Presentation is loading. Please wait.

Presentation is loading. Please wait.

NGIPS Refresh. © 2018 Cisco and/or its affiliates. All rights reserved. Identify the Refresh Opportunity Cisco IPS Cisco/IBM Alliance IBM exiting IPS.

Similar presentations


Presentation on theme: "NGIPS Refresh. © 2018 Cisco and/or its affiliates. All rights reserved. Identify the Refresh Opportunity Cisco IPS Cisco/IBM Alliance IBM exiting IPS."— Presentation transcript:

1 NGIPS Refresh

2 © 2018 Cisco and/or its affiliates. All rights reserved. Identify the Refresh Opportunity Cisco IPS Cisco/IBM Alliance IBM exiting IPS market Cisco recommended replacement EoS announced Dec 2018 EoS June 2019 7000, 8000 Series Appliances End of Support/EOL No signature updates No TAC support Cisco 4000 Series ASA IPS IBM Base FirePOWER IPS Former SourceFIRE

3 © 2018 Cisco and/or its affiliates. All rights reserved. Have the Conversation Competitive TakeoutRefresh/MigrationCisco/IBM Alliance Engage IBM AMs QRadar + Firepower + Talos Soft bundle Move fast; Fortinet, Trend and PAN are ! NGIPS defends against targeted attacks with customized Snort signatures Firepower NGIPS openness/automation/ flexibility beats competition Appeal to SecOps and SOC owners $500M+ EoL/EoS product One click bookmark 2X performance Deployment flexibility Compliance mandates drive refresh Install BaseIBM Base McAfee, Trend

4 © 2018 Cisco and/or its affiliates. All rights reserved. Why Cisco for NGIPS replacement? Cisco Firepower NGIPS Market Leader EoS Creates New Opportunities Innovations Industry Leader, IDPS Gartner MQ 2018 Recommended multiple years by NSS Labs for NGIPS, NGFW, Breach Detection and Breach Prevention Systems $500M+ opportunity from IBM and Cisco End of Sales IBM endorses Cisco NGIPS as replacement solution Talos Security Intelligence fastest to protect against cyber threats Advanced Malware Protection (AMP) integration Threat Intelligence Director to ingest 3rd party threat feeds

5 © 2018 Cisco and/or its affiliates. All rights reserved. Why position dedicated NGIPS appliances? Large deployments require greater IPS throughput on dedicated appliances Fail-to-wire provides increased uptime and network reliability Provides optimal security operations with threat visibility and policy control Cisco NGIPS can be deployed behind any existing Firewall PerformanceResiliencyBuilt for Sec Ops

6 © 2018 Cisco and/or its affiliates. All rights reserved. Why position NGFW as IPS replacement? Device consolidation at small/branch offices: lower costs Unified approach: reduced complexity, lower mgmt overhead, Performance with granular policy control ensures network resiliency Firepower NGFW unifies Firewall and NGIPS protection into single FTD software image Cost benefits Less administration Built for NetOps

7 © 2018 Cisco and/or its affiliates. All rights reserved. Firepower 9300, 4100 and 2100: dedicated NGIPS appliance or NGFW Cisco Firepower is NGIPS platform for the future

8 © 2018 Cisco and/or its affiliates. All rights reserved. Firepower Portfolio Firepower 2100 Series Firepower 4100 Series Firepower 9300 Security Appliance Internet edge, high-performance enterprise environments Firewall throughput and threat inspection from 20 to 60 gigabytes NGIPS, Stateful firewall, AVC, AMP, URL filtering, DDoS (Radware vDP) Internet edge to small data center environments. Better security, more visibility Firewall throughput and sustained performance with threat inspection from 2.0 to 8.5 gigabytes NGIPS, Stateful firewall, AVC, AMP, URL filtering Service provider, data center Firewall throughput up to 225 gigabytes and threat inspection up to 90 gigabytes NGIPS, Firewall, AVC, AMP, URL filtering, DDoS (Radware vDP)

9 © 2018 Cisco and/or its affiliates. All rights reserved. End of Life process = Revenue Opportunity

10 © 2018 Cisco and/or its affiliates. All rights reserved. Advanced threats drive refresh

11 © 2018 Cisco and/or its affiliates. All rights reserved. Reasons for End of Life Process EOL Reasons will vary due to a number of factors including : Market Requirements Availability of Manufacturing Components Evolution of Technology Introduction of Newer Products with Added Features and Functionality

12 © 2018 Cisco and/or its affiliates. All rights reserved. FirePOWER 7000/8000 EoS Announced Important Dates: Announcement – Dec 2018 End of Sale - June 2019 End of Support – June 2024

