FTD Intro

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

Introduction – Key Terminology

These terms are within the context of Firepower Threat Defense.


Term Definition

FTD Firepower Threat Defense – unified software image (ASA + Firepower)

Lina Underlying ASA-derived process that is integrated into the FTD product

Snort Components of the Firepower product integrated into FTD

FMC Firepower Management Center – Off-box GUI used to manage FTD devices
(Configuration, reporting, monitoring, etc.)

FXOS Firepower Extensible Operating System – System that manages the hardware
platforms for Firepower 9300, 4100, and 2100 series products

BRKSEC-2494 © 2020 Cisco and/or its aliates. All rights reserved. Cisco Public 8
Introduction – Key Terminology
These terms are within the context of Performance & Threat Efficacy Testing .
Term Definition

DUT Device Under Test

CPS New connections per Second

Maximum Open Maximum number of concurrent/open connections on device


Connections
IMIX/EMIX Internet Mix or Enterprise traffic consisting of varying packet
sizes, services and applications
Security/Threat Efficacy Security effectiveness, coverage and accuracy

POV or POC Proof of Value/Proof of Concept

BRKSEC-2494 © 2020 Cisco and/or its aliates. All rights reserved. Cisco Public 9
Introduction – What is Firepower Threat
Defense?
• ASA and Firepower
functionality wrapped into a
single, unified image
ASA Firepower
(Lina) (Snort)
• All processes run within single
operating system

• Latest hardware platforms


introduce Firepower Extensible
Operating System (FXOS) as
FTD
FXOS
wrapper around FTD
application
FXOS

BRKSEC-2494 © 2020 Cisco and/or its aliates. All rights reserved. Cisco Public 10
Firepower Threat Defense - Functional Diagram

Platform (Virtual, FPR 1100, 2100, 4100, 9300)

Lina Internal, DMA-based packet transport system


Physical
Layer,
Interface
allocation,
HW
ARP, NAT,
Routing, L3 Snort
redundancy ACLs, TCP
State AppID, URL Filtering, IPS, SSL Decryption, User
Checking Awareness, Geolocation, Security Intelligence

BRKSEC-2494 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 11

You might also like