policy / SaaS controlmanagement (OOB)telemetry / logsidentity context (pxGrid / RADIUS)
Cisco Security Cloud (SaaS control plane)
platformSecurity Cloud ControlcdFMC · CDO · change requests
Cloud manager for FTD/ASA/Meraki/Multicloud Defense. Depends on: Security Cloud Sign On, outbound 443 from devices.
identityDuoMFA · SSO · Device Trust · Passwordless
Policy engine for user+device trust. On-prem shims: Auth Proxy (RADIUS/LDAP), Network Gateway (ZTNA). DoD → Duo Federal (IL4). Feeds Identity Intelligence.
SSESecure Access / UmbrellaZTNA · SWG · CASB · DLP · DNS · FWaaS · RBI
Cloud PoPs enforce for remote users and branches. Depends on: Secure Client ZTA/Umbrella modules, IPsec tunnels from FTD/SD-WAN, Resource Connectors in DCs, Umbrella VAs for internal IP attribution.
EDRSecure EndpointAMP · Orbital · isolation
Connector on hosts; verdicts from Talos + Secure Malware Analytics. Private Cloud appliance for air-gap. Feeds ISE TC-NAC, XDR, Duo Trusted Endpoints.
sandboxSecure Malware AnalyticsThreat Grid
Dynamic analysis for FTD, ESA/WSA, Endpoint, Umbrella, Meraki. Appliance for on-prem.
XDRCisco XDRcorrelation · attack chains · automation
Consumes Endpoint, FMC, SNA, ISE (pxGrid Cloud), Duo, Email, Umbrella + 3rd party. Pushes response to ISE ANC, FMC, Endpoint, Umbrella, Duo.
SIEMSplunk ES / SOAR / Attack Analyzersystem of record
eStreamer, ISE syslog/pxGrid, SNA, Duo, Umbrella, Endpoint add-ons. SOAR playbooks call ISE ANC, FMC SI lists, Duo lock.
intelTalosrules · reputation · IR
Pushes Snort/ClamAV rules, IP/URL/domain/file reputation to every product. Air-gap: SRU/VDB/profiler bundles by sneakernet.
ITDRIdentity IntelligenceOort
Analyzes Duo/Entra/Okta/AD/Secure Access for dormant accounts, MFA gaps, impossible travel.
vulnVulnerability ManagementKenna
Risk-based prioritization from Tenable/ACAS, Qualys, Defender. Feeds ISE TC-NAC, Secure Workload.
AIAI Defensemodel validation · runtime guardrails
Discovers AI assets, red-teams models, enforces guardrails inline via Multicloud Defense / Hypershield / Secure Access AI Access. ISO 42001 / EU AI Act evidence.
cloud FWMulticloud DefenseValtix
NGFW/WAF/egress gateways in AWS/Azure/GCP/OCI managed from SCC.
NDRSecure Cloud AnalyticsStealthwatch Cloud
VPC flow-log NDR for public cloud; on-prem sensors optional.
DEMThousandEyesExperience Insights
Endpoint/enterprise agents; embedded in Secure Access and Secure Client.
Untrust — Internet · attackers · remote users · branches
Remote userSecure Client: VPN · NAM · ZTA · Umbrella · Endpoint · ISE Posture · NVM
Single agent carrying every module. Always-On + TND for DoD. Auth via FTD SAML → Duo; posture via ISE.
Branch / SD-WANCatalyst 8K · Meraki MX · UTD/Snort · Umbrella SIG
IPsec to DC FTD and to Secure Access PoPs; local Enterprise Firewall + Snort IPS; Meraki Adaptive Policy = SGT.
Partners / CloudS2S VTI · Multicloud Defense
Route-based IKEv2 VTIs; dynamic objects from cloud attributes connector.
DDoSSecure DDoS Edge/Cloud (Radware)
Scrubbing in front of FTD outside interface.
Attacker (lab: Kali)traffic gen · IPS validation
Drives Snort/IPS, EVE, SI feeds, SNA detections in the lab.