13 © 2018 Cisco and/or its affiliates. All rights reserved. 2022 2019 2018 FirePOWER 7000 and 8000 EoS Timeline December 2018 Announcing 7/8K EoL June 10, 2019 LAST DATE to order HW and 5 Yr. license June 2020 End of Maintenance June 2021 EOS 3 Yr. Subscription 2020 2021 June 2022 End of Software and Signature support June 2024 End of Support

14 © 2018 Cisco and/or its affiliates. All rights reserved. NGIPS Appliances Moving Forward The following are suggested replacements: FirePOWER 7050 7110 7120 7125 Firepower 2100 Series

15 © 2018 Cisco and/or its affiliates. All rights reserved. NGIPS Appliances Moving Forward The following are suggested replacements: FirePOWER 7150 Firepower 4100 Series

16 © 2018 Cisco and/or its affiliates. All rights reserved. Appliances Moving Forward The following are suggested replacements: FirePOWER 8350 8360 8370 8390 Firepower 9300 Series

17 © 2018 Cisco and/or its affiliates. All rights reserved. ASA 5512-X and ASA 5515-X Important Dates: End of Life Announced - February 2017 End of Sale – August 2017 End of Support – August 2022

18 © 2018 Cisco and/or its affiliates. All rights reserved. ASA 5506-X and ASA 5512-X Firepower Threat Defense / Firepower Services Last Supported Version – 6.2.3 Current Version – 6.3.0 (Released Late 2018)

19 © 2018 Cisco and/or its affiliates. All rights reserved. Fully End of Life No TAC support No signature support Cisco Legacy IPS

20 © 2018 Cisco and/or its affiliates. All rights reserved. IBM Exits IPS Market = Cisco Opportunity

21 © 2018 Cisco and/or its affiliates. All rights reserved. IBM exited the IPS market Dec 2017. No longer sells QRadar Network Security (XGS) Cisco Firepower NGIPS is IBM recommended replacement Cisco/IBM collaboration partnership Cisco Security products fully integrated with QRadar (SIEM) Collaboration between Talos and IBM X-Force threat intelligence IBM Announcement

22 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco and QRadar SIEM Together Leverage integration to drive migration from XGS to Firepower Sense Analytics ™ WatsonAdvanced analytics for threat prevention, detection, and response Prioritized incidents Ingest Cisco threat telemetry Apply Analytics & Watson AI engine Identify & Prioritize Capture & classify threats for faster response

23 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Firepower App for QRadar: Advanced and Persistent Threats Asset Database Fully Qualified Event Network Behaviour Analytics IP/URL/DNS Threat Intelligence Cognitive Analysis Firepower intrusion, advanced threat, or IoC event happens against high profile asset Firepower “Impact Assessment” determines asset is vulnerable to this attack and sends a Severity 1 event to QRadar Network analytics detects abnormal behaviour Firepower detects outbound connection to a known ‘bad’ site based on IP, URL or DNS threat intelligence Watson reveals wider campaign, Malware other IOCs INCIDENT ALERT Complimentary solution Single, real-time attack view Business driven prioritization Cognitive analysis Comprehensive investigation

24 © 2018 Cisco and/or its affiliates. All rights reserved. XGS to FTD Migration Tool- Windows software Significantly lowers the risk; competition doesn’t allow visibility due to closed detection logic

25 © 2018 Cisco and/or its affiliates. All rights reserved. Selling Aids

26 © 2018 Cisco and/or its affiliates. All rights reserved. Selling Tools Field Guide Use case Website Competitive table BDM/TDM FireJumper Migration Incentive Program (MIP) Security Ignite Account Breakaway ContentPromos/Offers Proof of Value (POV) Center of Excellence

27 © 2018 Cisco and/or its affiliates. All rights reserved. up to 60 % Base Program Additional 4% Deal Level Incentive +2 VIP Bonus Kicker +4% +2 VIP Bonus Kicker Does Deal Qualify for MIP? 1 3 Always Register Deals Customer Must agree to destroy or return HW *Replaced legacy TMP (MIP Applies to HW, SW, and Service) Competitive Accelerator Additional 1% Deal Level Incentive Competitive Accelerator Additional 1% Deal Level Incentive Technology Offers SKU Level Incentives 5585 -> 41xx +8% WSA, ESA, SMA +10% Technology Offers SKU Level Incentives 5585 -> 41xx +8% WSA, ESA, SMA +10% New Deal Registration & How Migration Stacks on Top Account Breakaway New / Competitive or Upgrade / Reactivate + +1% Partners with Registered Bookings Often Achieve 20% - 35% GPM + + Migration Incentive Program* +2 VIP Bonus Kicker 2 Define Deal Details New Account / Competitive or Upgrade/Reactivate

