperties":{"description":"Additional details, if any, about the error.","example":{},"type":"object"},"description":"Additional details, if any, about the error.","example":{},"type":"object"},"errorCode":{"description":"Unique code that describes the error.","enum":["INVALID_INPUT","UNAUTHORIZED","FORBIDDEN","NOT_FOUND","METHOD_NOT_ALLOWED","CONFLICT","TOO_MANY_REQUESTS","SERVER_ERROR","PROXY_ERROR","BAD_REQUEST","UNPROCESSABLE_ENTITY"],"example":"INVALID_INPUT","type":"string"},"errorMsg":{"description":"Human-readable error description in English.","example":"sample error","type":"string"}},"type":"object","$$ref":"#/components/schemas/CommonApiError"}}},"description":"Internal server error."}},"security":[{"bearerAuth":[]}],"summary":"(cdFMC-managed FTDs only) Deploy changes to multiple FTD devices","tags":["Device Deployments"],"__originalOperationId":"deployChangesToMultipleFtdDevices","method":"post","path":"/v1/inventory/devices/ftds/deploy"}}