protegendo sua rede

17
Protegendo sua Rede Sergio Dias Systems Engineer CCIE DC #47837 Fabiane Paulino Consulting Systems Engineer

Upload: cisco-do-brasil

Post on 17-Feb-2017

278 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Protegendo sua rede

Protegendo sua Rede

Sergio Dias Systems Engineer CCIE DC #47837

Fabiane Paulino Consulting Systems Engineer

Page 2: Protegendo sua rede

Legacy  Security:  Costly  &  Complex  

Siloed  

Inefficient  

Manual  

Limited  integra,on,  security  gaps  

Hard-­‐coded  processes  

Over-­‐provisioned,  sta,c  and  slow  

•  $  400  Millions  the  es?mated  financial  loss  in  2015  with  breachs  

•  98%  stemmed  from  External  Agents    •  81%  u?lized  some  form  of  Hacking  •  69%  incorporated  Malware    •  96%  of  aPacks  Not  Highly  Difficult  

     

*  Verizon  2015  Data  Breach  Inves?ga?on  Report    

 

Page 3: Protegendo sua rede

Cisco’s  Threat-­‐Centric  Security  Model  

Network   Endpoint   Mobile   Virtual   Cloud  

DURING Detect Block

Defend

AFTER Scope

Contain Remediate

BEFORE Discover Enforce Harden

Advanced  Malware  Protec?on  VPN  Firewall   NGIPS   DDoS  

Policy  Management  Applica?on  Control  

Secure Access + Identity Services

Malware  Sandboxing  Web  Security  

Email  Security   Network  Behavior  Analysis  

Security  Services  

Page 4: Protegendo sua rede

4 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Corp Network

Global Orchestration

Page 5: Protegendo sua rede

5 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Corporate HQ

Partners Guests

...

Page 6: Protegendo sua rede

6 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Branches / Home Office

Page 7: Protegendo sua rede

7 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Partners Guests

Network Security Challengers Distributed Network, Compliance and Control

Grant and Control access to Corporate Devices, Guests Devices and BYOD Devices.

Compliance.

Borderless network (wireless, wired and VPN) keeping the same level of access and control. Distributed network (Datacenter, Stores and Remote Locations, HQ and Remote Users).

Employees ...

Grant and Control access to Employees, Partners and Guests.

Compliance.

Keep track and have visibility over all users, devices, applications and vulnerabilities on the network.

Protect the network against security events and advanced threats.

Page 8: Protegendo sua rede

8 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Access Control Consistent Secure Access Policy Across Wired, Wireless and VPN

Guests

BYOD Corporate and Partners

SSID: Guest

SSID: Corporate

Authentication Users and Devices

Cisco ISE

Onboarding (Portals)

Access Enforcement

Traffic Analysis

AD, LDAP, RADIUS or Local Database

Rest API

Full Reports

Corporate

Corporate and Partners

Corporate and Partners How

What Who

Where When

Page 9: Protegendo sua rede

9 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Cisco pxGrid Context Sharing

FirePower NGIPS

ASA and ASA with FP Services

Stealth Watch WSA

FirePower Threat Defense

Cisco ISE

pxGrid

User Identity User, Location IP,

Device Type and SGT Tag

Page 10: Protegendo sua rede

10 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

FirePower and ISE Integration Fire&ISE pxGrid

Page 11: Protegendo sua rede

11 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

WSA and ISE Integration WSA&ISE pxGrid

Page 12: Protegendo sua rede

12 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Corp Network

Global Orchestration

Page 13: Protegendo sua rede

13 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

New Features

Sourcefire FirePOWER

Cisco ASA

Converged Software – Firepower Threat Defense (FTD)

Page 14: Protegendo sua rede

14 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Total Visibility

Web

WWW

Endpoints Network Email Mobile

Cloud

FTD - Centralized Management Web, Multi-Tenant, Full Visibility

Page 15: Protegendo sua rede

15 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Corp Network

Global Orchestration

Page 16: Protegendo sua rede

16 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Q&A

Page 17: Protegendo sua rede

17 © 2015 Cisco and/or its affiliates. All rights reserved. Cisco Confidential

Thank you!!