SlideShare a Scribd company logo
Cisco Firepower NGIPS Series Migration Options
Strengthen Your Network Defenses
It’s no secret that today’s attackers have the resources, expertise, and persistence to
compromise any organization at any time. Traditional defenses are no longer
effective.
Many people think that with the adoption of a next-generation firewall
(NGFW), that they no longer need a stand-alone intrusion prevention
system (IPS).
That’s simply not true. A “true” NGIPS can provide visibility, threat detection,
threat response, and malware discovery. And it can do all that in areas of
your network that remain off-limits to firewall inspection and controls.
Safeguarding your network assets and data from today’s threats requires
detailed visibility into all your network layers and resources.
1. It requires comprehensive, and up-to-date security intelligence.
2. It requires a dynamic approach that uses awareness and automation to
adapt to new threats, new vulnerabilities, and everyday network changes.
3. It requires Cisco Firepower NGIPS (Next-Generation Intrusion
Prevention System) threat appliances.
The Cisco Firepower NGIPS threat appliance provides industry-leading
visibility and threat efficacy against both known and unknown threats.
Cisco Firepower NGIPS stops threats by using:
• More than 30,000 IPS rules that identify and block traffic trying to exploit a
vulnerability in your network
• Reputation-based IP, URL, and DNS security intelligence that can shrink the
attack surface by identifying malicious sites
• A tightly integrated defense against network-based advanced malware
attacks
• An integrated sandboxing technology that uses hundreds of behavioral
indicators to spot zero-day attacks
• An Indications of Compromise (IoC) feature that correlates events from
multiple sources to identify what may be compromised hosts
Upgrade your customers to Cisco Firepower NGIPS today to help them protect
their network, users, applications, and information assets.
It’s as easy as 1...2...3
1. Confirm your current IPS model and refresh needs.
2. Review the recommended migration path.
3. Contact your trusted Cisco Security account manager or partner to get
started.
Migration Recommendations for Cisco IPS and FirePOWER (former
Sourcefire) Customers
Cisco IDS/IPS 4000
Appliances
Recommendation Throughput
Performance
Improvement
Cisco IPS 4270-20 Firepower 4110 2X
Cisco IPS 4360 Firepower 4110 3.2X
Cisco IPS 4510 Firepower 4110 1.33X
Cisco IPS 4520 Firepower 4120 1.6X
Cisco IPS 4520-XL Firepower 4140 1X
FirePOWER
81xxAppliances
Recommendation Throughput
Performance
Improvement
FirePOWER 8120 Firepower 4110 2X
FirePOWER 8130 Firepower 4110 1X
FirePOWER 8140 Firepower 4120 1.33X
Firepower 8xxxx AMP
Appliances
Recommendation Throughput
Performance
Improvement
FirePOWER AMP 8050 Firepower 4110 AMP 1.5X
FirePOWER AMP 8150 Firepower 4120 AMP 1.2X
FirePOWER AMP 8150 Firepower 4140 AMP 2X
Learn More: Find the Right Cisco Firewall for your Needs
Why NGFW and NGIPS are needed in network security infrastructure?
Do you really need both a next-generation firewall (NGFW) and next-
generation intrusion prevention system (NGIPS) for my network
security infrastructure? The answer is YES!
What does a next-generation firewall do? The NGFW has its core
competencies and it includes:
1. Network address translation
2. Acting as a stateful firewall
3. VPN concentrator
4. Application visibility and control
5. And don’t forget, IPS inspection
A next-generation IPS has its core competencies and they include:
1. Inspect asymmetric traffic flows
2. Perform as a transparent bump-in-the wire inspection device
3. Provide visibility and protection by inspecting network traffic that
moves lateral to a perimeter firewall
Since the NGFW is a network device, it can operate lower in the OSI stack
and can act as a network boundary or create a network pinch-point perfect
for stateful firewalling, application identification, and deep packet inspection.
Using a NGIPS to perform deep packet inspection makes for a more
effective strategy against the would-be-adversary. Because an NGIPS
does not maintain a state table, it is less vulnerable to attacks that exploit
state table exhaustion and result in denial of service. This also gives it the
ability to inspect asymmetric data flows. The NGIPS is also a transparent
device, just a bump in the wire, allowing traffic to flow as if it is not even
there, even if it is deployed in the core, doing deep packet inspection or on
the network edge.
Did you know that traffic looks differently in the core vs. the edge of the
network? Advanced persistent threats are more easily detected by the NGIPS.
Because the NGIPS can be deployed where it will have of the lateral visibility
of the traffic, it gives you that advantage over a firewall. A traditional stateful
firewall cannot provide this. The lateral visibility it is perfect to identifying
machines on a network that have already been compromised and are being
used by a bad guy to collect and infiltrate sensitive or important data.
Visibility and the ability to secure a network at the perimeter and at the
network core should be essential for every organization that wants to
strengthen their overall security posture.
To learn more about Cisco Firepower NGIPS threat appliances, please visit
http://www.cisco.com/go/ngips.
To learn more about the Cisco Advanced Malware Protection capability, please
visit http://www.cisco.com/go/amp.
To learn more about Cisco’s Talos Security Intelligence and Research team,
please visit http://www.talosintelligence.com/.
Info from
https://www.cisco.com/c/dam/m/en_us/products/security/ngips/NGIPS_transi
tion_guide.pdf
More Related
Guide to the New Cisco Firepower 2100 Series
How to Deploy the Cisco ASA FirePOWER Services in the Internet Edge, VPN
Scenarios and Data Center?
The Most Common NGFW Deployment Scenarios
Cisco’s High-end Next Generation Firewalls-Firepower 4100 and 9300 Series
UTM vs. NGFW