Enforcement edge — Secure Firewall (ASA / FTD) HA pair or cluster
FTD data plane (Lina)stateful · NAT · routing · VPN · HA/cluster
Three arms: outside (untrust), dmz, inside (trust) + OOB mgmt. Failover links dedicated.
Snort 3IPS · malware · URL · AVC · SI · EVE · TLS decrypt
Talos rules via SRU; EVE fingerprints TLS without decrypting; selective decrypt policy.
Identity policySGT / user via ISE pxGrid
FTD learns SGT↔IP + user↔IP from ISE; rules written on users/groups/SGTs.
Remote Access VPNSAML → Duo · IKEv2/SSL · posture
CNSA suites; Secure Client posture via ISE or HostScan; dACL/SGT authorization from ISE.
Zero-Trust App Policyclientless ZTNA on FTD 7.4+
Publishes internal web apps with SAML IdP; alternative to DNG for on-prem.
DMZ — screened services and connectors
Secure Email Gateway (ESA)MTA · anti-spam · AMP · DLP · DMARC · encryption
Cluster of 2+; LDAP recipient validation in trust; sandbox to Secure Malware Analytics.
Secure Web Appliance (WSA)proxy · URL · AMP · decrypt · ICAP DLP
WCCP from FTD/core or explicit; identity from ISE/AD; reports to SMA.
Duo Network GatewayZTNA reverse proxy
Docker host publishing web/SSH/RDP with Duo policy.
Secure Access Resource Connectoroutbound tunnel to PoPs
2+ per DC; no inbound ports; exposes private apps to ZTA clients.
Splunk HF / syslog relaylog once, route many
Fans out eStreamer/syslog/pxGrid to Splunk ES, XDR, archive.
External DNS · OCSP/CRLpublished PKI
Needed by remote Secure Client cert auth and partners.
Trust — campus · data center · management
ISE (PAN · MnT · PSN · pxGrid)802.1X · MAB · posture · profiling · TrustSec · TACACS+
The PDP. Depends on AD/LDAP, PKI (EAP-TLS + OCSP), NTP, DNS. Exports context to FMC, SNA, Workload, Splunk, XDR. DoD C2C engine.
Catalyst 9K / WLCNAD · SGT inline · MACsec · NetFlow/ETA
RADIUS to PSNs (server groups, dead time); SXP where no inline tagging; NetFlow to Flow Collector.
Nexus / ACI · N9300 Smart Switchcontracts · ESG · DPU (Hypershield)
ACI↔ISE SGT exchange; Hypershield DPU enforcement for east-west.
Secure Workloadapp dependency map · micro-seg · CVE
Agents on VMs/K8s; enforces host firewall or pushes to FMC/ACI; ISE + Catalyst Center connectors.
Isovalent Cilium / TetragonK8s CNI · runtime · Hypershield agent
eBPF enforcement in Kubernetes; Hubble telemetry; basis for Hypershield software agents.
Secure Network AnalyticsManager · Flow Collector · Sensor · UDP Director · Data Store
NDR from NetFlow/ETA/NVM/FTD events; ISE quarantine via ANC; on-prem SAL.
Umbrella Virtual ApplianceDNS forwarder pair
Adds internal IP/AD identity to DNS policy.
Duo Authentication ProxyRADIUS/LDAP shim
Fronts AD for FTD/ASA VPN, ISE, TACACS+, RDP. Pair behind LB. failmode=secure for DoD.
AD / PKI / NTP / DNSfoundation
Everything depends on these. Two-tier CA, OCSP HA, CNSA key sizes, authenticated NTP.
SMAemail/web reporting & quarantine
Central config/reporting for ESA/WSA.
Workloads · clientsSecure Endpoint · Secure Client · agents
Segmented by SGT/VLAN; posture-checked; telemetry via NVM.
Cyber Vision / SEAOT / ICS
Sensors on IE switches; OT asset inventory to ISE profiling.
OOB management VLAN (jump host · CAC/PIV · Duo)
FMC (HA pair / cdFMC)policy · events · Talos updates · Change Mgmt
sftunnel 8305 to FTDs; FIPS/CC; CAC via LDAPS/SAML; syslog to Splunk; size for 2× events.
