Brksec 2236
Brksec 2236
Brksec 2236
Keeping Up on Network
Security with Cisco Secure
Firewall
Subtitle goes here
Andrew Ossipov
Distinguished Engineer, CTO
BRKSEC-2236
#CiscoLive
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Your Speaker
Andrew Ossipov
aeo@cisco.com
Distinguished Engineer
Product CTO for Network, Workload, and Cloud Security
Firewall Architecture, Hybrid Cloud, Unified Policy, SASE
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
FTD ASA
• Introduction
• Secure Firewall 3100
• Threat Prevention
Agenda • Connectivity
• Private and Public Cloud
• Management
• Conclusion
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Firewall: From DPI to Inference and Cooperation
Customers
CloudLock
SaaS
Remote
Umbrella Inbound
Mapping network flows to specific user actions via
cloud application API and CASB
Continue to decrypt inbound for full app threat protection
(IPS, WAF, AMP, API) with minimal functional impact
Outbound
Apps
Campus New-Normal Firewall
TCP inside:192.168.1.11/54397 outside:203.0.113.100/443
TCP inside:192.168.2.110/34624 DC:172.16.45.200/443
TCP outside:198.51.100.231/13945 DC: 172.16.45.201/443 Dynamic Attribute
Secure Endpoint Secure Workload Connector
Client context discovery via passive fingerprinting and Server/workload attribute discovery, host
trusted endpoint agent cooperation OS and cloud native API protection
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Secure Firewall 3100
FTD ASA
1RU
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
FTD ASA
Ethernet
3110-3120: 25Gbps
Flow Offload Crypto
3130-3140: 80Gbps
Crypto
Engine Offload
Engine
Chip-to-Chip Link
3110-3120 :2x10Gbps 3110-3120: 40Gbps
3130-3140: 2x25Gbps 3130-3140: 50Gbps
10GE SFP On-board 8x1GE 3110-3120: On-board 8x10GE SFP Hot-swappable interface
Management/Events copper interfaces 3130-3140: On-board 8x25GE SFP expansion module
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
FTD ASA
Up to 7x Boost in
FW+AVC+IPS
Up to 17x Boost in
IPsec VPN
Up to 14x Boost in
TLS
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Threat Protection
FTD
7.1
Encrypted Visibility Engine (EVE)
TLS ClientHello
Confidence: 99.94%
Process: firefox.exe
Version: 76.0.1
Category: browser
OS: Windows 10 19041.329
Destination FQDN: cisco.com
https://github.com/cisco/mercury
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
FTD
EVE-enriched Unified Events 7.1
Client process name and detection confidence score; the name
can be linked to a custom AppID for enforcement in FTD 7.2.
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
FTD
Portscan Detection and Prevention 7.2
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Connectivity
FTD
Application-Aware Policy Routing 7.1
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
FTD
Elephant Flow Detection 7.2
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
FTD ASA
Loopback Interface 7.3 9.18.2
Loopback0
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Private and Public Cloud
FTD ASA
• Network firewall service insertion for both inbound and outbound flows
• Redirection with GEneric NEtwork Virtualization Encapsulation (GENEVE)
• Bring-your-own TLS decryption with available software capabilities
AWS Cloud
• FTD 7.2 and ASA 9.18 add Autoscale support and snapshot-based image bring-up
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
FTD ASA
vPC
• Clustering combines multiple firewalls into one logical device
• Seamless scalability up to 16 FTD units with no traffic disruption
Cluster
• Stateful handling of asymmetric traffic and failure recovery FTD FTD
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Infrastructure as Code
FTD ASA
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Management
FMC
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Simplified Access Control Policy View FMC
7.2
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
FMC
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
FMC
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
FMC
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
FMC
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Cisco Security Beta Programs
Sign-Up Now:
http://cs.co/clive-security-beta
“I've been involved in many beta programs…I must say that this one has been the
best organized. This beta takes a very active, hands-on approach.”
Higher-Ed Beta Customer
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Pay for Learning with
Cisco Learning Credits
Cisco Learning and Certifications (CLCs) are prepaid training
vouchers redeemed directly
From technology training and team development to Cisco certifications and learning with Cisco.
plans, let us help you empower your business and career. www.cisco.com/go/certs
Here at the event? Visit us at The Learning and Certifications lounge at the World of Solutions
#CiscoLive BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
• Visit the Cisco Showcase
for related demos
BRKSEC-2236 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Thank you
#CiscoLive
#CiscoLive