cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
165
Views
1
Helpful
2
Replies

Enterprise agent on switches security best practices

SLAK
Level 1
Level 1

Hello,

I have a few cybersecurity-related questions regarding Cisco ThousandEyes Enterprise Agents, specifically their deployment on Cisco 9300 switches:

https://docs.thousandeyes.com/product-documentation/global-vantage-points/enterprise-agents/installing/cisco-devices/installation-methods/installing-enterprise-agents-on-cisco-switches-with-docker 

  1. For deployment on 9300 switches what are the recommended security best practices? Is hosting them on core infrastructure considered a security risk?

  2. How are the switch-hosted Enterprise Agents hardened? What security practices are recommended for their deployment?

  3. Can these agents be scanned with Tenable scanners?

  4. Do switch-hosted agents support certificates from customer CA? If so, what's the best way to automate certificate deployment to a large number of agents?

Best Regards

2 Replies 2

Tyler Langston
Community Manager
Community Manager

Howdy @SLAK - I ran your questions by our experts and they had some really good input I want to share with you, addressing by question:

  1. For deployment on 9300 switches what are the recommended security best practices? Is hosting them on core infrastructure considered a security risk? "Please ask the member to open a support case with our InfoSec team to provide better, more personalized insights into this."

  2. How are the switch-hosted Enterprise Agents hardened? What security practices are recommended for their deployment? "At a high level, we use Alpine as the latest version for Enterprise Agents installed on Cisco devices. Alpine is built on musl which is a security-hardened C library, rather than the more general glibc.  This includes automatic hardening for many C and C++ projects built against it, including the Enterprise Agent."

  3. Can these agents be scanned with Tenable scanners? "Please ask the member to open a support case with our InfoSec team to provide better, more personalized insights into this."

  4. Do switch-hosted agents support certificates from customer CA? If so, what's the best way to automate certificate deployment to a large number of agents? "Enterprise Agents are installed on standard operating systems which the customer controls, including control of the certificate stores. At the moment, certificates should be updated manually but there is currently a feature request to have them updated in bulk. It should be noted that it is not yet on our roadmap. Additional details on certificates is in this documentation."

Welcome to the community! If you've never opened a case with our support team it's pretty simple! This article goes into more detail if you need a refresher.

 

 

 

SLAK
Level 1
Level 1

Thanks for the response @Tyler Langston. I'll check feasibility of opening support cases as suggested.

Review Cisco Networking for a $25 gift card