
Trace the evolution of Cisco firewalls from pix to ftd, introduce firepower services, and explore firepower threat defense with os, feeds, and policies like access control and intrusion prevention.
Install FMC and FTD in routed mode on a simplified topology and boot them. Configure DMZ IPs, DNS, and HTTP servers, then verify management access and basic connectivity.
Configure outside, inside, and dmz security zones, assign IPv4 addresses, explore interface types: sub, redundant, bridge group, and virtual tunnel; verify with show interface ip brief and ping tests.
Develop and implement DNS policies in Cisco Firepower NGFW, configuring DNS rules, domain not found blocking, and sinkhole behavior to illuminate who accesses blocked domains via security intelligence events.
Configure a dns sinkhole in Cisco Firepower by creating a sinkhole object, applying it to the dns policy, and deploying to redirect malware traffic.
Enable identity policy by integrating Active Directory with the FMC, configure realms, download domain users, enable discovery, and apply user-based access control to tag traffic and block apps for users.
The Cisco Firepower™ Next-Generation Firewall (NGFW) is the foundation of the integrated Cisco security architecture. It delivers comprehensive, unified policy management of firewall functions, application control, threat prevention, and advanced malware protection from the network to the endpoint.
Cisco Firepower Benefits:
• Leverage your existing investments with Cisco.
• Enforce policies with greater security control points.
• Safeguard users anywhere they access the internet.
• Extend the capabilities of your network appliances for better, more integrated security.
• Gain a robust set of product integrations for zero trust.
Cisco offers a range of options to address your business needs: Firepower 1000 Series, 2100 Series, 4100 Series, 7000 Series, 8000 Series, and 9300 Series appliances.
At-a-Glance Industry’s First Fully Integrated, Threat-Focused Next-Generation Firewall Most next-generation firewalls (NGFWs) focus heavily on enabling application control, but little on their threat defense capabilities. To compensate, some NGFW’s will try to supplement their first-generation intrusion prevention with a series of non-integrated add-on products. However, this approach does little to protect your business against the risks posed by sophisticated attackers and advanced malware. Further, once you do get infected, they offer no assistance in scoping the infection, containing it, and remediating quickly.
Protect Your Organization Before, During, and After an Attack The Cisco Firepower NGFW includes the industry’s most widely deployed stateful firewall and provides granular control over more than 4,000 commercial applications. Its single management interface delivers unified visibility from the network to the endpoint. Firepower NGFW enables comprehensive policy management that controls access, stops attacks, defends against malware and provides integrated tools to track, contain and recover from attacks that do get through.