About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Enhancing Firepower at the National Security Agency Norman St. Laurent on September 11, 2023 at 1:15 pm

Cyberattacks have become increasingly sophisticated as they target organizations of all sizes in both the public and private sectors. Governments and enterprises alike are constantly searching for… Read more on Cisco Blogs

Cyberattacks have become increasingly sophisticated as they target organizations of all sizes in both the public and private sectors. Governments and enterprises alike are constantly searching for effective strategies to safeguard their networks and sensitive data. And for the United States Federal Government, the National Security Agency (NSA) is refining its firepower to serve as a guiding light to all.

For the NSA’s cybersecurity team, preventing and eradicating threats to US national security systems also means focusing on the Defense Industrial Base and improving the security of weapon systems. Much of this work flows through their Cybersecurity Collaboration Center where it partners with allied nations, private industry, academics, and researchers to strengthen awareness and collaboration to advance the state of cybersecurity.

To enhance their process, the NSA has recently developed and released the Cisco Firepower Threat Defense (FTD) Hardening Guide, a comprehensive resource designed to fortify Cisco Firepower Threat Defense customers’ cyber defense capabilities (more here). And we’re glad to help share the news as we feel the hardening guide can be a great new resource for our existing Cisco FTD users.

Inside the National Security Agency’s FTD Hardening Guide

The NSA’s Firepower Threat Defense Hardening Guide is a collaborative effort, one that can provide security practitioners and Information Assurance (IA) groups with invaluable insights and best practices to secure their Cisco Firepower Threat Defense deployments. As a Cybersecurity Technical Report, the hardening guide is a testament to how collaboration between a variety of groups across both the public and private sectors can increase everyone’s success in securing infrastructure. This guide is a result of the collective efforts of cybersecurity experts, threat intelligence analysts, network architects, and security engineers combined with the NSA’s Cybersecurity Directorate Network Infrastructure Security group, working together for the greater good. As a result, our deterrence against growing cyber threats is increased and our strategic posture enhanced.

The primary goal of the National Security Agency’s FTD Hardening Guide is to augment the security posture of organizations utilizing Cisco FTD. It does so by outlining step-by-step procedures for configuring, managing, and optimizing their Firepower Threat Defense environments. By adhering to these guidelines, organizations can:

Bolster their resilience against cyber threats
Minimize vulnerabilities
And prevent potential breaches that may result in data loss or system compromise.

By implementing the suggestions of the hardening guide, your organization’s FTD systems will be configured in a secure and uniform manner, reducing the risk of misconfigurations or security gaps caused by inconsistent settings.

Benefits for Cisco Firepower users

Adhering to the National Security Agency Cybersecurity Firepower Threat Defense Hardening Guide also gives your organization several specific benefits, including:

Improved threat detection and prevention – leverage Cisco FTD to gain a deeper understanding of potential threats and vulnerabilities that may lurk in your networks. By implementing the recommended security measures, you can enhance your threat detection capabilities and proactively prevent cyberattacks. For our friends in the public sector, this helps reduce risk of data breaches and unauthorized access to critical information.  You can learn more here.

Reduced attack surface – Discover how to disable or remove unnecessary services, features, or protocols that are not required for your systems or organization’s operations or mission. Reducing your attack surface is critical to reducing opportunities for attackers to exploit any potential vulnerabilities.
Enhanced network resilience – Gain valuable insights into your network’s resilience to keep vital operations up and running. With Cisco FTD, you learn how to design resilient network architectures and deploy security mechanisms that can adapt to evolving threats, plus maintain continuity even during an attack.
Compliance with industry standards and frameworks – Support compliance mandates for industry regulations, frameworks, and data protection standards. Cisco FTD users can benefit by aligning their security practices with relevant industry standards, such as the Payment Card Industry Data Security Standard (PCI DSS), General Data Protection Regulation (GDPR), NIST 800-53, NIST Cybersecurity Framework, Zero Trust Mandates from the White House, Zero Trust Mandates from the Department of Defense, Center for Internet Security Critical Security Controls.
Strengthened user awareness – Expand beyond just the technical aspects to grow user awareness and enhance education. In my opinion this is the most important benefit from a hardening guide. Why? Because it encourages your organization to conduct cybersecurity training for your employees. And that training can be enhanced by using the hardening guide in the classroom. By leveraging the hardening guide in training sessions, your users develop a better understanding of any potential security risks, related engineering tasks, and their critical role in keeping your environment secure.