Catalyst CenterSD-Access · AI Endpoint Analytics
3-node cluster in production; pairs with ISE for VN/SGT.
SD-WAN ManagervManage · vSmart · vBond
Controls branch security policy (ZBFW, UTD, SIG).
Splunk indexers / SHES · SOAR
Indexer cluster RF3/SF2; SH cluster 3; 365-day retention.
SSM On-Premair-gap licensing
Smart Licensing satellite; or SLR/PLR per device.
Secure Endpoint Private Cloud · SMA applianceair-gap EDR / sandbox
For classified enclaves with no SaaS.
Ansible / Terraform · Gitcisco.fmcansible · cisco.ise
Policy as code; FMC Change Management for approvals.
How each flow works
1 · Campus access (Comply-to-Connect)
- Secure Client NAM does
EAP-TLSwith DoD PKI cert → switch → ISE PSN - ISE checks AD group + OCSP → authorizes VLAN + dACL +
SGTvia CoA - ISE Posture module reports AV/patch/encryption; non-compliant → remediation SGT
- Switch exports NetFlow/ETA → Flow Collector → SNA baseline
- pxGrid publishes session to FMC, SNA, Secure Workload, Splunk
2 · Remote access (VPN or ZTNA)
- Secure Client → FTD RA VPN →
SAML→ Duo SSO (MFA + Device Trust) - FTD asks ISE for authorization + posture → dACL/SGT
- OR: ZTA module → Secure Access PoP → Resource Connector → app (no VPN)
- DNS via Umbrella; web via SWG/CASB/DLP; files to Malware Analytics
3 · East-west segmentation
- Macro: zones/VRFs/VNs on FTD and fabric
- Micro: SGACL matrix from ISE enforced on 9K/FTD; ACI contracts in DC
- Workload: Secure Workload discovers flows → simulates → enforces host policy
- K8s: Cilium network policy + Tetragon runtime; Hypershield shadow-tests then enforces
4 · Detect → correlate → contain
- Talos pushes rules/reputation to FTD, ESA, WSA, Umbrella, Endpoint, SNA
- Events via eStreamer/syslog/pxGrid → Splunk ES + XDR
- XDR builds attack chain; ES raises risk-based notable
- SOAR/XDR automation → ISE
ANC quarantine, FMC SI block, Endpoint isolate, Umbrella block, Duo lock - Talos IR retainer for human response
5 · Email & web
- MX → ESA cluster (DMZ): reputation, anti-spam, AMP, Outbreak, DLP, encryption
- ETD watches M365 via API for BEC/ATO
- Users → WSA (WCCP) or Secure Access SWG: URL, AMP, decrypt, DLP
- Reports to SMA; logs to Splunk
6 · Dependency order to build
NTP → DNS → PKI (OCSP) → AD- Smart Licensing (SSM On-Prem / SLR)
- Splunk/syslog target
- FMC → FTD · ISE PAN/MnT → PSN → switches
- Duo Auth Proxy · Umbrella VA · Resource Connector
- SNA · Workload · XDR integrations
Lab build-outs — 3 zones
Untrust
- Kali attacker
- Client moves here to test RA VPN
DMZ
- (FTDv dmz arm only)
Trust
- FTDv (3 arms)
- FMCv (OOB)
- ISE all-in-one
- AD DS + AD CS + DNS + NTP
- Win11 + Secure Client
~18 vCPU / 66 GB. Optional: Duo Auth Proxy, CML IOSvL2 for 802.1X.
Untrust
- Kali
- ASAv outside
DMZ
- ESAv
- WSAv
- Duo Network Gateway
- Secure Access Resource Connector
Trust
- FTDv edge · FMCv (OOB) · ASAv
- ISE PAN+MnT · ISE PSN/pxGrid
- Cat8000v/IOSvL2 NAD
- AD DS/DNS/NTP · AD CS Sub CA + OCSP
- Duo Auth Proxy · Umbrella VA · SMAv
- SNA Manager · Flow Collector
- Splunk single + Cisco add-ons
- RHEL workload (Secure Workload agent / K3s+Cilium)
- Win11 client (all modules) · RHEL jump host
SaaS tenants: Duo, Secure Access/Umbrella, Secure Endpoint, Malware Analytics, XDR, Vuln Mgmt. ~70 vCPU / 220 GB.
