Cisco Security — how everything ties together

Security Cloud on top (identity, intelligence, analytics, SaaS controls) · three security zones underneath · enforcement points at the edges · telemetry flowing back up. Hover any product card for what it does and what it depends on.

policy / SaaS controlmanagement (OOB)telemetry / logsidentity context (pxGrid / RADIUS)

Cisco Security Cloud (SaaS control plane)

platformSecurity Cloud ControlcdFMC · CDO · change requests
Cloud manager for FTD/ASA/Meraki/Multicloud Defense. Depends on: Security Cloud Sign On, outbound 443 from devices.
identityDuoMFA · SSO · Device Trust · Passwordless
Policy engine for user+device trust. On-prem shims: Auth Proxy (RADIUS/LDAP), Network Gateway (ZTNA). DoD → Duo Federal (IL4). Feeds Identity Intelligence.
SSESecure Access / UmbrellaZTNA · SWG · CASB · DLP · DNS · FWaaS · RBI
Cloud PoPs enforce for remote users and branches. Depends on: Secure Client ZTA/Umbrella modules, IPsec tunnels from FTD/SD-WAN, Resource Connectors in DCs, Umbrella VAs for internal IP attribution.
EDRSecure EndpointAMP · Orbital · isolation
Connector on hosts; verdicts from Talos + Secure Malware Analytics. Private Cloud appliance for air-gap. Feeds ISE TC-NAC, XDR, Duo Trusted Endpoints.
sandboxSecure Malware AnalyticsThreat Grid
Dynamic analysis for FTD, ESA/WSA, Endpoint, Umbrella, Meraki. Appliance for on-prem.
XDRCisco XDRcorrelation · attack chains · automation
Consumes Endpoint, FMC, SNA, ISE (pxGrid Cloud), Duo, Email, Umbrella + 3rd party. Pushes response to ISE ANC, FMC, Endpoint, Umbrella, Duo.
SIEMSplunk ES / SOAR / Attack Analyzersystem of record
eStreamer, ISE syslog/pxGrid, SNA, Duo, Umbrella, Endpoint add-ons. SOAR playbooks call ISE ANC, FMC SI lists, Duo lock.
intelTalosrules · reputation · IR
Pushes Snort/ClamAV rules, IP/URL/domain/file reputation to every product. Air-gap: SRU/VDB/profiler bundles by sneakernet.
ITDRIdentity IntelligenceOort
Analyzes Duo/Entra/Okta/AD/Secure Access for dormant accounts, MFA gaps, impossible travel.
vulnVulnerability ManagementKenna
Risk-based prioritization from Tenable/ACAS, Qualys, Defender. Feeds ISE TC-NAC, Secure Workload.
AIAI Defensemodel validation · runtime guardrails
Discovers AI assets, red-teams models, enforces guardrails inline via Multicloud Defense / Hypershield / Secure Access AI Access. ISO 42001 / EU AI Act evidence.
cloud FWMulticloud DefenseValtix
NGFW/WAF/egress gateways in AWS/Azure/GCP/OCI managed from SCC.
NDRSecure Cloud AnalyticsStealthwatch Cloud
VPC flow-log NDR for public cloud; on-prem sensors optional.
DEMThousandEyesExperience Insights
Endpoint/enterprise agents; embedded in Secure Access and Secure Client.
policy / SAML / RADIUS-MFA (Duo) IPsec tunnels + ZTA (Secure Access) eStreamer · syslog · NetFlow · NVM · pxGrid Cloud EDR + identity context

Untrust — Internet · attackers · remote users · branches

Remote userSecure Client: VPN · NAM · ZTA · Umbrella · Endpoint · ISE Posture · NVM
Single agent carrying every module. Always-On + TND for DoD. Auth via FTD SAML → Duo; posture via ISE.
Branch / SD-WANCatalyst 8K · Meraki MX · UTD/Snort · Umbrella SIG
IPsec to DC FTD and to Secure Access PoPs; local Enterprise Firewall + Snort IPS; Meraki Adaptive Policy = SGT.
Partners / CloudS2S VTI · Multicloud Defense
Route-based IKEv2 VTIs; dynamic objects from cloud attributes connector.
DDoSSecure DDoS Edge/Cloud (Radware)
Scrubbing in front of FTD outside interface.
Attacker (lab: Kali)traffic gen · IPS validation
Drives Snort/IPS, EVE, SI feeds, SNA detections in the lab.