Enhancing Firepower by taking collaborative action

We consider the FTD hardening guide a collaborative effort that should be constantly evolving. That’s why feedback and constant revision is important as new versions of Cisco Firepower evolve and features are added and/or changed. The good news is that all Cisco Firepower Threat Defense customers benefit from this team effort. And by continuing the collaborative approach, and including you as well, we all benefit from a comprehensive and up-to-date resource that evolves with emerging threats and security trends.

We encourage you to be a continuing part of making the National Security Agency’s Cybersecurity Firepower Threat Defense Hardening Guide a long-term asset for all users by regularly submitting your feedback to:

Cybersecurity Report Feedback: CybersecurityReports@nsa.gov
General Cybersecurity Inquiries: Cybersecurity_Requests@nsa.gov
Defense Industrial Base Inquiries and Cybersecurity Services: DIB_Defense@cyber.nsa.gov

National Security Agency’s Hardening Guide helps us all

For Cisco Firepower Thread Defense customers seeking to enhance their cyber defense capabilities, the NSA’s FTD Hardening Guide is a valuable resource. By following the guide’s recommendations, along with other great material from Cisco (see below) your organization can strengthen threat detection and prevention mechanisms while streamlining incident response. Plus, standardize security configurations, raise overall security awareness and training, and bolster network resilience. Lastly, you can align compliance with industry standards and grow user awareness as well.

Remember, embracing this guide not only demonstrates your commitment to cybersecurity excellence but also signifies your belief in a proactive approach that safeguards critical data and assets. In the ever-evolving landscape of cyber threats, the National Security Agency’s Firepower Threat Defense Hardening Guide serves as a great resource and knowledge-sharing document, helping you stay one step ahead of malicious actors in the race to secure and resilient cybersecurity.

Learn More

More NSA Guidance
Cisco Secure Firewall
Cisco FTD Datasheets, Configuration Guides, Release Notes, Failover and Clustering and more
Cisco FTD Training Videos and Step-by-Step Guides and moreCisco FTD Hardening Guide

Share

  Did you know the NSA has just released the Cisco Firepower Threat Defense (FTD) Hardening Guide? Learn how it can help your agency strengthen its cyber defense.  Read More Cisco Blogs 

By |2023-09-11T23:52:00+00:00September 11, 2023|Cisco: Learning|0 Comments

The Journey to CCIE Certification, a Personal Story Matt Saunders on September 11, 2023 at 7:55 pm

This guest post was authored by Cisco Designated VIP Christian Kellerer. 

If you’re an aspiring CCIE, you know that achieving this prestigious certification requires hard work, discipline, and pe… Read more on Cisco Blogs

This guest post was authored by Cisco Designated VIP Christian Kellerer. 

If you’re an aspiring CCIE, you know that achieving this prestigious certification requires hard work, discipline, and persistence. My name is Chris Kellerer, and as a Cisco Learning Network VIP, I have successfully climbed the Cisco certification mountain from bottom to top. I hope that my story provides valuable insight and inspiration to help you reach your own CCIE certification goals.  

From apprentice to discovering Cisco certifications 

My networking journey began when I finished my apprenticeship in 2014, but I was still unsure of my long-term career path at that point. Then, in 2017, I found myself working alongside a CCIE-certified contractor on a complex networking project.  

He patiently taught me advanced networking technologies such as NX-OS, ASA, FirePOWER, ISE, and PRIME. After sharing his own CCIE Lab experience, it was the advice he gave next that started my certification journey.  

