- Видео 10
- Просмотров 188 286
Managing Cisco Advanced Security
Добавлен 18 авг 2016
Learn how local and central management can be used to manage, analyze and remediate your network against threats with Cisco's Next Generation Firewall that provides stateful firewalling, nat, routing, next-generation Intrusion Prevention System (NGIPS), Application Visibility and Control (AVC), URL filtering, and Advanced Malware Protection (AMP), all in one device.
Видео
Firepower Management Center Overview
Просмотров 51 тыс.7 лет назад
The Firepower Management Center is the heart of leveraging a Next Generation security architecture. Most users today only use it as a policy manager and an event viewer. In this session, we will dive into how the Firepower Manager works and can improve your security and business capabilities. We will examine how the system actually reduces the amount of time required to respond to events using ...
Site to Site VPN with Firepower Device Manager
Просмотров 14 тыс.7 лет назад
This video show how to configure Site to Site VPN on Firepower Threat Defense software using Firepower Device Manager.
Monitoring and Reporting with Firepower Device Manager
Просмотров 15 тыс.8 лет назад
This video shows the monitoring dashboards and eventing capabilities of Firepower Device Manager
Database Updates, Backup/Restore and Collecting Troubleshoot with Firepower Device Manager
Просмотров 5 тыс.8 лет назад
This video walks through the process of updating the various databases (signature, geolocation, url and vulnerability), explain how to maintain configuration backups, and collecting troubleshoot with Firepower Device Manager
Applying Intrusion Prevention and Advanced Malware Protection with Firepower Device Manager
Просмотров 10 тыс.8 лет назад
This video talks about how to apply IPS and Malware inspection to Permitted Traffic in your network with Firepower Device Manager
Managing Authentication and User Discovery with Firepower Device Manager
Просмотров 11 тыс.8 лет назад
This video shows how Active Authentication can be used with Active Directory to perform user discovery and create user based access control
Configuring NAT and Access Control for Next-Generation Firewall with Firepower Device Manager
Просмотров 42 тыс.8 лет назад
This video walks through the configuration of Auto NAT to provide connectivity and Access Control based on Application and URL Categories to provide Security to your network when using Firepower Device Manager
Out of Box Experience and User Interface walkthrough with Firepower Device Manager
Просмотров 13 тыс.8 лет назад
This video explains the ease of use of the initial setup wizard that provides the user with the best out of box experience and provide a high level overview of the Firepower Device Manager user interface.
Introduction to Firepower Device Manager
Просмотров 23 тыс.8 лет назад
This is an introduction to Cisco's new web-based onbox manager for Next-Generation Firewall
Still important after 7 years ..Thank You
could you share this PPT?
Hi Team, can you help us to me ,how to configure email notifications regarding FMC & FTD back-up status. For this request put one video in this channel. Or else related request please share the document website/ link . Thanks.,
Cisco products years ago use to be manufactured in Mexico, now they all made/flashed in china. Why the heck are firewalls being flashed/built in china and put into American companies to defend against hackers mainly coming from china is beyond me! How secure are these really?
Great video thanks! you guys have any idea if is posible to create sections where we can group rules, just like ASA does per interface
Good explanation.
Thank you so much!
Great Help
why do you need a route local network to remote GW??? you are configuring policy based VPN and how it is going to communicate both site LAN subnets without NO-NAT. :D
Hi - Great video, thanks for taking the time to make it. Do you plan to make a video on Uril filtering with Firepower Device Manager ?
Great … thanks a lot
How can you configure network object range Example object network Admin_Svr range 192.168.85.5 192.168.85.9
What is 192.168.1.250 ??? where do yuo have it on your network Map ? If I understarnd user from ps3 should enter 192.168.1.2 witch is firepower outside address and it translate it to 172.16.0.200. anyway I did same like in this video and it doesnt work.
did you figure it out? I am in the same situation
can you please send me remote desktop NAT configuration for outside network
I don't know why Cisco decided to stop supporting ASDM with he next generation firewalls, that was just plain dumb as there are thousands of network engineers who do allot of extensive troubleshooting using it. My 2 cents
How do we go from a 5506 to the next generation 1010 carrying over all access-list rules & Nat? There has to be a way instead of manually doing so, we have thousands of rules to carry over.
how to create user and group in FTD 6.2.3 for captive portel
@Deepti: You are "The Best" :)
Can you confirm with ranges of Firepower (2100 / 4100 / 9300) can run FDM, FMC & CDO ?
Hi Alex, I'm attempting to follow this on my FMC (6.2.3) and when I get to the stage where I need to define the detection pattern I do'nt have the ooption to do so. I can onlu upload a .lua file or packet capture. Any advice where I am going wrong? Thanks J
Any option to monitor the traffic/status for the VPN on the FDM ?
In FDM we have an Embedded CLI console in the UI which helps to run the show commands to monitor VPN traffic
Thanks Alex. Awesome video that will help me out. Just ran into an issue which Cisco TAC noted the FQDN is not supported (bug id: cscuv93558 ). Hey, wish you were still on our NS Cisco team. Hopefully our paths will cross again. Thanks, Oneal
Awesome videos, I tried to apply a file policy to a rule that contained applications allowed like Facebook but errored out with a warning and had to remove the file policy from rule to fix it, could you explain why?
