0% found this document useful (0 votes)
18 views

ComponentIntegration - AMP Unity - ST

Uploaded by

jomsm25
Copyright
© © All Rights Reserved
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views

ComponentIntegration - AMP Unity - ST

Uploaded by

jomsm25
Copyright
© © All Rights Reserved
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
You are on page 1/ 11

Integration

overview

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1
Introducing AMP Unity
• Enhanced Operational Visibility and Control

Systems Security Team Network Security


Event Sync Team
• Consolidation of
connector events in • Visibility into
AMP Console FMC AMP Events at the
• Visibility into the Endpoint
threat vector
• A4E Policy
Management

AMP for Endpoints


© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Firepower (FMC) Cisco ESA & WSA 2
AMP Unity

Manages for Endpoints: Manages for Network: Manages for Content:


• Endpoint Policies • Network Policies • Content Policies
• Black & White Lists • Bad & Good File Lists • Bad & Good File Lists
• Exclusions

Provides for Endpoints Provides for Network Provides for Content


• Device Trajectories • File Trajectories • File Trajectories
• File Trajectories • Retrospection • Retrospection
• Retrospection

AMP for Endpoints


© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Firepower (FMC) Cisco ESA & WSA3
AMP Unity Functionality with Releases

Global Trajectory Global Outbreak Control


Network Appliances
AMP FMC 6.2 Simple Custom Detection
Appliances (Bad Files)

NGIPS NGFW Firepower FMC 6.2


Appliances Good Files

Content Appliances Email Security AsyncOS 11.1

WWW
Web Security AsyncOS 11.5
WSA ESA/CES

* See File & Device trajectory from all your AMP-enabled devices

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Preparing for the
integration
Preparing for Integration
• Admin Access to each integration piece
• AMP for Endpoint Console
• Email Security Console
• Web Security Console
• Firepower Management Console

• Check OS version
• Break Content Security Cluster
• Create Network Groups
• Identify Endpoint Groups to include in integration
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
Post-integration
processes
Adding Endpoint Groups

Be sure to select the groups you


would like to export data from.

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8
Verify Integration

You can verify integration under


Accounts and Applications

... and shows up as an


integrated application

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
Resources

Ask the Experts Accelerators Services


1 2 3
• Expanding to New Use Cases: • Advanced Feature Deep Dive: • Cisco Learning Library
Advanced Malware Protection Threat Hunting
Everywhere

© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11

You might also like