“If you really want to become certified, you need the passion for it and must do it step by step. Start at the bottom. First, get your CCNA, and then if you’re still interested, do the CCNP. Finally, if you really want to dig deep, get the CCIE.”  

That’s what started me down the path to certification. 

Tackling the first hurdles: CCNA and CCNP 

Using Cisco whitepapers and official E-learning courses, I began my CCNA Routing & Switching studies (now simply called the CCNA) in early 2018. I completed it in just six months. After passing the exams, I immediately dove right into the CCNP Routing & Switching (now CCNP Enterprise) certification, completing it by March 2019.  

I found TSHOOT to be the most enjoyable exam, and in retrospect, it felt like a teeny-tiny baby version of the CCIE lab exam. While passing the exams boosted my confidence, I was still uncertain about my career direction.  

Cisco Live and the redesigned CCIE Certification Program 

My journey was not without its roadblocks. Despite my early success with CCNA and CCNP, it was at this point that I found myself stuck and uncertain about my career path. Not only was the CCIE blueprint intimidating, but it also felt somewhat outdated from a technology point of view.  

I stopped studying for a few months. However, that all changed when Cisco Live 2019 brought the clarity and motivation I needed to continue. That year, Cisco announced the coming of a redesigned certification program, including the successor to the CCIE Routing & Switching: The newly named CCIE Enterprise Infrastructure (CCIE EI) track.  

The updated blueprint included traditional networking while also introducing modern topics like SDx and programming/automation. That’s the moment I became determined to take the next step and earn my CCIE.  

The CCIE lab exam: First, second, and third attempts 

My first attempt at the CCIE Lab in October 2020 was a nerve-wracking experience. Even though I felt prepared for some aspects, I felt underprepared for others.  

I found myself struggling with the tasks, going through them in an unordered sequence—not to mention the large number of tasks was intimidating. The redesigned CCIE program added to the challenge, as the new lab environment was still in its early stages. Disappointed in my performance, I received the news that I had failed both modules. The failure hit me hard, and with the lab’s uncertainty due to the pandemic, I stopped studying for several months.  

When I restarted my studies in January 2021, I was more determined than ever. This time, I developed a “simple” 7-step strategy for the CCIE lab exam itself: 

Read the material.
Read the material again.
Answer the question.
Read the material again.
Check the answer.
Read the material again.
Recheck the answer. 

My second attempt in July 2021 went better than the first, but as I approached the 2.5-hour mark in the DOO module, I panicked. I realized I had made some mistakes and done some illogical things which caused me to run out of time and only finish 2/3 of the tasks.  

After the second lab, I again knew I had failed but it was because of simple mistakes and overconfidence. But when I received my scores the next morning, I saw my preparation had massively increased my scores this time around: I passed the DESIGN module, but still failed the DOO module.  

For my third attempt in September 2021, I booked the exam just seven days after the second try.  

The extra preparation paid off. The DESIGN module went well, and I felt confident approaching the DOO module. Despite getting stuck at one point, I pushed through.  

At the very end, with only 25 minutes on the clock and almost none of the tasks having been reviewed, I made a bold decision. I decided to save the running configuration to the startup configuration for every device, making sure they were all in privileged EXEC mode, and used the remaining time to do at least a little bit of configuration verification. With only 10 seconds to spare, I hit the End Exam button.  

After my best attempt yet, I received the news by 5 p.m. that same day. I had passed the exam and earned my CCIE EI certification! The journey had been long and tough, but the setbacks only made the win more satisfying.  

Life after CCIE: Embracing new opportunities and personal goals 

Becoming a CCIE requires hard work, discipline, and persistence. It wasn’t without its challenges, not to mention the substantial investment of time, energy, and cost. With my CCIE in hand and newfound free time, I’ve rediscovered my old hobbies and passions of playing piano… and finally getting back to my private life. I’m excited to discover where my learning journey will take me next. I will always be grateful to the CCIE contractor who introduced me to the world of Cisco certification.   