Untrust
- Kali
DMZ
- Tier 2 DMZ set
Trust (adds)
- FTDv #2 — Active/Standby w/ failover link
- FMCv #2 — FMC HA
- ISE split: PAN-P · PAN-S+MnT-S · MnT-P · PSN×2 node group
- F5 VE / HAProxy for PSN RADIUS LB
- Duo Auth Proxy #2
- 2nd NAD (SXP, server groups)
- Splunk 2 indexers + 1 SH
HA only where the failover mechanism is the lesson. ~95 vCPU / 300 GB.
Untrust
- Kali · simulated ISP
DMZ (adds)
- ESAv #2 cluster · WSAv #2 WCCP
- Resource Connector #2
- Splunk HF
Trust (adds)
- FTDv cluster ×3 (DC role)
- ISE 2+2+4 across two "sites"
- SNA Manager secondary · FC #2 · UDP Director · Data Store ×3
- Secure Endpoint Private Cloud (air-gap)
- SSM On-Prem
- Splunk indexer cluster ×3 · SH cluster ×3 · CM/deployer
- Umbrella VA #2 · 2nd AD DC · 2nd OCSP
- RKE2/K3s ×3 with Cilium/Hubble/Tetragon
- Catalyst Center (optional, 32 vCPU/256 GB)
DC-grade ops + accreditation patterns. ~200 vCPU / 640 GB.
Untrust
- Kali
DMZ
- (OPNsense dmz arm)
Trust
- OPNsense + Suricata (3 NICs)
- PacketFence ZEN
- Samba AD + step-ca
- Wazuh all-in-one
- Client
Untrust
- Kali
DMZ
- strongSwan/WireGuard VPN
- Pomerium / OpenZiti (ZTNA)
- Squid + c-icap + SquidGuard (SWG)
- Proxmox Mail Gateway
Trust
- OPNsense + Suricata edge
- PacketFence · FreeRADIUS + tac_plus-ng
- Keycloak + privacyIDEA (SSO/MFA)
- Samba AD/FreeIPA · EJBCA/Dogtag + OCSP
- Pi-hole + Unbound
- Zeek + Arkime sensor
- Wazuh + OpenSearch
- TheHive + Cortex + MISP + Shuffle
- K3s + Cilium/Hubble/Tetragon + CAPEv2
- Clients
Untrust
- Kali
DMZ (adds)
- PMG pair
- HAProxy/keepalived VIPs
Trust (adds)
- OPNsense CARP pair
- PacketFence A/P cluster
- FreeRADIUS pair behind HAProxy
- Keycloak ×2 + shared PostgreSQL
- OpenSearch ×3 · Wazuh manager ×2
- Zeek ×2 sensors
- 2nd Samba DC · 2nd OCSP
- K3s ×3 Cilium cluster mesh
Compliance map
DISA STIG/SRG ASA · FTD/FMC · ISE · IOS-XE/NX-OS · ESA · NDM/FW/IDPS/VPN/ALG SRGs
FIPS 140-3 FIPS mode on every appliance · Duo FIPS
CNSA 1.0→2.0 AES-256-GCM · SHA-384 · P-384 · RSA-3072+ · IKEv2 CNSA
NIST 800-207 / DoD ZT 7 pillars ISE+Duo PDP · FTD/switch/client PEP · SNA/XDR CDM
NIST 800-53 r5 AC AU CA CM IA IR SC SI RA
800-171 / CMMC L2 CUI enclave = Tier 2+
FedRAMP Duo Federal · Umbrella · Splunk GovCloud · verify XDR/Secure Access
Vanta 38 SOC 2 · ISO 27001/17/18/701 · CJIS · HIPAA/HITRUST · GDPR · PCI DSS 4.0 · CSF 2.0 · DORA · NIS 2 · ISO 42001 · EU AI Act (AI Defense) · Custom