Devwks 1420
Devwks 1420
Devwks 1420
Sandbox Security
Environments
DEVWKS-1420
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda
• Introduction
• What is DevNet Sandbox?
• Security Terminology
• Security Sandbox Overview
• Reserve an FMC/Splunk sandbox
• Exercises
• FMC REST API Explorer and Postman (Always On)
• Splunk with FMC (Private)
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
DevNet Sandbox: What is it?
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Portal Walkthrough
Cisco Security Terminology
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
DevNet Sandbox security Portfolio
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
FMC & Splunk
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Reserve Splunk Sandbox
pxGrid 2.0
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
FTD Standalone Sandbox
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Project Joy
• Joy: Open source package for capturing and analyzing network flow
• Specializes in analyzing Encrypted traffic
• Analyses .pcap or real time interface. Outputs JSON
• TLS usage commonplace and increasing in Malware
• Detect Cypher suites on Clients
• Offered/selected cipher suites.
• % probability that payload is Malware
• Uses machine learning to train the Joy application
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
MUD
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
StealthWatch
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
FMC REST API Sandbox
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Exercise 1: FMC
REST API
FMC REST API
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Exercise 2: Splunk Sandbox
FMC – Splunk
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Questions
Complete your
online session
survey • Please complete your session survey
after each session. Your feedback
is very important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (starting on Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events
Mobile App or by logging in to the Content
Catalog on ciscolive.com/emea.
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
DEVWKS-1420 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Thank you