If you’re interested in pursuing a CCIE certification yourself, I invite you to read CCIE Study Materials, Costs, and Preparation Tips. There you can find my study tips, cost breakdowns, and other useful tips that I gathered along my own CCIE certification journey. I also made my lab notes available to everyone at cice.cknetworking.de. Whether you’re just starting out or well into your studies, I hope you find these resources helpful in your pursuit of this challenging certification. Best of luck! 

Hear Christian Kellerer tell the story of how he became CCIE #65551 on the Cisco Learning Network Podcast.

Join the Cisco Learning Network today for free.

Follow Cisco Learning & Certifications

Twitter  YouTube

Use #CiscoCert to join the conversation.

 Read next: “What It Takes to Become a CCIE” by Yusuf Bhaiji, Director of Cisco Certifications. Read blog.

Share

  Cisco Designated VIP Christian Kellerer, CCIE #65551, shares his Cisco certification journey, how he refused to give up on the CCIE Enterprise Infrastructure certification, and the "simple" 7-step strategy that helped him pass the lab exam.  Read More Cisco Blogs 

By |2023-09-11T23:51:59+00:00September 11, 2023|Cisco: Learning|0 Comments

Cisco Welcomes Nicole Isaac as Vice President of Global Public Policy Jeff Campbell on September 10, 2023 at 7:00 pm

Today, Cisco announced Nicole Isaac has joined the company’s Government Affairs organization as Vice President of Global Public Policy. Leading a team of experts, Nicole will drive Cisco’s policy age… Read more on Cisco Blogs

Today, Cisco announced Nicole Isaac has joined the company’s Government Affairs organization as Vice President of Global Public Policy. Leading a team of experts, Nicole will drive Cisco’s policy agenda to bolster ICT adoption around the world and enable Cisco’s purpose to power an inclusive future for all.

Nicole joins Cisco with more than 20 years of diverse experience across the world. In addition to senior roles at Google, Meta, and LinkedIn, her background in government is wide-ranging. After beginning her career as counsel in the U.S. House of Representatives, she became a foreign law clerk at the Constitutional Court of South Africa before joining the office of U.S. Senate Assistant Majority Leader Richard Durbin (D-Ill.) as floor counsel. And for five years of the Obama administration, Nicole was the deputy director for legislative affairs to then-Vice President Joe Biden and later served as a special assistant to President Barack Obama in the White House’s Office of Legislative Affairs.

Nicole’s track record knows no boundaries, and her depth of experience across the world brings a valued perspective that very few people have. She is a tremendous addition to Cisco, and her leadership will help solidify Cisco’s global public policy efforts.

“As a company that is building next-generation wireless networks and connecting the world, Cisco recognizes that public policies are pivotal to enabling not only a secure and digital future but also one that is inclusive. I am excited to work with Cisco Government Affairs’ team of talented experts as we shape public policy in a way that helps governments around the globe meet their digitization goals.”

Passionate about empowering others, Nicole was the founder and CEO of Code the Streets, Inc.—a nonprofit organization designed to increase access to educational and mentoring resources for inner-city youth through technology. She has also been a trustee with World Learning Inc. and a board member of the Joseph R. Biden Foundation. She was recently appointed to serve as a commissioner to the United States Commission on the Preservation of America’s Heritage Abroad, which protects and preserves historic properties and monuments across Eastern and Central Europe.

Nicole grew up in the Bronx, New York and received her Bachelor of Arts from Brown University, Master of Arts from Columbia University, Juris Doctor from the University of Pennsylvania Law School, and Master of Studies (LLM equivalent) from the University of Oxford.

