
Discover the fundamentals of the Cisco Sourcefire Firepower intrusion prevention system and its role in network security.
Download and install the Firesight Defense Center virtual appliance from Cisco, extract the tar and the OVL files, deploy to infrastructure, configure the management interface, and apply the license.
Explore deployment modes for Cisco Sourcefire Firepower IPS, including in-line, passive, and best deployment, with traffic mirroring, security zones, and policy-based layer-3 routing for selective inspection.
Install and activate a Sourcefire IPS sensor, configure management and network interfaces, apply licenses, and set up inline or passive deployment with security zones for intrusion prevention.
Update and maintain Cisco Sourcefire Firepower by scheduling software and vulnerability database updates for the far side and sensors, monitor progress, and reapply intrusion and access control policies after updates.
Configure fire site and system policies to manage certificates, access controls, policy assignment to sensors, and change history for intrusion prevention.
Learn to create application-based access control policies with Cisco Sourcefire Firepower, blocking very high risk applications like Facebook using the protection and control license, with logging and rule management.
Configure an interactive block to prompt users before visiting web sites, apply intrusion policy to traffic, log events, and enforce access denied until users confirm to continue.
Create application filters to simplify access policies, exemplified by a Facebook filter that allows Facebook while blocking other very high risk apps, enabling dynamic updates to the policy.
Learn to simplify access control policies by creating network objects and object groups, then apply them in rules to replace individual objects with reusable groups for efficient policy management.
Block high-risk and non-business web categories with URL filtering in access control policies, using reset or block actions, while managing a 50-category limit and logging to verify blocked traffic.
Create custom application detectors on your farside system to monitor internal apps and apply access rules, using Wireshark packet captures to identify Company X Y Z traffic.
Explore how security intelligence aggregates known malicious and suspicious IP addresses to block traffic, upload custom block lists, apply policies, and generate alerts through correlation and analysis events.
Block traffic by country using geolocation based access rules in Cisco Sourcefire Firepower, configure weekly IP updates, and apply country source or destination policies in access control.
Learn to integrate Active Directory with the Firepower intrusion prevention system by configuring the user agent, AD server, and access-control policy to enforce group-based rules.
Explore SSL decryption policies in Sourcefire Firepower, including certificate-based decryption, man-in-the-middle interception, policy configuration, trusted certificates, and decrypting traffic by category from DMZ and internal servers.
Create and customize an intrusion policy by editing policies, selecting a base policy balance security over connectivity, configuring layers and variable sets for your home net, and enabling ICMP rules.
Learn how variable sets work in firepower, including the default set and custom variables. Understand inheritance and overriding across variable sets and their impact on policy and access control.
Configure network discovery policies to identify hosts and apply map remediation for port scans and operating system detection. Use correlation rules to scan new hosts and keep vulnerability data current.
Learn how network discovery policies exclude specific IPs, capture banners, and determine host identity using active and passive identity sources, then map vulnerabilities and monitor events for policy-driven responses.
Explore how Firesight recommendations analyze hosts to generate and enable intrusion prevention rules, commit and reapply policy updates, and automate scheduling to stay up to date with the latest threats.
Create custom ips rules under policy intrusion rules, using protocol checks (icmp, tcp, udp), source and destination variables, ports, and perl regular expressions to detect suspicious payloads in bidirectional traffic.
Explore generator IDs and preprocessor rules in Firepower, focusing on shared object rules (ID 3) that are compiled, modifiable only as new, with source and destination and classification options.
Explore locating, cloning, and customizing Cisco's network analysis policies in Firepower, and compare connectivity over security with maximum detection to balance security and connectivity while tuning pre-processing and ports.
Enable data loss prevention in the intrusion policy and configure sensitive data detection to identify credit card numbers, email addresses, phone numbers, and social security numbers, triggering drops at thresholds.
Enable a custom sensitive data pattern to detect sensitive information, like customer or patient numbers, leaving the network; define a data type, regex, threshold, and drop rules.