More Related Content

PDF
8 Ocak 2015 SOME Etkinligi - A10 Networks - Accelerating and Securing Applica...
PDF
Open Source IDS - How to use them as a powerful fee Defensive and Offensive tool
PDF
Advanced threat security - Cyber Security For The Real World
PPTX
Sourcefire Webinar - NEW GENERATION IPS
PPTX
IPS Best Practices
PDF
Talk2 esc2 muscl-wifi_v1_2b
PDF
SourceFire IPS Overview
PDF
Sourcefire - A Next-Generation Intrusion Prevention Solution Delivering Scala...
8 Ocak 2015 SOME Etkinligi - A10 Networks - Accelerating and Securing Applica...
Open Source IDS - How to use them as a powerful fee Defensive and Offensive tool
Advanced threat security - Cyber Security For The Real World
Sourcefire Webinar - NEW GENERATION IPS
IPS Best Practices
Talk2 esc2 muscl-wifi_v1_2b
SourceFire IPS Overview
Sourcefire - A Next-Generation Intrusion Prevention Solution Delivering Scala...

What's hot (18)

PDF
Next Generation Security
PDF
Talk2 esc4 muscl-ids_v1_2
PDF
BGA SOME/SOC Etkinliği - Tehdit Odaklı Güvenlik Mimarisinde Sourcefire Yakla...
PDF
'Moon' Security Management System for OPNFV
PPT
Next generation firewall(ngfw)feature and benefits
PDF
Cisco amp for meraki
PDF
Cisco umbrella overview
PPTX
Talos Insight: Threat Innovation Emerging from the Noise
PDF
stackArmor MicroSummit - Niksun Network Monitoring - DPI
PDF
8 Ocak 2015 SOME Etkinligi - Cisco Next Generation Security
PDF
Cisco ThreatGrid: Malware Analysis and Threat Intelligence
PDF
Next Generation Firewall and IPS
PDF
Trusted Environment. Blockchain for business: best practices, experience, tips
PPTX
TechWiseTV Workshop: OpenDNS and AnyConnect
PDF
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
PDF
The Network as a Sensor, Cisco and Lancope
PDF
Stop Translating, Start Defending: Common Language for Managing Cyber-Risk
PDF
Cisco Connect 2018 Thailand - Cisco Meraki an innovation journey to a smarter...
Next Generation Security
Talk2 esc4 muscl-ids_v1_2
BGA SOME/SOC Etkinliği - Tehdit Odaklı Güvenlik Mimarisinde Sourcefire Yakla...
'Moon' Security Management System for OPNFV
Next generation firewall(ngfw)feature and benefits
Cisco amp for meraki
Cisco umbrella overview
Talos Insight: Threat Innovation Emerging from the Noise
stackArmor MicroSummit - Niksun Network Monitoring - DPI
8 Ocak 2015 SOME Etkinligi - Cisco Next Generation Security
Cisco ThreatGrid: Malware Analysis and Threat Intelligence
Next Generation Firewall and IPS
Trusted Environment. Blockchain for business: best practices, experience, tips
TechWiseTV Workshop: OpenDNS and AnyConnect
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
The Network as a Sensor, Cisco and Lancope
Stop Translating, Start Defending: Common Language for Managing Cyber-Risk
Cisco Connect 2018 Thailand - Cisco Meraki an innovation journey to a smarter...
Ad