Share

  Today, Cisco announced Nicole Isaac has joined the company’s Government Affairs organization as Vice President of Global Public Policy. Leading a team of experts, Nicole will drive Cisco’s policy agenda to bolster ICT adoption around the world and enable Cisco’s purpose to power an inclusive future for all. Nicole joins Cisco with more than 20  Read More Cisco Blogs 

By |2023-09-10T22:51:24+00:00September 10, 2023|Cisco: Learning|0 Comments

Tips to optimize your drive-thru Mark Scanlan on September 7, 2023 at 7:42 pm

Would you wait 5 minutes in a drive-thru line? How about 10 minutes? Speed is imperative for drive-thrus, especially when there’s a long line. A quick and effective drive-thru has become the norm of… Read more on Cisco Blogs

Would you wait 5 minutes in a drive-thru line? How about 10 minutes? Speed is imperative for drive-thrus, especially when there’s a long line. A quick and effective drive-thru has become the norm of what a consumer expects. They want to order and leave the line as quickly as possible. According to Bluedot, 85% of consumers will consider or outright leave a perceived long line. So how can Cisco help you optimize your drive-thru, shorten the line and capture otherwise lost revenue?

Transform your drive-thru and curbside visibility and insights 

Computer vision can deliver business intelligence in drive-thrus with its ability to:

Detect and track vehicles from entrance to exit.
Monitor engagements at the window and curbside.
Measure elapse time at various stages of the process.
Automatically take action to shorten service time or triage the line to prevent balk.

Imagine picking up your kids from school and before heading home your favorite bakery sends you a message from their app. How does this happen? Let us show you:

Drive-thru optimization in Retail curbside pickup

Geo locationing in the app detects the vehicle leaving the school. As you pull into the bakery parking lot the store detects your phone via wireless and sends you a message that the drive-thru wait is 5 minutes, determined by video analytics but if you want your regular order, they can bring it curbside in 3 minutes. But since you are with your kids, and need to add their order, you decide to join the drive-thru line. The bakery starts to detect frustrated customers and some of them leave the line. Since the bakery knows you are a loyal customer, they offer you a free cake pop at the window. Once you pull into the digital menu board, you notice that it looks different. The bakery has actually updated it to promote items with shorter wait times, and to get customers served quicker. You place your order and pull into the window and pay with the bakery’s app. Quick right?

Continuing the conversation 

Going through a drive-thru remodel may seem intimidating. Working with an experienced partner like Cisco will enable you to put the focus back on your customer while we focus on implementing solutions that will increase traffic flow and ordering efficiency.

Check out our new use case focusing on drive-thru optimization in our updated Portfolio Explorer.  

Share

  Going through a drive-thru remodel may seem intimidating. Working with an experienced partner like Cisco will enable you to put the focus back on your customer while we focus on implementing solutions that will increase traffic flow and ordering efficiency.  Read More Cisco Blogs 

By |2023-09-08T20:50:55+00:00September 8, 2023|Cisco: Learning|0 Comments

Prepare for Managed Services Growth Grace Lo on September 8, 2023 at 7:00 pm

Capturing your share of the massive Managed Services Provider (MSP) market means making the most of every opportunity. Together, we can prepare to meet even more customer needs as expansion… Read more on Cisco Blogs

Capturing your share of the massive Managed Services Provider (MSP) market means making the most of every opportunity. Together, we can prepare to meet even more customer needs as expansion continues. We have several tools and resources available to help you do just that, including upcoming Cisco Ignite Provider Growth Session, where you can learn the keys to increasing your profitability.

“Managed Services Is Our Market to Win, Together.”– Alexandra Zagury, Vice President Partner Managed and as-a-Service Sales

Join our Cisco Ignite Provider Growth Session

This is a great opportunity to get educated about how to reach more customers in managed services, new incentives and three new Cisco Powered Services that just launched, how we have simplified the partner experience, and much more.

Here is our line-up of topics:

Provider Role Highlights and Evolution
New Partner Experience for Cisco Powered Services
Improved Earning Model for Provider MDF
Provider Pricing and PIF Investment
Licensing and Buying Models for MSEA & MSLA
Getting the Latest Resources

We value your partnership and look forward to seeing you. Together, we can grow our mutual success by serving customers.

