Cisco Secure Firewall Management Center
Combine the power of Secure Workload with the power of Cisco Secure Firewall (formerly known as Cisco Firepower) for a security solution that makes use of:
-
Segmentation
Firewall-based segmentation is suitable for workloads where software agents are not installed. However, you can also use this method for agent-based workloads. You can easily and broadly apply different sets of policies for traffic entering your network, for traffic exiting your network, and for traffic between workloads within your network.
-
Virtual Patching
Virtual patching adds Cisco Intrusion Prevention System (IPS) protection to workloads where software agents are installed. You can use virtual patching rules to protect your application from malicious traffic. You can create virtual patching rules by filtering the most critical vulnerabilities in your workloads using Cisco Security Risk Score or CVSS V2 or V3 scores and the corresponding attributes. After virtual patching is configured on Secure Workload, the Common Vulnerabilities and Exposures (CVEs) are published to Cisco Secure Firewall for consideration while creating the IPS policies.
With this integration, Secure Workload automatically enforces and manages segmentation policies on the Secure Firewall Threat Defense (formerly known as Firepower Threat Defense) firewalls managed by the Secure Firewall Management Center instance. Policies are updated dynamically, and the set of workloads to which policies apply is refreshed continually as the application environment changes.
Network inventory is dynamically updated by Secure Workload inventory filters on which your segmentation policies are based; when workloads are added, changed, or removed from your network, Secure Workload automatically updates the Dynamic Objects in the Secure Firewall Management Center on which the corresponding access control rules are based. All enforced policy changes are automatically deployed to managed Secure Firewall Threat Defense (formerly known as Firepower Threat Defense or FTD) devices; you never need to redeploy changes in Secure Firewall Management Center.
For complete information about this integration, including more details about how it works, supported platforms, limitations, setup instructions for both products, and troubleshooting information, see Cisco Secure Workload and Cisco Secure Firewall Management Center Integration Guide.