Features
Benefits
- Get up and running in minutes with our AWS Quick Starts or Infrastructure-as-a-Code (IaaC) scripts
- Deploy policy controls consistently regardless of if you are on-premises or in the cloud
- Scale up your firewall capacity automatically with AWS Auto Scaling support
- Deeper visibility into QUIC and TLS 1.3 encrypted traffic without breaking Layer 7 policies or compliance
- Quickly boot up or recover your virtual firewalls with snapshot support
- Firewall clustering for highly available threat defense
- Return on investment in less than 12 months
Stronger security against a new generation of threats
Cisco Secure Firewall Threat Defense Virtual helps drive stronger security by seeing more, detecting faster, and streamlining operations. It combats complexity with consistent policy enforcement, promotes visibility and control with deep packet inspection, as well as ingress and egress traffic inspection — all within a virtualized form factor.
Superior threat defense
Protect your hybrid and multicloud environment against known and unknown threats with advanced threat defense options including malware defense and URL filtering. And with the Snort 3 IPS, you can obtain hourly threat intelligence updates from Cisco Talos, enabling faster inspection without slowing down your network.
Greater visibility
Secure Firewall’s Encrypted Visibility Engine protects against malicious applications embedded in encrypted traffic, maintains Layer 7 policies on encrypted traffic, and delivers insights into application behavior. Only Cisco is addressing this critical concern for networking and security professionals, 65% of whom reported loss of IPS and Layer 7 efficacy with new protocols like TLS 1.3 and QUIC.
Dynamic policy management
Reduce policy maintenance and complexity in the cloud with dynamic attribute support for AWS tags. As workloads spin up and down in your AWS environment, your organization can keep policies current without redeploying with dynamic objects.
Specifications:
Accelerate incident response with Cisco SecureX
Cut incident response time by 70% with Cisco SecureX, our open security platform included with every Cisco Secure Firewall. It accelerates the time to detect, investigate, and remediate threats by aggregating and correlating global intelligence and local context in one centralized view. SecureX also integrates with Amazon GuardDuty to monitor your AWS accounts and workloads for malicious activity.
| Advanced capabilities |
Details |
| Introduce AWS services for added benefits |
- Combine with AWS Gateway Load Balancer to dynamically insert scalable security into your AWS environment and reduce complexity.
- Leverage Amazon Route 53 for remote access VPN.
- Integrate with AWS Transit Gateway for scalable inter-VPC traffic.
|
| Transport Layer Security (TLS) Server Identity and Discovery |
- Enables you to maintain Layer 7 policies on encrypted TLS 1.3 traffic. Maintain visibility and control in an encrypted world where it’s not realistic to decrypt and inspect every single traffic flow. Competing firewalls break your Layer 7 policies with encrypted TLS 1.3 traffic.
|
| Firewall clustering |
- Combine multiple firewalls into a single logical firewall for ease of management and performance scale.
- Laterally scale your virtual firewall deployments with predictable performance.
|
| Cisco Security Analytics and Logging |
- Highly scalable on-premises and cloud-based firewall log management with behavioral analysis for real-time threat detection and faster response times. Plus, continuous analysis to further refine your security posture to better defend against future attempts.
- Meet your compliance needs with log aggregation across all Cisco Secure Firewalls.
- Tight integration with firewall managers for extended logging and analysis, as well as aggregating firewall log data in a single intuitive view.
|
| Cisco Talos threat intelligence |
- Cisco Talos Intelligence Group is one of the largest commercial threat intelligence teams in the world. They create accurate, rapid and actionable threat intelligence for Cisco customers, products and services. Talos maintains the official rulesets of Snort.org, ClamAV, and SpamCop.
|