Invite your business colleagues: Managed Services Program Manager to attend.

Thursday, September 21 at 8:00-9:00 am PST – AMER & EMEA
Register: Provider Growth Session
Thursday, September 21 at 7:00-8:00 pm PST (Friday, September 22 10:00 am SGT) – APJC
Register: Provider Growth Session

We want to hear from you! Share your thoughts about e-books for managed services with us in this quick survey.

Register for the Provider Growth Session today!AMER/EMEAAPJC

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    Cisco Partners LinkedIn

Share

  Capturing your share of the massive Managed Services Provider (MSP) market means making the most of every opportunity. Together, we can prepare to meet even more customer needs as expansion continues.  Read More Cisco Blogs 

By |2023-09-08T20:50:54+00:00September 8, 2023|Cisco: Learning|0 Comments

The New Normal is Here with Secure Firewall 4200 Series and Threat Defense 7.4 Andrew Ossipov on September 8, 2023 at 6:16 pm

What Time Is It?

It’s been a minute since my last update on our network security strategy, but we have been busy building some awesome capabilities to enable true new-normal firewalling. As we r… Read more on Cisco Blogs

What Time Is It?

It’s been a minute since my last update on our network security strategy, but we have been busy building some awesome capabilities to enable true new-normal firewalling. As we release Secure Firewall 4200 Series appliances and Threat Defense 7.4 software, let me bring you up to speed on how Cisco Secure elevates to protect your users, networks, and applications like never before.

Secure Firewall leverages inference-based traffic classification and cooperation across the broader Cisco portfoliowhich continues to resonate with cybersecurity practitioners. The reality of hybrid work remains a challenge to the insertion of traditional network security controls between roaming users and multi-cloud applications. The lack of visibility and blocking from a 95% encrypted traffic profileis a painful problem that hits more and more organizations; a few lucky ones get in front of it before the damage is done. Both network and cybersecurity operations teams look to consolidate multiple point products, reduce noise, and do more with less; Cisco Secure Firewall and Workload portfolio masterfully navigates all aspects of network insertion and threat visibility.

Protection Begins with Connectivity

Even the most effective and efficient security solution is useless unless it can be easily inserted into an existing infrastructure. No organization would go through the trouble of redesigning a network just to insert a firewall at a critical traffic intersection. Security devices should natively speak the network’s language, including encapsulation methods and path resiliency. With hybrid work driving much more distributed networks, our Secure Firewall Threat Defense software followed by expanding the existing dynamic routing capabilities with application- and link quality-based path selection.

Application-based policy routing has been a challenge for the firewall industry for quite some time. While some vendors use their existing application identification mechanisms for this purpose, those require multiple packets in a flow to pass through the device before the classification can be made. Since most edge deployments use some form of NAT, switching an existing stateful connection to a different interface with a different NAT pool is impossible after the first packet. I always get a chuckle when reading those configuration guides that first tell you how to enable application-based routing and then promptly caution you against it due to NAT being used where NAT is usually used.

Our Threat Defense software takes a different approach, allowing common SaaS application traffic to be directed or load-balanced across specific interfaces even when NAT is used. In the spirit of leveraging the power of the broader Cisco Secure portfolio, we ported over a thousand cloud application identifiers from Umbrella,which are tracked by IP addresses and Fully Qualified Domain Name (FQDN) labels so the application-based routing decision can be made on the first packet. Continuous updates and inspection of transit Domain Name System (DNS) traffic ensures that the application identification remains accurate and relevant in any geography.

This application-based routing functionality can be combined with other powerful link selection capabilities to build highly flexible and resilient Software-Defined Wide Area Network (SD-WAN) infrastructures. Secure Firewall now supports routing decisions based on link jitter, round-trip time, packet loss, and even voice quality scores against a particular monitored remote application. It also enables traffic load-balancing with up to 8 equal-cost interfaces and administratively defined link succession order on failure to optimize costs. This allows a branch firewall to prioritize trusted WebEx application traffic directly to the Internet over a set of interfaces with the lowest packet loss. Another low-cost link can be used for social media applications, and internal application traffic is directed to the private data center over an encrypted Virtual Tunnel Interface (VTI) overlay. All these interconnections can be monitored in real-time with the new WAN Dashboard in Firewall Management Center.

