Professional Documents
Culture Documents
BRKSEC-2121 Help, My Firewall Has An Issue. How To Get A Health Alert - 2023
BRKSEC-2121 Help, My Firewall Has An Issue. How To Get A Health Alert - 2023
#CiscoLive
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
• Introduction
• Cisco Secure Firewall Health
Policy – FMC
• Health Evening
• Health Graphs
• Creating Alerts
Introduction
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
How do I Know if my System Working Correctly
Hello, helpdesk?
I can’t get to the
Internet
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco Secure Firewall
Health Policy - FMC
Health Policy Overview on FMC v7.x
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Architectural Overview
• Telegraf health agent is added to collect
specific metrics
• Prometheus collects the metrics from
Telegraf and stores in time series
fashion
• Alerts are generated when values
exceed the user-configured threshold in
the health policy
• Telegraf health agent is an Open-
Source plugin-driven agent for
collecting metrics. It collects data every
1 minute
• Prometheus, an open-source Time
Series Database on FMC, pulls the
metrics from device every 1 minute
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Health Processes
Use pmtool to confirm health processes are running
Steps:
Login to FMC CLI
Switch to Expert mode
Use SUDO SU to change to superuser
Confirm processes
Prometheus
HealthAlertServer
hmdaemon
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Health Modules
Refer to Firewall Management Center Documentation
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Health Modules
Some Metrics Enabled by Default
FMC FTD
Metric Group Name Enabled by default Description Platform
Metric Group
Enabled by default Description
Name Monitors different Chassis parameters like Fan speed, Applicable to only FPR2100
Chassis Status Yes
and temperature. and FPR1000 platforms
CPU No Monitors FMC CPU
Applicable to FPR9300
Flow offload Yes Monitors hardware flow offload statistics
and FPR4100 platforms
Memory Yes Monitors FMC Memory
ASP drops Yes Monitors Lina side packet drops All
Disk Yes Monitors FMC Disk Usage
Hit counts No Monitors hit counts for Access Control Policy Rules All
Event Yes Monitors Event Rate SSE connector status No Monitors SSE cloud connectivity from the FTD All
Sybase No Monitors Sybase Route statistics Yes Monitors Lina side packet drops All
Snort 3 perf stats Yes Monitors certain Snort3 performance statistics (perfstats) All
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Health Policy
System>Health>Policy
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Health Policy
Create Policy
1. Create
Policy
4. Edit
Policy
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Health Policy
Create Policy – Set Thresholds for each Health Module
Assign
Policy to
Device(s)
Turn all alerts on/off
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Health Policy
Apply Policy
1. Apply to
your device(s)
2. Choose
device(s)
3. Apply
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Health Eventing
Health Evening
System>Health>Events
Green ― No alarms
Orange ― At least one health warning
Red ― At least one critical health alarm.
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Health Graphs
Health Monitor 7.x
System>Health>Monitor
Green ― No alarms
Orange ― At least one health warning
Red ― At least one critical health alarm.
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Health Monitor 7.x
Drill into a Monitored Device - FMC
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Health Monitor 7.x
Drill into a Monitored Device - FTD
Health Policy
Thresholds
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Health Monitor 7.x
Drill into a Monitored Device – FMC Troubleshoot
Troubleshooting tools
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Creating Alerts
Health Policy Alerts
Setup alerts to notify you through email, SNMP, or the system log
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Health Policy Alerts
• The alerts generated by the health monitor contain the following information:
• Severity - which indicates the severity level of the alert.
• Module - which specifies the health module whose test results triggered the alert.
• Description - which includes the health test results that triggered the alert.
Severity Description
Critical The health test results met the criteria to
trigger a Critical alert status.
Warning The health test results met the criteria to
trigger a Warning alert status.
Normal The health test results met the criteria to
trigger a Normal alert status.
Error The health test did not run.
Recovered The health test results met the criteria to
return to a normal alert status, following a
Critical or Warning alert status.
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Creating Alert Notifications
Policy>Alerts
Email Alert
Example
Setup email
System>
Configuration>
Email Notification
Create Email,
SNMP or Syslog
alert destinations
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Health Policy Alerts – email example
System>Health>Monitor Alerts
The Threshold Timeout field, enter the number of minutes that should elapse before each threshold
period ends and the threshold count resets.