Similar to Cisco firepower ngips series migration options (20)

PDF
Cisco Firepower Next-Generation Firewall (NGFW).pdf
PDF
Cisco ASA con fire power services
PDF
Presentación - Cisco ASA with FirePOWER Services
PPTX
Cisco Next-Generation IPS and how to install Firepower version 6.X.pptx
PPTX
NGIPS(Next Generation Intrusion Prevention System) in Network security presen...
PDF
Putting Firepower into the Next Generation Firewall
PDF
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
PDF
Estratégia de segurança da Cisco (um diferencial para seus negócios)
DOCX
Migration to cisco next generation firewall
PDF
Putting Firepower Into The Next Generation Firewall
PDF
AGILE SECURITY™ Security for the Real World
PDF
Cisco Next Generation Firewall with Firepower
PDF
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
PDF
Putting firepower into the next generation firewall
PDF
Scalar Security Roadshow - Toronto Presentation
PDF
Midsize Business Solutions: Cybersecurity
PDF
PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
PDF
Cisco Security Architecture
PPTX
Isday 2017 - Atelier Cisco
DOCX
Cisco firepower 2100 series, as a ngfw or a ngips
Cisco Firepower Next-Generation Firewall (NGFW).pdf
Cisco ASA con fire power services
Presentación - Cisco ASA with FirePOWER Services
Cisco Next-Generation IPS and how to install Firepower version 6.X.pptx
NGIPS(Next Generation Intrusion Prevention System) in Network security presen...
Putting Firepower into the Next Generation Firewall
Cisco Connect Halifax 2018 Putting firepower into the next generation firewall
Estratégia de segurança da Cisco (um diferencial para seus negócios)
Migration to cisco next generation firewall
Putting Firepower Into The Next Generation Firewall
AGILE SECURITY™ Security for the Real World
Cisco Next Generation Firewall with Firepower
Cisco connect winnipeg 2018 putting firepower into the next generation fire...
Putting firepower into the next generation firewall
Scalar Security Roadshow - Toronto Presentation
Midsize Business Solutions: Cybersecurity
PLNOG14: Firewalls In Modern Data Centers - Piotr Wojciechowski
Cisco Security Architecture
Isday 2017 - Atelier Cisco
Cisco firepower 2100 series, as a ngfw or a ngips
Ad

More from IT Tech (20)