Enforcement edge — Secure Firewall (ASA / FTD) HA pair or cluster

FTD data plane (Lina)stateful · NAT · routing · VPN · HA/cluster
Three arms: outside (untrust), dmz, inside (trust) + OOB mgmt. Failover links dedicated.
Snort 3IPS · malware · URL · AVC · SI · EVE · TLS decrypt
Talos rules via SRU; EVE fingerprints TLS without decrypting; selective decrypt policy.
Identity policySGT / user via ISE pxGrid
FTD learns SGT↔IP + user↔IP from ISE; rules written on users/groups/SGTs.
Remote Access VPNSAML → Duo · IKEv2/SSL · posture
CNSA suites; Secure Client posture via ISE or HostScan; dACL/SGT authorization from ISE.
Zero-Trust App Policyclientless ZTNA on FTD 7.4+
Publishes internal web apps with SAML IdP; alternative to DNG for on-prem.

DMZ — screened services and connectors

Secure Email Gateway (ESA)MTA · anti-spam · AMP · DLP · DMARC · encryption
Cluster of 2+; LDAP recipient validation in trust; sandbox to Secure Malware Analytics.
Secure Web Appliance (WSA)proxy · URL · AMP · decrypt · ICAP DLP
WCCP from FTD/core or explicit; identity from ISE/AD; reports to SMA.
Duo Network GatewayZTNA reverse proxy
Docker host publishing web/SSH/RDP with Duo policy.
Secure Access Resource Connectoroutbound tunnel to PoPs
2+ per DC; no inbound ports; exposes private apps to ZTA clients.
Splunk HF / syslog relaylog once, route many
Fans out eStreamer/syslog/pxGrid to Splunk ES, XDR, archive.
External DNS · OCSP/CRLpublished PKI
Needed by remote Secure Client cert auth and partners.

Trust — campus · data center · management

ISE (PAN · MnT · PSN · pxGrid)802.1X · MAB · posture · profiling · TrustSec · TACACS+
The PDP. Depends on AD/LDAP, PKI (EAP-TLS + OCSP), NTP, DNS. Exports context to FMC, SNA, Workload, Splunk, XDR. DoD C2C engine.
Catalyst 9K / WLCNAD · SGT inline · MACsec · NetFlow/ETA
RADIUS to PSNs (server groups, dead time); SXP where no inline tagging; NetFlow to Flow Collector.
Nexus / ACI · N9300 Smart Switchcontracts · ESG · DPU (Hypershield)
ACI↔ISE SGT exchange; Hypershield DPU enforcement for east-west.
Secure Workloadapp dependency map · micro-seg · CVE
Agents on VMs/K8s; enforces host firewall or pushes to FMC/ACI; ISE + Catalyst Center connectors.
Isovalent Cilium / TetragonK8s CNI · runtime · Hypershield agent
eBPF enforcement in Kubernetes; Hubble telemetry; basis for Hypershield software agents.
Secure Network AnalyticsManager · Flow Collector · Sensor · UDP Director · Data Store
NDR from NetFlow/ETA/NVM/FTD events; ISE quarantine via ANC; on-prem SAL.
Umbrella Virtual ApplianceDNS forwarder pair
Adds internal IP/AD identity to DNS policy.
Duo Authentication ProxyRADIUS/LDAP shim
Fronts AD for FTD/ASA VPN, ISE, TACACS+, RDP. Pair behind LB. failmode=secure for DoD.
AD / PKI / NTP / DNSfoundation
Everything depends on these. Two-tier CA, OCSP HA, CNSA key sizes, authenticated NTP.
SMAemail/web reporting & quarantine
Central config/reporting for ESA/WSA.
Workloads · clientsSecure Endpoint · Secure Client · agents
Segmented by SGT/VLAN; posture-checked; telemetry via NVM.
Cyber Vision / SEAOT / ICS
Sensors on IE switches; OT asset inventory to ISE profiling.

