Devwks 1420

Download as pdf or txt
Download as pdf or txt
You are on page 1of 31

Introduction to DevNet

Sandbox Security
Environments

Joseph Kearns, Application Engineer, Cisco DevNet


@jtkearns01

DEVWKS-1420
Cisco Webex Teams

Questions?
Use Cisco Webex Teams to chat
with the speaker after the session

How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda

• Introduction
• What is DevNet Sandbox?
• Security Terminology
• Security Sandbox Overview
• Reserve an FMC/Splunk sandbox
• Exercises
• FMC REST API Explorer and Postman (Always On)
• Splunk with FMC (Private)

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
DevNet Sandbox: What is it?

• Free access to preconfigured Cisco environments.


• API integration, development and test
• Multiple Datacentres
• Fully Private & Public URL Access
• Software and Hardware VPN Access.
• API hello world code examples / quick start guides / videos / documentation
• 50k Users and 25k Companies
• Powering Learning Labs
• Support forum

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Portal Walkthrough
Cisco Security Terminology

• ASA (filtering, NAT, VPN etc.)


• Acquisition of Sourcefire 2013
• Firepower (2100, 4110, virtual), snort engine (IPS), AMP
• Firepower + ASA = Firepower Threat Defence (FTD)
• NGFW - Deep packet inspection, malware, threat focused
• FTD has option of on-board management (FDM)
• Firepower Management Center (FMC)
• When FTD is FMC Managed, no GUI & no REST API

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
DevNet Sandbox security Portfolio

• FMC & Splunk


• pxGrid 2.0
• FMC REST API
• FTD REST API Standalone Sandbox
• Project Joy
• Identity Services Engine with MUD
• Cisco Stealthwatch
• Firepower 4110 Single/Clustered Chassis

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
FMC & Splunk

• Private Lab Environment


• Showcases FMC -> Splunk Integration
• FMC 6.3, FTD 6.3, Splunk, Ansible
• Generate 10k events on FTD
• eStreamer API (FMC) and eNcore client (Splunk)
• Capture and Display intrusion events on Splunk

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Reserve Splunk Sandbox
pxGrid 2.0

• Platform Exchange Grid 2.0


• ISE publishes real-time contextual information
• Context Sharing: who, what, when, devices, users etc. Partners subscribe to topic
• Dynamic Topics: Partners can share their own Info. pxGrid acts as a broker
• Adaptive Network Control: Take action on violation. Quarantine, port shutdown

• pxGrid 2.0 released with REST API over Stomp


• Sandbox has standalone ISE 2.4 with pxGrid enabled
• ISE preloaded with 802.1x authentications/failures
• Users can subscribe to topics and pull information

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
FTD Standalone Sandbox

• Firepower Threat Defense 6.5


• Not FMC connected
• Ubuntu DevBox Included
• Load FDM (Firepower Device Manager)
• FTD REST API Explorer
• Jared Smith (TME)

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Project Joy

• Joy: Open source package for capturing and analyzing network flow
• Specializes in analyzing Encrypted traffic
• Analyses .pcap or real time interface. Outputs JSON
• TLS usage commonplace and increasing in Malware
• Detect Cypher suites on Clients
• Offered/selected cipher suites.
• % probability that payload is Malware
• Uses machine learning to train the Joy application

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
MUD

• Manufacturers Usage Description


• An approach to IoT security
• A way for a device to state:
• What type of device is this
• What network policies should be applied to it

• Use DCHP broadcast to publish a URL


• URL pointing to a MUD file
• MUD file defines network access to controller
• https://www.genisyslighting.com/files/MUD/79590001A4.json

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
StealthWatch

• Comprehensive Security solution


• Enterprise wide network visibility
• Leverages NetFlow to detect threats
• Machine learning classifiers and Encrypted Traffic Analysis
• Eliminates Blind spots from the network
• Set up and monitor traffic in the sandbox
• REST APIs

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
FMC REST API Sandbox

• Hybrid” Sandbox. Static Servers but requires reservation


• FMC 6.3 with two Devices (FTD and NGFW)
• Access to FMC API Explorer URL
• Play with the API
• Exercise 1

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Exercise 1: FMC
REST API
FMC REST API

1. Access FMC REST API Sandbox


2. Open URL for API explorer
3. Open Postman (collection already provided)
4. Generate access token
5. Make rest API call to list policies
6. Make API call to find server version

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Exercise 2: Splunk Sandbox
FMC – Splunk

1. Access running reservation through portal


2. Open output window and copy VPN info
3. Connect to Lab network with Anyconnect
4. Open FMC GUI -> Intrusion events = 90k
5. Generate Events on FTD -> button on portal
6. Notice Intrusion events number increasing to 100k events
7. Goto Splunk GUI and see incoming events displayed

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Questions
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.

Cisco Live sessions will be available for viewing on


demand after the event at ciscolive.com.

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Continue your education

Demos in the
Walk-In Labs
Cisco Showcase

Meet the Engineer


Related sessions
1:1 meetings

DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Thank you

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy