<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3936122#M16875</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;This is always a difficult task but you can have the visibility when connecting to FMC and looking at the dashboard or creating few reports on the reporting tab. You can also check the context explorer which will give you source hosts and destination and applications.&lt;BR /&gt;You will need to start with the most used applications and then narrow down the logs after few days by filtering all events matching the default open rule. Few back and forth here to be able to construct few rules before moving the default to a deny statement.</description>
    <pubDate>Mon, 07 Oct 2019 03:28:35 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2019-10-07T03:28:35Z</dc:date>
    <item>
      <title>Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3935969#M16874</link>
      <description>&lt;P&gt;Hi all, We have recently deployed some firewalls in a client's network which was initally an "open" network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the design of these new firewalls put in place to implement proper segmentation, I have been tasked with developing baseline firewalls rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because the network was initially open, there is no way I could possily use any existing rules because there were no rules! Plus getting the expected traffic flow information between each zones from the relevant teams of the client is not possible for unknown reasons. They do not have that sort of visibility. So the responsibility is all upon me to somehow develop this baseline firewall rules based on just looking at the traffic logs. Without no surprise, this is a humongous task.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence, I am wondering if there is any better or more efficient and faster way to do this ? I dont want to go through the logs line by line to determine what firewall rule should I create ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if there's any such feature or dashboard/report in FMC where I can get the visibility of the high traffic patterns from all zones, which can eventually help me build this firewall policy ?&lt;/P&gt;&lt;P&gt;For e.g a list of traffic flows which tells me there is high amount of traffic between zone A to zone B and so on.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3935969#M16874</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-02-21T17:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3936122#M16875</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;This is always a difficult task but you can have the visibility when connecting to FMC and looking at the dashboard or creating few reports on the reporting tab. You can also check the context explorer which will give you source hosts and destination and applications.&lt;BR /&gt;You will need to start with the most used applications and then narrow down the logs after few days by filtering all events matching the default open rule. Few back and forth here to be able to construct few rules before moving the default to a deny statement.</description>
      <pubDate>Mon, 07 Oct 2019 03:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3936122#M16875</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-10-07T03:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3936304#M16876</link>
      <description>&lt;P&gt;They might be better off running a Stealthwatch POV with the FTD device as a source for the Netflow records.&lt;/P&gt;
&lt;P&gt;Stealthwatch is much better at capturing and visualizing flows as it has a lot of built-in reporting and customizing the output is quite easy from the Stealthwatch Management Console (SMC).&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 10:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3936304#M16876</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-07T10:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3938927#M16877</link>
      <description>&lt;P&gt;That sounds like a great idea. Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently exploring how I can do this via reports. Incase, if you already know, can you please advise if there's a place from where I can get a list of porys/protocols regularly accessed from a security zone and to destination zone, apart from logs?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 22:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3938927#M16877</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-10-10T22:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3938970#M16878</link>
      <description>If you go into the report menu you should be able to explore different reports and find which one fits your need.&lt;BR /&gt;Let me check it and come back to you.&lt;BR /&gt;&lt;BR /&gt;I've not mentioned stealthwatch in my previous answer and if you're able to to add this piece then it would much more helpful.</description>
      <pubDate>Fri, 11 Oct 2019 01:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3938970#M16878</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-10-11T01:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for developing baseline firewall rules based ONLY on logs from FMC</title>
      <link>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3946805#M16879</link>
      <description>&lt;P&gt;Answering my own question here. I was finally able to figure out a way to do this after spending a lot of time studying the FMC features.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;To find out what interfaces are carrying most of the traffic, the&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="gwt-InlineLabel"&gt;Traffic by Ingress/Egress Security Zone&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="gwt-InlineLabel"&gt;panel can be used within the &lt;STRONG&gt;context explorer&lt;/STRONG&gt; page under &lt;STRONG&gt;Analysis.&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;If there are multiple firewalls, you can drilldown by using filter option at top left. There you can mention the firewall name in the &lt;STRONG&gt;device&lt;/STRONG&gt; option. On top right, choose your preferred timeline next to &lt;STRONG&gt;Show the last:&amp;nbsp;&lt;/STRONG&gt; field.&lt;/LI&gt;&lt;LI&gt;Once you have done that, go to Analysis --&amp;gt; connections --&amp;gt;&amp;nbsp;Table View of Connection Events. Edit and apply the search based on below filters,&lt;UL&gt;&lt;LI&gt;enter device name, (firewall you are working on)&lt;/LI&gt;&lt;LI&gt;ingress zone (based on what your finding in step 1)&lt;/LI&gt;&lt;LI&gt;egress zone (based on what your finding in step 1)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Choose appropriate timeline (top right). I prefer static - 1 month for tuning purpose.&lt;/LI&gt;&lt;LI&gt;Select interesting fields,&lt;UL&gt;&lt;LI&gt;Click on &lt;STRONG&gt;x&amp;nbsp;&lt;/STRONG&gt;icon next to any of the field name&lt;/LI&gt;&lt;LI&gt;Check next to All Columns to select all&lt;/LI&gt;&lt;LI&gt;Uncheck to unselect all columns&lt;/LI&gt;&lt;LI&gt;Check&lt;UL&gt;&lt;LI&gt;Ingress Zone&lt;/LI&gt;&lt;LI&gt;Ingress Interface&lt;/LI&gt;&lt;LI&gt;Egress Zone&lt;/LI&gt;&lt;LI&gt;Egress Interface&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Destination Port / ICMP Code&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Click Apply&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Once the page is loaded, select&amp;nbsp;&lt;STRONG&gt;Count&amp;nbsp;&lt;/STRONG&gt;(extreme right field) to sort in descending order. Thats where you will see the high traffic flow information.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps anyone who is working on similar thing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If anyone knows more efficient way of doing this, feel free to share!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 01:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommendation-for-developing-baseline-firewall-rules-based-only/m-p/3946805#M16879</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2019-10-24T01:22:31Z</dc:date>
    </item>
  </channel>
</rss>