OOB management VLAN (jump host · CAC/PIV · Duo)

FMC (HA pair / cdFMC)policy · events · Talos updates · Change Mgmt
sftunnel 8305 to FTDs; FIPS/CC; CAC via LDAPS/SAML; syslog to Splunk; size for 2× events.
Catalyst CenterSD-Access · AI Endpoint Analytics
3-node cluster in production; pairs with ISE for VN/SGT.
SD-WAN ManagervManage · vSmart · vBond
Controls branch security policy (ZBFW, UTD, SIG).
Splunk indexers / SHES · SOAR
Indexer cluster RF3/SF2; SH cluster 3; 365-day retention.
SSM On-Premair-gap licensing
Smart Licensing satellite; or SLR/PLR per device.
Secure Endpoint Private Cloud · SMA applianceair-gap EDR / sandbox
For classified enclaves with no SaaS.
Ansible / Terraform · Gitcisco.fmcansible · cisco.ise
Policy as code; FMC Change Management for approvals.

How each flow works

1 · Campus access (Comply-to-Connect)

  1. Secure Client NAM does EAP-TLS with DoD PKI cert → switch → ISE PSN
  2. ISE checks AD group + OCSP → authorizes VLAN + dACL + SGT via CoA
  3. ISE Posture module reports AV/patch/encryption; non-compliant → remediation SGT
  4. Switch exports NetFlow/ETA → Flow Collector → SNA baseline
  5. pxGrid publishes session to FMC, SNA, Secure Workload, Splunk

2 · Remote access (VPN or ZTNA)

  1. Secure Client → FTD RA VPN → SAML → Duo SSO (MFA + Device Trust)
  2. FTD asks ISE for authorization + posture → dACL/SGT
  3. OR: ZTA module → Secure Access PoP → Resource Connector → app (no VPN)
  4. DNS via Umbrella; web via SWG/CASB/DLP; files to Malware Analytics

3 · East-west segmentation

  1. Macro: zones/VRFs/VNs on FTD and fabric
  2. Micro: SGACL matrix from ISE enforced on 9K/FTD; ACI contracts in DC
  3. Workload: Secure Workload discovers flows → simulates → enforces host policy
  4. K8s: Cilium network policy + Tetragon runtime; Hypershield shadow-tests then enforces

4 · Detect → correlate → contain

  1. Talos pushes rules/reputation to FTD, ESA, WSA, Umbrella, Endpoint, SNA
  2. Events via eStreamer/syslog/pxGrid → Splunk ES + XDR
  3. XDR builds attack chain; ES raises risk-based notable
  4. SOAR/XDR automation → ISE ANC quarantine, FMC SI block, Endpoint isolate, Umbrella block, Duo lock
  5. Talos IR retainer for human response

5 · Email & web

  1. MX → ESA cluster (DMZ): reputation, anti-spam, AMP, Outbreak, DLP, encryption
  2. ETD watches M365 via API for BEC/ATO
  3. Users → WSA (WCCP) or Secure Access SWG: URL, AMP, decrypt, DLP
  4. Reports to SMA; logs to Splunk

6 · Dependency order to build

  1. NTP → DNS → PKI (OCSP) → AD
  2. Smart Licensing (SSM On-Prem / SLR)
  3. Splunk/syslog target
  4. FMC → FTD · ISE PAN/MnT → PSN → switches
  5. Duo Auth Proxy · Umbrella VA · Resource Connector
  6. SNA · Workload · XDR integrations

Lab build-outs — 3 zones

Untrust
  • Kali attacker
  • Client moves here to test RA VPN
DMZ
  • (FTDv dmz arm only)
Trust
  • FTDv (3 arms)
  • FMCv (OOB)
  • ISE all-in-one
  • AD DS + AD CS + DNS + NTP
  • Win11 + Secure Client

~18 vCPU / 66 GB. Optional: Duo Auth Proxy, CML IOSvL2 for 802.1X.

Untrust
  • Kali
  • ASAv outside
DMZ
  • ESAv
  • WSAv
  • Duo Network Gateway
  • Secure Access Resource Connector
Trust
  • FTDv edge · FMCv (OOB) · ASAv
  • ISE PAN+MnT · ISE PSN/pxGrid
  • Cat8000v/IOSvL2 NAD
  • AD DS/DNS/NTP · AD CS Sub CA + OCSP
  • Duo Auth Proxy · Umbrella VA · SMAv
  • SNA Manager · Flow Collector
  • Splunk single + Cisco add-ons
  • RHEL workload (Secure Workload agent / K3s+Cilium)
  • Win11 client (all modules) · RHEL jump host

SaaS tenants: Duo, Secure Access/Umbrella, Secure Endpoint, Malware Analytics, XDR, Vuln Mgmt. ~70 vCPU / 220 GB.