Learn how adaptive profiles in the intrusion prevention system defragment packets and reassemble tcap streams like the destination os, enabling anomaly detection and network discovery-driven policy tuning.
Adaptive profiles in passive deployment identify the destination operating system of traffic using the network map and host data, guiding IP fragment reassembly and OS-based stream processing.
The lecture explains how to manage IP policy layers, share and merge layers, create a master policy, and ensure updates propagate to network analysis and IPX policies across sites.
Configure dynamic state rules to throttle or drop traffic after threshold matches, applying intrusion policy to block sources during denial of service, demonstrated with icmp echo reply.
Enable rate based attack protection in the network analysis policy, track by source or destination, and drop traffic when thresholds are exceeded to prevent excessive connections and intrusions.
Learn how to create suppression policies in Cisco Sourcefire Firepower IPS to reduce false positives by suppressing events from a specific server while still alerting on other hosts.
Configure global and per-rule thresholds to minimize alerts in the Cisco IPS. Set limit, threshold, and both types of thresholds within a time window, with rule-level overrides.
Explore port scan detection in Cisco Sourcefire Firepower IPS, including TCP/UDP/ICMP/IP scans, sensitivity settings, watch/ignore lists, dynamic blocking, and negative responses.
Explain impact level from unknown (0) to vulnerable (1) and beyond, based on whether hosts appear in the network map, and how ports or protocols drive orange and yellow statuses.
Learn how packet latency and rule performance thresholds govern intrusion policy behavior, including how threshold violations suspend rules and how to enable alert events in the policy.
Create company-wide file policies and a block executable policy to block malware and control file transfers, using Active Directory and FireAMP VM for dynamic analysis and cloud lookups.
Learn to configure custom detection lists in Cisco Sourcefire Firepower to flag files that shouldn't leave the network, trigger malware events, and send alerts to security operations center for investigation.
Explore file policy additional features, including no fly and clean lists, sha checks via upload or manual sha, archive inspection, encrypted archive blocking, and local file storage for malware analysis.
Use the network file trajectory tool to trace file transfers, enabling forensics by showing which machines downloaded the file and when, with sender and receiver IPs and disposition.
Set up a correlation policy to notify on an indication of compromise (IOC) detected by discovery events, then configure log alerts, syslog, and high-priority emails to trigger immediate action.
Understand the order of file policies by restrictiveness and how cloud lookups, time-to-live, and retrospective status influence blocking, transfers, and device visibility through Fire integration.
Use Firesight as a compliance tool to enforce network policy by whitelisting hosts, listing allowed ports, web apps, and protocols, and generating alerts for noncompliance.
Create and review a host white list from host map and discovery data, survey networks by IP range to identify operating systems, specify clients and protocols, and enforce policy compliance.
Create and monitor traffic profiles in Cisco Firepower to sample data, build a baseline, and alert when activity exceeds normal patterns via standard deviations.
Automate threat response by blocking suspicious traffic with a policy-driven remediation using the map module, correlation events, and block source actions on a Cisco ASA.
Automate threat responses with Cisco Sourcefire Firepower by using a null route to block the offending source, configure remediation actions, and update correlation policies to halt suspicious traffic.
Use the set attribute action to tag hosts with unusual traffic, triggering remediation and alerts via policy rules in the Firepower intrusion prevention system.
Learn to use connection tracking in Cisco Sourcefire Firepower IPS to trigger alerts when external initiations target internal hosts, with criteria like country, bytes, time, and host or user identity.
Discover how to use and customize dashboards in Cisco Sourcefire Firepower, adding widgets to monitor traffic, events, risk, and intrusion activity, and build your own custom dashboards.
Create and customize widgets in the Cisco Sourcefire Firepower dashboard by enabling custom widgets and selecting tables, fields, and host-count aggregations. Name each widget, choose colors, and save tailored dashboards.
Learn how to use the NOC dashboard in Cisco Sourcefire Firepower Intrusion Prevention System to create a non-admin read-only user exempt from session timeout for uninterrupted access.