Divide by Zero Trust

The obligatory inclusion of Zero Trust Network Access (ZTNA) into every vendor’s marketing collateral has become a pandemic of its own in the last few years. Some security vendors got so lost in their implementation that they had to add an internal version control system. Once you peel away the colorful wrapping paper, ZTNA is little more than per-application Virtual Private Network (VPN) tunnel with an aspiration for a simpler user experience. With hybrid work driving users and applications all over the place, a secure remote session to an internal payroll portal should be as simple as opening the browser – whether on or off the enterprise network. Often enough, the danger of carelessly implemented simplicity lies in compromising the security.

A few vendors extend ZTNA only to the initial application connection establishment phase. Once a user is multi-factor authenticated and authorized with their endpoint’s posture validated, full unimpeded access to the protected application is granted. This approach often results in shamingly successful breaches where valid user credentials are obtained to access a vulnerable application, pop it, and then laterally spread across the rest of the no-longer-secure infrastructure. Sufficiently motivated bad actors can go as far as obtaining a managed endpoint that goes along with those “borrowed” credentials. It’s not entirely uncommon for a disgruntled employee to use their legitimate access privileges for less than noble causes. The simple conclusion here is that the “authorize and forget” approach is mutually exclusive with the very notion of Zero Trust framework.

Secure Firewall Threat Defense 7.4 software introduces a native clientless ZTNA capability that subjects remote application sessions to the same continuous threat inspection as any other traffic. After all, this is what Zero Trust is all about. A granular Zero Trust Application Access (ZTAA – see what we did there?) policy defines individual or grouped applications and allows each one to use its own Intrusion Prevention System (IPS) and File policies. The inline user authentication and authorization capability interoperates with every web application and Security Assertion Markup Language (SAML) capable Identity Provider (IdP). Once a user is authenticated and authorized upon accessing a public FQDN for the protected internal application, the Threat Defense instance acts as a reverse proxy with full TLS decryption, stateful firewall, IPS, and malware inspection of the flow. On top of the security benefits, it eliminates the need to decrypt the traffic twice as one would when separating all versions of legacy ZTNA and inline inspection functions. This greatly improves the overall flow performance and the resulting user experience.

Let’s Decrypt

Speaking of traffic decryption, it is generally seen as a necessary evil in order to operate any DPI functions at the network layer – from IPS to Data Loss Prevention (DLP) to file analysis. With nearly all network traffic being encrypted, even the most efficient IPS solution will just waste processing cycles by looking at the outer TLS payload. Having acknowledged this simple fact, many organizations still choose to avoid decryption for two main reasons: fear of severe performance impact and potential for inadvertently breaking some critical communication. With some security vendors still not including TLS inspected throughput on their firewall data sheets, it is hard to blame those network operations teams who are cautious around enabling decryption.

Building on the architectural innovation of Secure Firewall 3100 Series appliances, the newly released Secure Firewall 4200 Series firewalls kick the performance game up a notch. Just like their smaller cousins, the 4200 Series appliances employ custom-built inline Field Programmable Gateway Array (FPGA) components to accelerate critical stateful inspection and cryptography functions directly within the data plane. This industry-first inline crypto acceleration design eliminates the need for costly packet traversal across the system bus and frees up the main CPU complex for more sophisticated threat inspection tasks. These new appliances keep the compact single Rack Unit (RU) form factor and scale to over 1.5Tbps of threat inspected throughput with clustering. They will also provide up to 34 hardware-level isolated and fully functional FTD instances for critical multi-tenant environments.