Untrust
  • Kali
DMZ
  • Tier 2 DMZ set
Trust (adds)
  • FTDv #2 — Active/Standby w/ failover link
  • FMCv #2 — FMC HA
  • ISE split: PAN-P · PAN-S+MnT-S · MnT-P · PSN×2 node group
  • F5 VE / HAProxy for PSN RADIUS LB
  • Duo Auth Proxy #2
  • 2nd NAD (SXP, server groups)
  • Splunk 2 indexers + 1 SH

HA only where the failover mechanism is the lesson. ~95 vCPU / 300 GB.

Untrust
  • Kali · simulated ISP
DMZ (adds)
  • ESAv #2 cluster · WSAv #2 WCCP
  • Resource Connector #2
  • Splunk HF
Trust (adds)
  • FTDv cluster ×3 (DC role)
  • ISE 2+2+4 across two "sites"
  • SNA Manager secondary · FC #2 · UDP Director · Data Store ×3
  • Secure Endpoint Private Cloud (air-gap)
  • SSM On-Prem
  • Splunk indexer cluster ×3 · SH cluster ×3 · CM/deployer
  • Umbrella VA #2 · 2nd AD DC · 2nd OCSP
  • RKE2/K3s ×3 with Cilium/Hubble/Tetragon
  • Catalyst Center (optional, 32 vCPU/256 GB)

DC-grade ops + accreditation patterns. ~200 vCPU / 640 GB.

Untrust
  • Kali
DMZ
  • (OPNsense dmz arm)
Trust
  • OPNsense + Suricata (3 NICs)
  • PacketFence ZEN
  • Samba AD + step-ca
  • Wazuh all-in-one
  • Client
Untrust
  • Kali
DMZ
  • strongSwan/WireGuard VPN
  • Pomerium / OpenZiti (ZTNA)
  • Squid + c-icap + SquidGuard (SWG)
  • Proxmox Mail Gateway
Trust
  • OPNsense + Suricata edge
  • PacketFence · FreeRADIUS + tac_plus-ng
  • Keycloak + privacyIDEA (SSO/MFA)
  • Samba AD/FreeIPA · EJBCA/Dogtag + OCSP
  • Pi-hole + Unbound
  • Zeek + Arkime sensor
  • Wazuh + OpenSearch
  • TheHive + Cortex + MISP + Shuffle
  • K3s + Cilium/Hubble/Tetragon + CAPEv2
  • Clients
Untrust
  • Kali
DMZ (adds)
  • PMG pair
  • HAProxy/keepalived VIPs
Trust (adds)
  • OPNsense CARP pair
  • PacketFence A/P cluster
  • FreeRADIUS pair behind HAProxy
  • Keycloak ×2 + shared PostgreSQL
  • OpenSearch ×3 · Wazuh manager ×2
  • Zeek ×2 sensors
  • 2nd Samba DC · 2nd OCSP
  • K3s ×3 Cilium cluster mesh

Compliance map

DISA STIG/SRG ASA · FTD/FMC · ISE · IOS-XE/NX-OS · ESA · NDM/FW/IDPS/VPN/ALG SRGs FIPS 140-3 FIPS mode on every appliance · Duo FIPS CNSA 1.0→2.0 AES-256-GCM · SHA-384 · P-384 · RSA-3072+ · IKEv2 CNSA NIST 800-207 / DoD ZT 7 pillars ISE+Duo PDP · FTD/switch/client PEP · SNA/XDR CDM NIST 800-53 r5 AC AU CA CM IA IR SC SI RA 800-171 / CMMC L2 CUI enclave = Tier 2+ FedRAMP Duo Federal · Umbrella · Splunk GovCloud · verify XDR/Secure Access Vanta 38 SOC 2 · ISO 27001/17/18/701 · CJIS · HIPAA/HITRUST · GDPR · PCI DSS 4.0 · CSF 2.0 · DORA · NIS 2 · ISO 42001 · EU AI Act (AI Defense) · Custom