Would have to see the error see why it failed. You could even open a TAC case if needed.
@@managingciscoadvancedsecur4046 actually you can't apply a file policy to a rule containing an application like Facebook. Just need to understand why, thank you again
Hi, can the firepower FTD are run full functionality (threat, malware, url filtering, etc) without internet connection? Can i download the database signature from software.cisco.com (*.sh) and upload to the box?
No, you cannot download the SRU updates and upload them manually via FDM. So, you need timeline internet connection for both Smart Licensing & Updates. But via FMC we do support that + Offline licensing support
Can you tell how to fatch the report of all ACL in excel format.
Hi Rakesh, we dont have that from the GUI but we have REST APIs available that can help you fetch the ACL Table
thanks
How can we get monthly or 2 monthly systwm usage like mem and cpu usage from fmc??
Can you pls also share how to change security-level on interface from GUI or CLI? Thanks for the video!
FTD is a zone based Firewall. You dont need to configure security levels anymore. The traffic is controlled by using the Zones in the access control rules
I'm still not getting that perverted logic. Why if I need to have packet to be translated from outside to inside network, I have to create NAT rule in the opposite direction? It's like NATing reply packets from the server
I tottally agree with you! I don't get it. I am trying to use the IP address of the outside interface to publish a server and I just can't do it yet. In the FMC is more simple.
hi. i am using ftd 6.2.3 evaluation license but RA VPN is greyed. Unable to enable it. What could he happening? Thanks
Mario Lopez - you need export compliance for RA VPN which doesnt come with eval lic
What about trying to nat an inside server to public outside interface directly ?
This is just an example. You can do NAT depending on the translation you want.
Hi I have Cisco ASA 5525-x Firepower SFR as usual managing through FMC. I have one scenario which is given by customer and that is they want to block particular extension files while downloading from internet. Extension like : .exe, .mp4, .mp3, .mkv It would be great help for me if you explain me in brief.
Try File Policy in FMC. Here are the File Rule Components - www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.html#ID-2193-000002e9
Managing Cisco Advanced Security Thanks for your help. Is it possible to block only attachment file from a particular application. Like user can use all feature of skype, outlook,gmail, etc. But they are not able to attach any file with this applications.
If you dont have internet and skip the device setup, is there a way to run it again later to complete the process?
Yes, you can skip the wizard and do it later from system settings
Excellent!!!
Excellent explanation and it becomes a great help. Now we must expand the work that starts. I encourage you to continue, thank you very much
great information
Hi Mrs. Depti, at this moment is there a resource on Cisco or some cloud in order to learn and practice with FDM? Thanks
ok many thanks, do you have some basic CLI reference to do that?
www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/vmware/ftdv/ftdv-fdm-vmware-qsg.html
What version FMC are you using?
FMC version 6.1 if I remember right
Is there a way to configure dynamic routing like EIGRP from the User Interface or the CLI on the firepower using only the Device Manager and not the Management Center?
Hi Nelson, Dynamic Routing is not supported yet with this Onbox Manager but coming soon
Hi.. Thanks for the videos.. simply supperb. My question, is it possible to migrate the configurations from Cisco ASA5500 series to Cisco FTD 2100 appliance? NB: i do not own any FMC (virtual or otherwise).
Hi Shabeeb, Today the migration tool we have is with FMC. But if you want to reach out to me at dhemwani@cisco.com, we can discuss more on this.
You gave me a fair Idea Thanks
Does Firepower version 6.1.0-330 need User Agent installed on Domain Controller? I'm facing a lot of problems with User Agent and I didn't find any solution using Firepower 5.4. If version 6.1 solves these problems, I will update my Firepower.
Hi Jones, This is not a Product using UserAgent. You might want to reach out to your local CSE and address your concerns. Thanks, Deepti
OK thank you for your answer. And do you know if Cisco will realease a FTD Virtual Image for learning (the same way as ASAv)? Thanks
FTDv is already available. FDM on FTDv should be available in the next release.
Are you showing the configurations based on old GUI?
Which old GUI are you referring to? This is based on Firepower Device Manager(FDM) managing our new converged software called Firepower Threat Defense. FDM released in 6.1 release.
I dont understand why you dont have to specify ports when doing ACL/NAT rules ?
You can if you wish to. I am just not showing all combinations as part of this series. This is to just get you started on our new GUI.
Could you please provide an example for setting up static nat, so i can recive mail on my spamfilter ?
It looks like you have left the web server open to access on ALL ports - Severe Security breach.
Excuse me: the firewall of this tutorial is an ASA 5508-X but it is not running ASA software. It is running sourcefire software directly? what about SSD module? Thanks.
Correct, the ASA5508-X is running the converged software called Firepower Threat Defense (FTD). You need the SSD to reimage the box to FTD
I am really thankful for the this mini series.. I am also looking for more on FDM and configuring FTD 6.1 using FMC 6.1..
Nice Video