Even if the policy run time interval value is less than the threshold timeout value, the interval between
two reported health events from a given module is always greater. For example, if you change the
threshold timeout to 8 minutes and the policy run time interval is 5 minutes, there is a 10-minute
interval (5 x 2) between reported events.
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Health Policy Alerts – email example
Email contents
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Health Policy Alerts – syslog example
System>Health>Monitor Alerts
Syslog Events
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Cisco XDR Health
Alert Workflow - FMC
Cisco XDR Dashboard
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
XDR Incident
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Cisco XDR Ribbon
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Cisco XDR Automation
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Cisco XDR Orchestration
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Cisco XDR Automation
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Cisco XDR Automation
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Cisco XDR Automation
FMC Alert to Incident Workflow
Atomic Actions
Atomic Actions
Enter Workflow
Parameters in
this Pane
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Cisco XDR Automation
FMC Alert to Incident Workflow
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Cisco XDR Automaiton
Add a Trigger to
FMC Alert to Incident Workflow run the workflow
on a Schedule
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Cisco XDR – How Communicate with FMC
• FMC + Cisco XDR + SSE Proxy • FMC + Cisco XDR + Remote
• Requires version FMC 7.2+ Appliance
• Requires Device to be registered • Versatile to interact wit other on-
to SSE prem API’s
• Provides a native “built-in” • Requires the deployment of a VM
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Cisco XDR Automation
Setup FMC Credentials
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Cisco XDR Automation
Setup the SSE Proxy as a target to access FMC
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Cisco XDR Automation
Use the Cisco XDR Target to access FMC
Target is a member of
the Default Target Group
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Cisco XDR Automaiton
Get the Health Alerts using the FMC API
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Cisco XDR Automation https://<fmc-ip>/api/api-explorer/
Firepower api-explorer
Path
Test it out
Alert Contents
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Cisco XDR Automation
Setup the Table of Health Alert Items
Setup a table of
Health Alerts
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Cisco XDR Automation
Firepower api-explorer
Response Strings
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Cisco XDR Automation
Set Access to
Cisco XDR
Ribbon
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Cisco XDR Automation
If the Health Alert is Red or Yellow Continue to Create and Incident
Orchestration Logic
While loop and
Conditional Block
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Cisco XDR Automation
Check to see if the Health Incident already exists
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Cisco XDR Automation
Update a Previous Existing Incident
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Cisco XDR Automaiton
Which Device has a Health Alert
Incident is New
UUID=0 is an FMC
UUID is Hostname
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Cisco XDR Automation
Create a New Health Incident
Information Format to
be posted
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Cisco XDR Health
Alert Workflow –
Meraki MX
Meraki MX– email example
Email contents
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
XDR Incident
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Cisco XDR Ribbon
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Cisco XDR Automation
Meraki API Doc https://developer.cisco.com/meraki/api-latest/#!get-network-health-alerts
Path
Test it out
Alert
Contents
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Cisco XDR Automation
Meraki Alert to Incident Workflow
Enter Workflow
Local Variables
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Get Todays
Workflows
Cisco XDR Automation – Import todays workflow
Automate>Options>Git Repositories
Add a Git
Repository
api.github.com/repos/lcammara/SLED-East-TSA-Cisco-SecureX
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Conclusion
What Did We Cover Today
• Cisco Secure Firewall Health Policy – FMC
• Health Evening
• Health Graphs
• Creating Alerts
• Cisco XDR Health Alert Workflow – FMC
• Cisco XDR Health Alert Workflow – Meraki MX
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Fill out your session surveys!
These points help you get on the leaderboard and increase your chances of winning daily and grand prizes
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
• Visit the Cisco Showcase
for related demos
BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Thank you
#CiscoLive
Gamify your Cisco Live experience!
Get points for attending this session!
How:
1 Open the Cisco Events App.
4 Click the + at the bottom of the screen and scan the QR code:
#CiscoLive BRKSEC-2121 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
#CiscoLive