DOCX
Cisco ip phone key expansion module setup
DOCX
Cisco catalyst 9200 series platform spec, licenses, transition guide
DOCX
Cisco isr 900 series highlights, platform specs, licenses, transition guide
DOCX
Hpe pro liant gen9 to gen10 server transition guide
DOCX
The new cisco isr 4461 faq
DOCX
New nexus 400 gigabit ethernet (400 g) switches
DOCX
Tested cisco isr 1100 delivers the richest set of wi-fi features
DOCX
Aruba campus and branch switching solution
DOCX
Cisco transceiver module for compatible catalyst switches
DOCX
Cisco ios on cisco catalyst switches
DOCX
Cisco's wireless solutions deployment modes
DOCX
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
DOCX
Four reasons to consider the all in-one isr 1000
DOCX
The difference between yellow and white labeled ports on a nexus 2300 series fex
DOCX
Cisco transceiver modules for compatible cisco switches series
DOCX
Guide to the new cisco firepower 2100 series
DOCX
892 f sfp configuration example
DOCX
Cisco nexus 7000 and nexus 7700
DOCX
Eol transceiver to replacement model
DOCX
16 questions of cisco sfp 10 g-sr...
Cisco ip phone key expansion module setup
Cisco catalyst 9200 series platform spec, licenses, transition guide
Cisco isr 900 series highlights, platform specs, licenses, transition guide
Hpe pro liant gen9 to gen10 server transition guide
The new cisco isr 4461 faq
New nexus 400 gigabit ethernet (400 g) switches
Tested cisco isr 1100 delivers the richest set of wi-fi features
Aruba campus and branch switching solution
Cisco transceiver module for compatible catalyst switches
Cisco ios on cisco catalyst switches
Cisco's wireless solutions deployment modes
Competitive switching comparison cisco vs. hpe aruba vs. huawei vs. dell
Four reasons to consider the all in-one isr 1000
The difference between yellow and white labeled ports on a nexus 2300 series fex
Cisco transceiver modules for compatible cisco switches series
Guide to the new cisco firepower 2100 series
892 f sfp configuration example
Cisco nexus 7000 and nexus 7700
Eol transceiver to replacement model
16 questions of cisco sfp 10 g-sr...

Recently uploaded (20)

PPTX
OMC Textile Division Presentation 2021.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PPTX
A Presentation on Artificial Intelligence
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Mushroom cultivation and it's methods.pdf
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Encapsulation theory and applications.pdf
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
August Patch Tuesday
PDF
Empathic Computing: Creating Shared Understanding
PPTX
TLE Review Electricity (Electricity).pptx
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
1. Introduction to Computer Programming.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Encapsulation_ Review paper, used for researhc scholars
OMC Textile Division Presentation 2021.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
A Presentation on Artificial Intelligence
Digital-Transformation-Roadmap-for-Companies.pptx
Mushroom cultivation and it's methods.pdf
Univ-Connecticut-ChatGPT-Presentaion.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
NewMind AI Weekly Chronicles - August'25-Week II
SOPHOS-XG Firewall Administrator PPT.pptx
Encapsulation theory and applications.pdf
gpt5_lecture_notes_comprehensive_20250812015547.pdf
August Patch Tuesday
Empathic Computing: Creating Shared Understanding
TLE Review Electricity (Electricity).pptx
cloud_computing_Infrastucture_as_cloud_p
1. Introduction to Computer Programming.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Encapsulation_ Review paper, used for researhc scholars