28 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Firepower NGIPS Info Web page Video – Superior Threat ProtectionSuperior Threat Protection Video – Power of VisibilityPower of Visibility Video – Automation | Correlation | IntegrationAutomation | Correlation | Integration Messaging – InternalInternal NSS DCIPS response – InternalInternal IBM Info Sales Connect Security Tab Landing page for IBM customers Landing page Cisco Firepower NGFW Web page Where to Find More Information Competitive: McAfee battlecard (internal) McAfee battlecard Trend Micro battlecard (internal) Trend Micro battlecard Competitive comparison table (public) Competitive comparison table

29 © 2018 Cisco and/or its affiliates. All rights reserved. Opportunity Summary $500M+ iRevenue Opportunity from IPS Refresh, plus services $$ Maintain account control – Keep competition out Establish backdoor into lost FW deals (PAN, FORT, CKPT) Firepower platform enables future sales: (AMP, NGFW, or NGIPS)

30

31 © 2018 Cisco and/or its affiliates. All rights reserved. Capabilities & Migration Details

32 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco NGIPS Feature Differentiation Visibility See what other IPS solutions cannot Operational Cost Do more with less overhead expense Efficacy Industry leading research, threat intelligence from Talos / Dynamic threat handling from AMP Flexibility Deploy the IPS appliance the way you want Integration Seamlessly navigate between your security solutions

33 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco NGIPS efficacy advantage is growing larger in today’s dynamic and dangerous world Efficacy is Dynamic Customization Automated rules and security intelligence Time to detect & retrospective analysis High-fidelity events TalosAMP Threat Grid SNORT rules Open App ID CTID Talos FMC

34 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Talos Threat Intelligence Backed by Talos – Industry Best Security Intelligence Talos has 250+ threat researchers and analysts on the front lines of cybersecurity: See 1.5 unique malware samples per day vs. 10s of thousands each for competitors Block 19.7 billion threats per day Scan 600 billion email messages per day Monitor 16 billion web requests per day Automated security intelligence feeds update Cisco NGFW every 2 hours, adjustable to 5-minute interval Unmatched, timely threat intelligence blocks zero-day threats first

35 © 2018 Cisco and/or its affiliates. All rights reserved. Capabilities and Capacities Firepower 2100 Model FP2100 2110212021302140 Throughput: FW+AVC+IPS 1024B 2.0 Gbps3.0 Gbps4.75 Gbps8.5 Gbps Max Concurrent Sessions w/AVC 1M1.2M2M3M Max New Connections/ Sec 12K16K24K40K IPSec VPN Throughput 750 Mbps1 Gbps1.5 Gbps3 Gbps Maximum VPN Peers 15003500750010000 Firepower 2100 Series Note: Includes Local Management with FDM

36 © 2018 Cisco and/or its affiliates. All rights reserved. Capabilities and Capacities Firepower 4100 Model FP4100 4110412041404150 Throughput: FW+AVC+IPS 1024B 10 Gbps15 Gbps20 Gbps24 Gbps Max Concurrent Sessions w/AVC 9M15M25M30M Max New Connections/ Sec 68K120K160K200K IPSec VPN Throughput 6 Gbps10 Gbps13 Gbps14 Gbps Maximum VPN Peers 100001500020000 Firepower 4100 Series

37 © 2018 Cisco and/or its affiliates. All rights reserved. Capabilities and Capacities Firepower 9300 Model – FP9300 1 SM-24 Module 1 SM-36 Module 1 SM-44 Module 3 SM-44 Module Throughput: FW+AVC+IPS 1024B 24 Gbps34 Gbps53 Gbps133 Gbps Max Concurrent Sessions w/AVC 30M 60M Max New Connections/ Sec 120K160K300K900K IPSec VPN Throughput 13.5 Gbps16 Gbps17 Gbps51 Gbps Maximum VPN Peers 20000 60000 Firepower 9300 Series

38 © 2018 Cisco and/or its affiliates. All rights reserved. Inline vs Passive HA Failover Downtime? Visibility Network Communication Deployment considerations: Migrating NGIPS/NGFW

