Firepower Threat Defense packet processing

Firepower Threat Defense packet processing

Do you ever have that feeling that the documentation is not technical enough? I do.

I have seen a whole bunch of flowcharts and handmade graphics made to give insights in how a packet traverses the inside of the Firepower Threat Defense. Not two are the same.

Like many others, I also created a flowchart. This time I did not make a simple version. I need a place to lookup every operation of the software in the "rare" case of troubleshooting. What stopped my packet and why can I not see this in the logs? Am I even looking through the right logs?

Actually I have created a chart for FTD and another one for ASA with FirePOWER Services.

Please contact me if you find any of the charts incorrect or missing key components. I will update it when more knowledge is acquired from my part.

Firepower Threat Defense - NGFW mode


Firepower Threat Defense - NGIPS mode


ASA with FirePOWER Services


If you liked this post, please click "Like" so that others can find it.

About: Dennis Perto is an enthusiastic security consultant who places great honour in genuinely humble consulting. He believes in serving the client with expert knowledge, and in not being afraid to admit when he is not the right expert anymore. He enjoys configuring Cisco Firepower for every special need.

Feel free to connect with me here on LinkedIn, and follow me on Twitter: @PertoDK

Steve McNutt

M.S. Cybersecurity | CCIE #6495x2 | CISSP | Cybersecurity Technical Solutions Architect

7 年

Wish i could like this post more than once

回复
Dennis Perto

Leading engineering in the OT SOC | Public speaker | OSCP | CCNP Security | Bitcoin maximalist | OWASP Chapter Leader

7 年

Updates are online, once more. :)

Daniel Larsson

IT Consultant - Network Specialist p? Cygate | #CiscoVIP 2017-2023 | #CiscoChampion 2017-2018 |

7 年

This so Great. Thank you for The Great effort!

Curtis Vermeulen

Senior Network Architect, Team Leader at High Availability, Inc.

7 年

Dennis, apologies if I'm blind but the charts are not showing up for me.

回复
Dennis Perto

Leading engineering in the OT SOC | Public speaker | OSCP | CCNP Security | Bitcoin maximalist | OWASP Chapter Leader

7 年

Edits have been deployed.

要查看或添加评论,请登录

Dennis Perto的更多文章

  • Concluding on my OSCP journey

    Concluding on my OSCP journey

    Some fear the OSCP. Some see the OSCP as an entrance into the penetration testing- or even the IT Security field.

    61 条评论
  • Testing Wazuh at home

    Testing Wazuh at home

    Today I had an hour to spare and decided to test Wazuh. I have heard about OSSEC many years ago but never tried it.

    7 条评论
  • Simple drop box for full network access

    Simple drop box for full network access

    Part 2. Why, How, What, Edit C2, Edit drop box, Full access.

    6 条评论
  • Simple drop box with reverse shell

    Simple drop box with reverse shell

    Part 1. Why, How, What, Create C2, Create drop box, Got shell.

    15 条评论
  • Cisco WLC on QNAP NAS

    Cisco WLC on QNAP NAS

    For a long time I have been looking for a home lab solution for the Cisco Wireless Lan Controller. My QNAP NAS supports…

    3 条评论
  • FirePOWER 8200 and 8300 hardware specs

    FirePOWER 8200 and 8300 hardware specs

    These specs are my personal notes from working with the different appliances. Please tell me if you find any of this…

    5 条评论
  • Looking at the future of Snort

    Looking at the future of Snort

    Differences between Snort 2 and Snort 3 (dubbed Snort++) can be seen in this document on Github. The biggest difference…

    10 条评论
  • Reimage "old" Firepower appliances

    Reimage "old" Firepower appliances

    As you may already know I am working with Cisco Firepower on a daily basis. Not just the new and shiny Firepower 2100…

    15 条评论
  • Honeypot generating blacklists for Cisco Firepower

    Honeypot generating blacklists for Cisco Firepower

    I will iterate through the steps of grabbing data from the log files generated by Heralding to make blacklists on the…

    12 条评论
  • SSL/TLS decryption in Cisco hardware

    SSL/TLS decryption in Cisco hardware

    I am about to write a bit about the problems with decrypting traffic both before and after the year of 2018. I will…

    16 条评论

社区洞察

其他会员也浏览了