Cisco firepower ngips series migration options

  • 1. Cisco Firepower NGIPS Series Migration Options Strengthen Your Network Defenses It’s no secret that today’s attackers have the resources, expertise, and persistence to compromise any organization at any time. Traditional defenses are no longer effective. Many people think that with the adoption of a next-generation firewall (NGFW), that they no longer need a stand-alone intrusion prevention system (IPS). That’s simply not true. A “true” NGIPS can provide visibility, threat detection, threat response, and malware discovery. And it can do all that in areas of your network that remain off-limits to firewall inspection and controls. Safeguarding your network assets and data from today’s threats requires detailed visibility into all your network layers and resources. 1. It requires comprehensive, and up-to-date security intelligence. 2. It requires a dynamic approach that uses awareness and automation to adapt to new threats, new vulnerabilities, and everyday network changes. 3. It requires Cisco Firepower NGIPS (Next-Generation Intrusion Prevention System) threat appliances. The Cisco Firepower NGIPS threat appliance provides industry-leading visibility and threat efficacy against both known and unknown threats. Cisco Firepower NGIPS stops threats by using:
  • 2. • More than 30,000 IPS rules that identify and block traffic trying to exploit a vulnerability in your network • Reputation-based IP, URL, and DNS security intelligence that can shrink the attack surface by identifying malicious sites • A tightly integrated defense against network-based advanced malware attacks • An integrated sandboxing technology that uses hundreds of behavioral indicators to spot zero-day attacks • An Indications of Compromise (IoC) feature that correlates events from multiple sources to identify what may be compromised hosts Upgrade your customers to Cisco Firepower NGIPS today to help them protect their network, users, applications, and information assets. It’s as easy as 1...2...3 1. Confirm your current IPS model and refresh needs. 2. Review the recommended migration path. 3. Contact your trusted Cisco Security account manager or partner to get started. Migration Recommendations for Cisco IPS and FirePOWER (former Sourcefire) Customers Cisco IDS/IPS 4000 Appliances Recommendation Throughput Performance Improvement Cisco IPS 4270-20 Firepower 4110 2X Cisco IPS 4360 Firepower 4110 3.2X Cisco IPS 4510 Firepower 4110 1.33X Cisco IPS 4520 Firepower 4120 1.6X Cisco IPS 4520-XL Firepower 4140 1X
  • 3. FirePOWER 81xxAppliances Recommendation Throughput Performance Improvement FirePOWER 8120 Firepower 4110 2X FirePOWER 8130 Firepower 4110 1X FirePOWER 8140 Firepower 4120 1.33X Firepower 8xxxx AMP Appliances Recommendation Throughput Performance Improvement FirePOWER AMP 8050 Firepower 4110 AMP 1.5X FirePOWER AMP 8150 Firepower 4120 AMP 1.2X FirePOWER AMP 8150 Firepower 4140 AMP 2X Learn More: Find the Right Cisco Firewall for your Needs Why NGFW and NGIPS are needed in network security infrastructure? Do you really need both a next-generation firewall (NGFW) and next- generation intrusion prevention system (NGIPS) for my network security infrastructure? The answer is YES! What does a next-generation firewall do? The NGFW has its core competencies and it includes: 1. Network address translation 2. Acting as a stateful firewall 3. VPN concentrator 4. Application visibility and control 5. And don’t forget, IPS inspection A next-generation IPS has its core competencies and they include: 1. Inspect asymmetric traffic flows 2. Perform as a transparent bump-in-the wire inspection device 3. Provide visibility and protection by inspecting network traffic that moves lateral to a perimeter firewall Since the NGFW is a network device, it can operate lower in the OSI stack and can act as a network boundary or create a network pinch-point perfect for stateful firewalling, application identification, and deep packet inspection.
  • 4. Using a NGIPS to perform deep packet inspection makes for a more effective strategy against the would-be-adversary. Because an NGIPS does not maintain a state table, it is less vulnerable to attacks that exploit state table exhaustion and result in denial of service. This also gives it the ability to inspect asymmetric data flows. The NGIPS is also a transparent device, just a bump in the wire, allowing traffic to flow as if it is not even there, even if it is deployed in the core, doing deep packet inspection or on the network edge. Did you know that traffic looks differently in the core vs. the edge of the network? Advanced persistent threats are more easily detected by the NGIPS. Because the NGIPS can be deployed where it will have of the lateral visibility of the traffic, it gives you that advantage over a firewall. A traditional stateful firewall cannot provide this. The lateral visibility it is perfect to identifying machines on a network that have already been compromised and are being used by a bad guy to collect and infiltrate sensitive or important data. Visibility and the ability to secure a network at the perimeter and at the network core should be essential for every organization that wants to strengthen their overall security posture. To learn more about Cisco Firepower NGIPS threat appliances, please visit http://www.cisco.com/go/ngips. To learn more about the Cisco Advanced Malware Protection capability, please visit http://www.cisco.com/go/amp. To learn more about Cisco’s Talos Security Intelligence and Research team, please visit http://www.talosintelligence.com/. Info from https://www.cisco.com/c/dam/m/en_us/products/security/ngips/NGIPS_transi tion_guide.pdf More Related Guide to the New Cisco Firepower 2100 Series How to Deploy the Cisco ASA FirePOWER Services in the Internet Edge, VPN Scenarios and Data Center? The Most Common NGFW Deployment Scenarios Cisco’s High-end Next Generation Firewalls-Firepower 4100 and 9300 Series UTM vs. NGFW