39 © 2018 Cisco and/or its affiliates. All rights reserved. NGIPS and NGFW Tuning Once the new NGIPS/NGFW is in place remember these tuning steps: Rationalize rule sets and streamline or optimize where appropriate Utilize variables and variable sets Implement Firepower Recommendations For additional information: http://cisco.lookbookhq.com/ngfw_ftd_common-practices/ngfw-ftd-policy-mgmt

40 © 2018 Cisco and/or its affiliates. All rights reserved. FirePOWER (SourceFIRE)Cisco Firepower FirePOWER 8350Firepower 9300 SM 44 FirePOWER 8360Firepower 9300 SM 44 – 3 Blade Cluster FirePOWER 8370Firepower 9300 SM 44 – 4 Blade Cluster FirePOWER 8390Firepower 9300 SM 36 – 6 Blade Cluster FirePOWER 8120Firepower 4110 FirePOWER 8130Firepower 4110 FirePOWER 8140Firepower 4120 FirePOWER 7050Firepower 2130 FirePOWER 7110Firepower 2130 FirePOWER 7115Firepower 2130 FirePOWER 7120Firepower 2130 FirePOWER 7125Firepower2130 FirePOWER Migration Matrix

41 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Legacy IPSCisco Firepower IPS 4520-XLFirepower 4140 IPS 4520Firepower 4120 IPS 4510Firepower 4110 IPS 4360Firepower 4110 IPS 4345Firepower 4110 IPS 4270Firepower 4110 IPS 4260Firepower 2130 IPS 4255Firepower 2120 IPS 4240Firepower 2120 IPS 4215Firepower 2110 Cisco Legacy IPS Migration Matrix

42 © 2018 Cisco and/or its affiliates. All rights reserved. *IBM Inspection performance includes the base performance and licensable performance upgrades IBM XGS Migration to Firepower NGIPS IBM XGSInspection Performance*Cisco Migration ProductPerformance (IPS/AVC)Cisco Advantages XGS 3100 L1: 400Mbps L2: 800Mbps ASA5508-5516-X running FTD 600Mbps - 1.2Gbps Leader in the 2017 Gartner IPS MQ High security effectiveness as reported in the NSS Labs Breach and IPS tests (2016) Malware identification and detection with Cisco AMP for Networks Sandboxing technology with Cisco Threat Grid Integrated Network Discovery and Host Mapping Automated Impact Assessment Automated Rule Recommendations Higher performance (up to 60Gbps) IPS with the 8300 series appliances ASA hardware appliances running FTD support NGIPS deployments and easy migration to NGFW XGS 4100 L1: 750Mbps L2: 1.5Gbps ASA5516-X running FTD FPR2110 1.2 Gbps 2 Gbps XGS 5100 L1: 2.5Gbps L2: 4Gbps L3: 5Gbps L4: 7Gbps FPR2100 Series FPR4100 Series 2-8.5 Gbps 10-24 Gbps XGS 5200 L1: 3Gbps L2: 6Gbps L3: 12Gbps L4: 15Gbps FPR2100 Series FPR4100 Series 2-8.5 Gbps 10-24 Gbps XGS 7100 L1: 5Gbps L2: 10Gbps L3: 15Gbps L4: 20Gbps L5: 25Gbps FPR4100 Series10-24 Gbps

43 © 2018 Cisco and/or its affiliates. All rights reserved. IBM GX Migration to Firepower NGIPS IBM GXInspection PerformanceCisco Migration ProductPerformance (IPS/AVC)Cisco Advantages GX4004-200 GX4004 GX5008 Up to 200Mbps Up to 800Mbps Up to 1.5Gbps ASA5508-5516-X running FTD FPR2110 600 Mbps – 1.2 Gbps 2 Gbps Leader in the 2017 Gartner IPS MQ High security effectiveness as reported in the NSS Labs Breach and IPS tests (2016) Malware identification and detection with Cisco AMP for Networks Sandboxing technology with Cisco Threat Grid Integrated Network Discovery and Host Mapping Automated Impact Assessment Automated Rule Recommendations Higher performance (up to 60Gbps) IPS with the 8300 series appliances ASA hardware appliances running FTD support NGIPS deployments and easy migration to NGFW GX5108Up to 2.5Gbps FPR2110 FPR2120 2 Gbps 3 Gbps GX5208Up to 4Gbps FPR2130 FPR2140 5 Gbps 8.5 Gbps GX7412-5Up to 5Gbps FPR2130 FPR2140 5 Gbps 8.5 Gbps GX7412-10Up to 10Gbps FPR4110 FPR4120 10 Gbps 15 Gbps GX7412Up to 15Gbps FPR4120 FPR4140 FPR9300-SM24 15 Gbps 20 Gbps 24 Gbps GX7800Up to 20Gbps FPR4140 FPR4150 FPR9300-SM24 20 Gbps 24 Gbps

