Cisco · Software · YoctoIT tech page

Secure Firewall

Next-generation firewalling: inspection, IPS and segmentation — the perimeter that sees the applications, not just the ports.

FOCUS · THE PERIMETER THAT UNDERSTANDSApps, users and threats in the same rule: the firewall with Talos intelligence
YoctoIT material for clients and partners · Cisco, Meraki, Splunk, Duo and the other products mentioned are trademarks of Cisco Systems, Inc. or its affiliates.
01 · What it is

Secure Firewall, made clear.

Secure Firewall (Firepower) thinks in applications and users, not just IPs and ports: it recognizes the traffic, inspects it (Snort IPS, malware, TLS), applies policies by identity and blocks what Talos — one of the largest threat intelligences in the world — has already seen elsewhere. From the perimeter to the data center, centrally managed.

Snort 3
the reference IPS, inside: the exploits stopped in transit
Talos
the intelligence that sees billions of events: your firewall knows first
TLS
the inspection of encrypted traffic: where (almost) everything passes by now
Secure Firewall
OFFICIAL CISCO BRANDING · SECURE FIREWALL
CONSOLE REALE · FIREWALL MANAGEMENT CENTER · FONTE: CISCO
REAL CONSOLE · FIREWALL MANAGEMENT CENTER · SOURCE: CISCO
02 · How to use it well

The things that make the difference.

Layered defense

Internet & partnerswhat comes in and goes out
App control
IPS & malware
Decryption
recognize · stop · see
FMC · central managementsingle policies, unified logs
Internal segments & DCeast-west traffic too
The traffic read, not just filtered

Policies cleaned up

The legacy firewall has archaeological rules: the migration is the chance to understand and prune.

Internal segmentation

The perimeter isn't enough: the internal zones (servers, clients, OT) separated and inspected.

Selective decryption

TLS inspected where it counts, excluded where it mustn't be (banking, healthcare): the balance is policy.

Logs to the SIEM

The events in the monitoring flow: the firewall as a sensor, not just as a wall.

03 · In depth

Threat defense: Snort 3, TLS and the firewall that sees

Secure Firewall (FTD) combines stateful firewalling, Snort 3 IPS, malware defense and URL filtering: the policies are written on applications and users (not ports), TLS decryption (selective too, with dedicated hardware on the 4200s) restores visibility on encrypted traffic, Security Intelligence blocks via Talos feeds, management is FMC (on-prem) or cloud (cdFMC); the multithreaded Snort 3 raises the IPS throughput.

  • Snort 3 — the IPS rewritten multithreaded: deep inspection without choking
  • Policy su app/utenti — readable rules on AD and applications: away from the ports
  • TLS decryption — the encrypted inspected where needed: 80% of the traffic becomes visible again
  • Talos — the industry's largest threat intelligence inside every rule
  • FMC/cdFMC — centralized policies for the firewall fleet, on-prem or cloud
  • Clustering — scale and HA by cluster: the firewall that grows with the throughputs
04 · Numbers and lifecycle

The numbers that matter.

650
the Talos analysts behind the feeds
Tbps
the scale of the 4200/9300 clusters
~5 anni
a firewall's life: a refresh to plan
24/7
the policies in our watch: continuous tuning
The firewall is worth as much as its rules: policy migration, selective decryption and IPS tuning — our trade.
05 · Use cases

Where it really pays off.

Corporate perimeters

Internet edge with IPS and application control.

Data center

The segmentation of the critical servers.

Compliance

The control evidence for NIS2 and audits.

The modern firewall is a traffic reader: we configure it so it understands YOURS.