Those network security administrators who look for an intuitive way of enabling TLS decryption will enjoy the completely redesigned TLS Decryption Policy configuration flow in Firewall Management Center. It separates the configuration process for inbound (an external user to a private application) and outbound (an internal user to a public application) decryption and guides the administrator through the necessary steps for each type. Advanced users will retain access to the full set of TLS connection controls, including non-compliant protocol version filtering and selective certificate blocklisting.

Not-so-Random Additional Screening

Applying decryption and DPI at scale is all fun and games, especially with hardware appliances that are purpose-built for encrypted traffic handling, but it is not always practical. The majority of SaaS applications use public key pinning or bi-directional certificate authentication to prevent man-in-the-middle decryption even by the most powerful of firewalls. No matter how fast the inline decryption engine may be, there is still a pronounced performance degradation from indiscriminately unwrapping all TLS traffic. With both operational costs and complexity in mind, most security practitioners would prefer to direct these precious processing resources toward flows that present the most risk.

Lucky for those who want to optimize security inspection, our industry-leading Snort 3 threat prevention engine includes the ability to detect applications and potentially malicious flows without having to decrypt any packets. The integral Encrypted Visibility Engine (EVE) is the first in the industry implementation of Machine Learning (ML) driven flow inference for real-time protection within the data plane itself. We continuously train it with petabytes of real application traffic and tens of thousands of daily malware samples from our Secure Malware Analytics cloud. It produces unique application and malware fingerprints that Threat Defense software uses to classify flows by examining just a few outer fields of the TLS protocol handshake. EVE works especially well for identifying evasive applications such as anonymizer proxies; in many cases, we find it more effective than the traditional pattern-based application identification methods. With Secure Firewall Threat Defense 7.4 software, EVE adds the ability to automatically block connections that classify high on the malware confidence scale. In a future release, we will combine these capabilities to enable selective decryption and DPI of those high-risk flows for truly risk-based threat inspection.

The other trick for making our Snort 3 engine more precise lies in cooperation across the rest of the Cisco Secure portfolio. Very few cybersecurity practitioners out there like to manually sift through tens of thousands of IPS signatures to tailor an effective policy without blowing out the performance envelope. Cisco Recommendations from Talos has traditionally made this task much easier by enabling specific signatures based on actually observed host operating systems and applications in a particular environment. Unfortunately, there’s only so much that a network security device can discover by either passively listening to traffic or even actively poking those endpoints. Secure Workload 3.8 release supercharges this ability by continuously feeding actual vulnerability information for specific protected applications into Firewall Management Center. This allows Cisco Recommendations to create a much more targeted list of IPS signatures in a policy, thus avoiding guesswork, improving efficacy, and eliminating performance bottlenecks. Such an integration is a prime example of what Cisco Secure can achieve by augmenting network level visibility with application insights; this is not something that any other firewall solution can implement with DPI alone.

Light Fantastic Ahead

Secure Firewall 4200 Series appliances and Threat Defense 7.4 software are important milestones in our strategic journey, but it by no means stops there. We continue to actively invest in inference-based detection techniques and tighter product cooperation across the entire Cisco Secure portfolio to bring value to our customers by solving their real network security problems more efficiently. As you may have heard from me at the recent Nvidia GTC event, we are actively developing hardware acceleration capabilities to combine inference and DPI approaches in hybrid cloud environments with Data Processing Unit (DPU) technology. We continue to invest in endpoint integration both on the application side with Secure Workload and the user side with Secure Client to leverage flow metadata in policy decisions and deliver a truly hybrid ZTNA experience with Cisco Secure Access. Last but not least, we are redefining the fragmented approach to public cloud security with Cisco Multi-Cloud Defense.

The light of network security continues to shine bright, and we appreciate you for the opportunity to build the future of Cisco Secure together.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Read on for an in-depth discussion of our latest Cisco Secure Firewall announcement, including the new 4200 Series appliance, and 7.4 software features.  Read More Cisco Blogs 

By |2023-09-08T20:50:54+00:00September 8, 2023|Cisco: Learning|0 Comments
Go to Top