02-15-2025 10:02 AM
Hello,
I have a few cybersecurity-related questions regarding Cisco ThousandEyes Enterprise Agents, specifically their deployment on Cisco 9300 switches:
For deployment on 9300 switches what are the recommended security best practices? Is hosting them on core infrastructure considered a security risk?
How are the switch-hosted Enterprise Agents hardened? What security practices are recommended for their deployment?
Can these agents be scanned with Tenable scanners?
Do switch-hosted agents support certificates from customer CA? If so, what's the best way to automate certificate deployment to a large number of agents?
Best Regards
02-18-2025 03:26 PM
Howdy @SLAK - I ran your questions by our experts and they had some really good input I want to share with you, addressing by question:
For deployment on 9300 switches what are the recommended security best practices? Is hosting them on core infrastructure considered a security risk? "Please ask the member to open a support case with our InfoSec team to provide better, more personalized insights into this."
How are the switch-hosted Enterprise Agents hardened? What security practices are recommended for their deployment? "At a high level, we use Alpine as the latest version for Enterprise Agents installed on Cisco devices. Alpine is built on musl
which is a security-hardened C library, rather than the more general glibc
. This includes automatic hardening for many C and C++ projects built against it, including the Enterprise Agent."
Can these agents be scanned with Tenable scanners? "Please ask the member to open a support case with our InfoSec team to provide better, more personalized insights into this."
Do switch-hosted agents support certificates from customer CA? If so, what's the best way to automate certificate deployment to a large number of agents? "Enterprise Agents are installed on standard operating systems which the customer controls, including control of the certificate stores. At the moment, certificates should be updated manually but there is currently a feature request to have them updated in bulk. It should be noted that it is not yet on our roadmap. Additional details on certificates is in this documentation."
Welcome to the community! If you've never opened a case with our support team it's pretty simple! This article goes into more detail if you need a refresher.
02-19-2025 02:44 PM
Thanks for the response @Tyler Langston. I'll check feasibility of opening support cases as suggested.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide