Onboarding
Steps:
-
Step 1: Familiarize yourself with the Firepower system
- Task 1: Firepower documentation
- Task 2: Watch Success Tip | Product Overview and Business Value: Cisco Secure Firewall
- Task 3: Watch Success Tip | Getting Started: Cisco Secure Firewall Overview
- Step 2: Document success criteria to keep stakeholders aligned as you move forward
-
Step 3: Familiarize yourself with Smart Licensing
- Task 6: Ensure Smart Licensing has been set up and appropriate users can log in to generate tokens in a later stage
-
Step 4: Gather information on your assets to formulate your network insertion
and policy strategies
- Task 7: Identify workloads and applications, as well as protected IP address subnets/segments/ranges within the data center
-
Step 5: Create your network insertion strategy
- Task 8: Learn about design considerations for the data center and define your physical and logical architecture
- Task 9: Determine if you will use IPS blocking
- Task 10: Learn about deployment modes (routed/transparent) and interface types
- Task 11: Learn about licensing for multi-instance deployments
- Task 12: Understand your high availability and/or clustering requirements
- Task 13: Understand your routing requirements
Implement
Steps
-
Step 1: Understand firewall migration requirements
- Task 1: View the migration tool overview and guides
- Task 2: View the migration tool compatibility guide
- Task 3: Watch Success Tip | Installation / Implementation Best Practices: Post Installation Validation
- Task 4: Watch Success Tip | Migration Strategies and Best Practices: Migration Guidance
- Step 2: Understand design principles of basic access control policies
-
Step 3: Install the solution components including both virtual and physical
- Task 7: 9300 Hardware Install Guide
- Task 8: 4100 Hardware Install Guide
- Task 9: Cisco Secure Firewall Threat Defense Virtual Install and Upgrade Guides
- Task 10: Cisco Firepower Management Center (FMC) Install Guides
- Task 11: Cisco Firepower Management Center (FMC) Virtual Getting Started Guide
- Task 12: Firepower Compatibility Guide
- Task 13: FXOS Compatibility Guide
- Task 14: Software download
-
Step 4: Test Connectivity between the Firewall Management Center to the
managed devices and Cisco
- Task 15: Validate that communication paths are opened between solution components
-
Step 5: Apply the initial bootstrap configurations to system components
based on your design
- Task 16: Cisco Firepower 9300 Getting Started Guide
- Task 17: Cisco Firepower 4100 Getting Started Guide
- Task 18: Cisco Secure Firewall Threat Defense Virtual Getting Started Guide
- Task 19: Cisco Firepower Management Center (FMC) Install Guides
- Task 20: Cisco Secure Firewall Management Center (FMC) Virtual Install Guides
- Task 21: Configure high availability and/or clustering, where required
-
Step 6: Register with Smart Licensing and Activate Licenses
- Task 22: Apply Smart Licensing to managed devices
- Step 7: Ensure telemetry is enabled (Cisco Success Network)
-
Step 8: Enable data interfaces
- Task 24: Define and enable interfaces
- Step 9: Deploy initial configurations for network insertion
-
Step 10: Configure HA and/or Clustering requirements
- Task 28: Deployed high availability and/or clustering, where applicable
-
Step 11: Configure routing requirements
- Task 29: Apply routing where applicable
-
Step 12: Validate the initial setup
- Task 30: Register for a virtual event, available on Cisco Community
- Step 13: Learn about available integrations
Use
Steps: 3 Steps / 13Tasks
-
Step 1: Learn about Network Discovery
- Task 1: Plan how you will leverage Network Discovery
- Task 2: Watch Success Tip | Feature Overview: Advanced Malware Protection
- Task 3: Watch Success Tip | Feature Overview: Threat Intelligence Overview
- Task 4: Watch Success Tip | Feature Overview: Application Detection and URL Policy Brief Overview
- Task 5: Watch Success Tip | Feature Overview: Identity Store Integration Overview for User-Based Policy Decisions
-
Step 2: Learn about Access Control Policy and Threat Intelligence
- Task 6: Plan how you will leverage Access Control Policies
- Task 7: Plan how you will leverage Threat Intelligence features
-
Step 3: Learn about Identity Stores for User Based Policy
- Task 8: Learn about identity stores for user-based policy
-
Step 4: Learn about Advanced Malware Protection
- Task 9: Plan how you will leverage Advanced Malware Protection
-
Step 5: Learn about Intrusion Detection and Prevention
- Task 10: Plan how you will leverage IDS/IPS policies
-
Step 6: Finish planning, creation, and deployment of Data Center Protection
policies
- Task 11: Deploy your policies
-
Step 7: Learn connectivity troubleshooting techniques
- Task 12: Be prepared with tips to test upcoming policies
- Task 13: Troubleshooting best practices
-
Step 8: Discover Firepower dashboards and reports
- Task 14: Discover Firepower dashboards
- Task 15: Discover Firepower reports
Engage
Steps
-
Step 1: Build a firewall rule lifecycle process
- Task 1: Firewall rule lifecycle management
- Task 2: Watch Success Tip | Operations Planning and Best Practices: Turning on Automatic Security Updates and Keeping Policies Updated
- Task 3: Watch Success Tip | Operations Planning and Best Practices: Initial Policy Tuning
- Task 4: Watch Success Tip | Advanced Feature Overview: SSL Inspection and TLS Decryption Overview
- Step 2: Set up operational monitoring
-
Step 3: Initial tuning of false positives and security feature related
policies
- Task 8: Tuning intrusion policies
-
Step 4: Learn about TLS decrypt and its deployment strategy
- Task 9: Understanding TLS traffic decryption
- Step 5: Continue your deployment
Adopt
Steps
-
Step 1: Enable Automatic Security Updates
- Task 1: Turn on automatic security updates
- Task 2: Deploy policies with security updates to managed services
- Task 3: Watch Success Tip | ROI Assessment Best practices: NGFW
-
Step 2: Discover APIs and their uses
- Task 4: Confirm usage and strategy for APIs
- Task 5: Watch Success Tip | Adapting to Changes: Cisco Secure Firewall
- Step 3: Perform your first health check and rule tuning
Comments
0 comments
Please sign in to leave a comment.