<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC Insider Threat/Malware Detection Across the LAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490094#M1084548</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1262961"&gt;@davsnet2000&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;I agree. The test they should be running is from a standard (lockdown) port, with all the standard restrictions. Your bosses would get a better understanding of your network security that way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer your question, you could use Secure Network Analytics (previously called StealthWatch) that could monitor for abnormal or malicous traffic on the LAN (for traffic that doesn't transit the firewalls).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en_uk/products/security/stealthwatch/index.html" target="_blank"&gt;https://www.cisco.com/c/en_uk/products/security/stealthwatch/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2021 18:14:54 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-10-21T18:14:54Z</dc:date>
    <item>
      <title>FMC Insider Threat/Malware Detection Across the LAN</title>
      <link>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490087#M1084546</link>
      <description>&lt;P&gt;In regards to Cisco's Threat Deteaction how would you scan for insider threats if the device doesn't have the Secure Endpoint software installed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Situation:&lt;/P&gt;&lt;P&gt;&amp;nbsp; The LAN is setup with Cisco Firepower FMC monitoring with AMP for Endpoints or (Secure Endpoint) software on all devices and you have ISE deployed.&amp;nbsp; How do you scan for someone that connects a device on the network and the switch port is not configured for 802.1x?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; If someone is using hacking tools within the network how can that be detected if it's local only and doesn't go to the outside through the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The reason I asked is because our company brought in a "Red Team" to determine the security of our network and their requirements kind of made me think (THAT'S NOT FAIR)!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The requirement was for us to open up several ports for them to plug in their scanning laptops.&amp;nbsp; The port configurations were to be bare with no port security or 802.1x configured and no port mirroring set up.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Additionally Secure Endpoint software would not be installed on the (Red Team's) computers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; How would you monitor for malicious activity on the LAN?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 18:03:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490087#M1084546</guid>
      <dc:creator>davsnet2000</dc:creator>
      <dc:date>2021-10-21T18:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Insider Threat/Malware Detection Across the LAN</title>
      <link>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490094#M1084548</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1262961"&gt;@davsnet2000&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;I agree. The test they should be running is from a standard (lockdown) port, with all the standard restrictions. Your bosses would get a better understanding of your network security that way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To answer your question, you could use Secure Network Analytics (previously called StealthWatch) that could monitor for abnormal or malicous traffic on the LAN (for traffic that doesn't transit the firewalls).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en_uk/products/security/stealthwatch/index.html" target="_blank"&gt;https://www.cisco.com/c/en_uk/products/security/stealthwatch/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 18:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490094#M1084548</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-10-21T18:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Insider Threat/Malware Detection Across the LAN</title>
      <link>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490119#M1084550</link>
      <description>&lt;P&gt;Rob, thanks for the reply.&amp;nbsp; I've requested StealthWatch in the past, but it never got funded.&amp;nbsp; And you are correct, I expected them to connect to a fully secured port or attempt from outside the WAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp; How does this method even test our network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Can I set up port monitors connected from the Firepower devices to the Access Switches or VLAN interfaces?&amp;nbsp; When the Cisco sales team pitched the FMC/Firepower upgrade for our firewall suite they said we could create ports and connect them to switches or VLAN interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp; I'm guessing this method would miss anything within an individual switch if the traffic never leaves the switch and we're connected to the L3 VLAN interface and not to the switch.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 20:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-insider-threat-malware-detection-across-the-lan/m-p/4490119#M1084550</guid>
      <dc:creator>davsnet2000</dc:creator>
      <dc:date>2021-10-21T20:53:02Z</dc:date>
    </item>
  </channel>
</rss>