Context Explorer provides a quick network overview, showing traffic, intrusion events, and top users by source IP and destination IP, with filters for country, security zones, and application protocol.
Learn to run security reports, customize templates, and create your own reports with charts and imported dashboard sections to analyze intrusion events, policy compliance, and top applications.
Schedule automatic email delivery of a custom report by creating a scheduled task, selecting the report, and setting daily or weekly recurrence for recipients.
Explore snort rules, including shared objects, rigid rules, standard text intrusion rules, and preprocessor rules, and learn how headers and options drive payload matching.
Learn how perl-compatible regular expressions match payload content in snort rules, with key syntax and modifiers, and how service metadata guides rule application based on identified applications.
Learn to craft snort rules in Firepower to match fragmented IP headers, IP options such as source routing, ICMP values, and flow tracking with content and file inspections.
Explore how transport and network layer preprocessing decodes packets, verifies checksums, and applies inline normalization of headers and payloads for intrusion rules, then manages ECN, TTL, fragmentation, defragmentation, and streams.
Explore the DCE/RPC preprocessor in Cisco Sourcefire Firepower IPS, including SMB fragmentation, defragmentation, policy configuration, auto-detect, and file inspection.
Learn how the dns preprocessor inspects dns traffic, maps queries to ip addresses, and analyzes dns responses by their sections. Configure ports and detect obsolete resource records and overflow attempts.
Explore the ftp and telnet preprocessor in the Cisco Sourcefire firepower intrusion prevention system, using stateful inspection to detect encrypted traffic and normalize internet traffic (generator ids 125 and 126).
Analyze and normalize http traffic, decode requests and responses, and feed normalized data to the rules engine to detect attacks, with configurable port, compression, and encoding options.
Explore other preprocessors in the firepower intrusion prevention system, including sip/rtp inspection, traffic fragmentation handling, email attachment decoding, ssl inspection considerations, and protocol-specific preprocessing (gtp, modbus, back orifice).
Learn clustering and stacking to achieve high availability with active standby, designate a device as active and other as passive, and apply policies to cluster for spillover via ha link.
Configure virtual switches on supported sensors to enable inter-network packet switching via logical interfaces and vlan tags, with static mac entries and optional spanning tree and tcp handshake enforcement.
Configure a virtual router on Sourcefire devices to route traffic between segments, apply security policies and intrusion prevention, and manage layer 3 interfaces, arp entries, static routes, and icmp behavior.
Explore lag interfaces, their types, and how link aggregation control protocol (lacp) negotiates active links, while learning load balancing algorithms, port counts, and policies to optimize redundancy and bandwidth.
Configure hybrid interfaces to bridge traffic between virtual routers and virtual switches, linking layer 2 to layer 3, with icmp options and redundancy protocol settings in Sourcefire Firepower.
Configure Sourcefire vpn gateways using phase one diffie-hellman and phase two sa with rsa authentication to establish encrypted traffic across point-to-point, hub-and-spoke, and mesh deployments.
Learn how to configure NAT policies on a Sourcefire sensor, including static, dynamic, and many-to-one translations, to expose internal servers and hide private addresses with port translation.
This course covers Cisco Sourcefire / Firesight next generation IPS and takes the student into advanced topic that would allow them to understand the solution and prepare for the SSFIPS exam - 500-285
Firepower Threat Defense is not covered in this class; however, information in this class is still valid and applies to firesight configuration and if you are running ASA with SFR module. New class covering FTD will be available soon. You will get an email with a coupon code once the new class is available.
This course covers version 5.4.1
Student needs to have previous knowledge about the terminology of intrusion prevention and detection.
Over 8 hours of video instructions
No material are included with this class.
You should take this course if you are curious about the SourceFire / Firesight / Firepower and want to get familiar with the product or if you want to prepare for the 500-285 exam.
The course progress the student in configuring the product from basics to advanced level and covers theoretical knowledge needed for the exam. Student will gain in-depth understanding on IPS tuning and in-depth configuration topics
Covering Firepower management center and IPS virtual
You get a Certificate Of Completion after finishing this course