44 © 2018 Cisco and/or its affiliates. All rights reserved. IBM XGS Migration to Firepower NGFW IBM GXInspection Performance*Cisco Migration Product Performance (IPS/AVC) Cisco Advantages XGS 3100 L1: 400Mbps L2: 800Mbps ASA5508-5516-X running FTD 600 Mbps – 1.2 Gbps High security effectiveness as reported in the NSS Labs Breach (2016) and NGFW (2017) tests Malware identification and detection with Cisco AMP for Networks Sandboxing technology with Cisco Threat Grid Integrated Network Discovery and Host Mapping Automated Impact Assessment Automated Rule Recommendations Higher performance inspection capabilities with the FPR9300 Rich NGFW feature set XGS 4100 L1: 750Mbps L2: 1.5Gbps ASA5516-X running FTD FPR2110 1.2 Gbps 2 Gbps XGS 5100 L1: 2.5Gbps L2: 4Gbps L3: 5Gbps L4: 7Gbps FPR2100 NGFW series2-8.5 Gbps XGS 5200 L1: 3Gbps L2: 6Gbps L3: 9Gbps L4: 12Gbps FPR2100 NGFW series FPR4110 FPR4120 2-8.5 Gbps 10 Gbps 15 Gbps XGS 7100 L1: 5Gbps L2: 10Gbps L3: 15Gbps L4: 20Gbps L5: 25Gbps FPR2140 FPR4100 NGFW series FPR9300 NGFW series 8.5 Gbps 10-24 Gbps 24-53 Gbps *IBM Inspection performance includes the base performance and licensable performance upgrades

45 © 2018 Cisco and/or its affiliates. All rights reserved. IBM XGS Migration to Firepower NGFW IBM GXInspection Performance*Cisco Migration ProductPerformance (IPS/AVC)Cisco Advantages GX4004-200 GX4004 GX5008 Up to 200Mbps Up to 800Mbps Up to 1.5Gbps ASA5508-5516-X running FTD FPR2110 600 Mbps – 1.2 Gbps 2 Gbps High security effectiveness as reported in the NSS Labs Breach (2016) and NGFW (2017) tests Malware identification and detection with Cisco AMP for Networks Sandboxing technology with Cisco Threat Grid Integrated Network Discovery and Host Mapping Automated Impact Assessment Automated Rule Recommendations Higher performance inspection capabilities with the FPR9300 Rich NGFW feature set GX5108Up to 2.5Gbps FPR2110 FPR2120 2 Gbps 3 Gbps GX5208Up to 4Gbps FPR2130 FPR2140 5 Gbps 8.5 Gbps GX7412-5Up to 5Gbps GX7412-10Up to 10Gbps FPR4100 NGFW Series FPR9300 NGFW Series 10-24 Gbps 24-53 Gbps GX7412Up to 15Gbps GX7800Up to 20Gbps

46 © 2018 Cisco and/or its affiliates. All rights reserved. Start Over with Clean Policy Migration Services from Cisco Migrations Services from IBM Migration Services from other partners DIY with Migration Tool Migration Paths

47 © 2018 Cisco and/or its affiliates. All rights reserved. FTD and NGIPS are functionally different platforms than XGS and there is merit in allowing Cisco’s Next Gen platforms do what they do best Passive identification of devices to tune policies uniquely to the environment optimizes policy rather than consuming compute for policies that never be touched (Better resource usage – reduction in overhead) Less labor and maintenance related to tuning of policies: Balanced policy feed from TALOS ~9.5k rules that’d otherwise have to be maintained manually (Big win for customers)  much easier to just add a few custom rules We see this option working most often when in a Cisco led deal with a customer PoC/PoV to show off FTD features Starting Over with Clean Policies (1 st Choice)

48 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco is working with Lanooka on a tool to speed up migrations for customers moving from XGS > FTD that want to retain their existing policies Allows customers to match existing XGS signatures to CVEs and then import into FTD via a secondary script The migration tool is currently in test, but the expectations are that it could offload about 50-60% of the effort during the migration activity IBM to Cisco Migration Tool Overview


Download ppt "NGIPS Refresh. © 2018 Cisco and/or its affiliates. All rights reserved. Identify the Refresh Opportunity Cisco IPS Cisco/IBM Alliance IBM exiting IPS."

Similar presentations


Ads by Google