Cisco FTD
You can integrate Cisco Firepower Threat Defense (FTD) with Sophos XDR so that it sends audit data to Sophos for analysis. You can use either Cisco Secure Firewall Device Manager (FDM) or Cisco Secure Firewall Management Center (FMC) to send the syslogs.
This page gives you an overview of the integration.
Cisco FTD product overview
Cisco FTD is a firewall solution that leverages real-time contextual awareness to combine advanced threat protection, intrusion prevention, and next-generation firewall capabilities into a single integrated platform.
What we ingest
Sophos XDR collects Cisco FTD data over syslog forwarded from your FTD device (or from a Firepower Management Center on its behalf) to a Sophos XDR data collector. FTD emits messages using the standard Cisco ASA/FTD syslog grammar of %FTD-<severity>-<message-id>: or %ASA-<severity>-<message-id>: for the shared ASA-style records, and adds Firepower-specific message IDs in the 430000 range for Snort engine events. We use the following Cisco FTD log categories:
- Connection traffic: Session build and teardown (for example, 302013-302016, 302020-302021, 302303-302304), access list permits, and the Firepower Snort connection log (430002), including source and destination addresses and ports, protocol, action, bytes or packets, and policy or rule context.
- Access control and intrusion: ACL permit/deny records, Snort intrusion events (430001), and traffic anomaly detections (for example, 313009 and 733101 attack/threat detection), with rule or signature identifiers, severity, action, and the affected endpoints.
- File and malware: Firepower file events and malware events (for example, 430004 and 430005), including file name, hash, file disposition, action, and the source and destination context.
- VPN authentication and tunnel: Remote access, AnyConnect or Secure Client, IPsec, IKE, and SSL VPN authentication and session lifecycle messages (for example, 109001-109104, 113004-113039, 722003-722056, 751026), including user, source address, group or policy, and outcome.
- Device authentication and AAA: Console, SSH, and management plane authentication and authorization events (for example, 605xxx, 611xxx, and related AAA messages) for administrative access to the firewall.
- DNS, HTTP, and other application-layer events: DNS inspection (746015), HTTP access (304001), and related application-layer records emitted by FTD inspection engines.
- Management and configuration: Audited administrative actions and configuration commits captured under the 111008-111010 series.
- Other FTD system messages: Remaining FTD/ASA syslog messages (system, status, NAT, routing, certificate, and similar operational records) are ingested and searchable with lighter normalization.
Cisco FTD sends these messages exactly as configured on the device or on FMC. Which message IDs and fields appear depends on the device's logging level and logging filters, which features are licensed and enabled (for example, Snort intrusion, Malware Defense, URL filtering, AnyConnect/Secure Client VPN), and which message classes your logging configuration permits.
Event and data types
We ingest the following event and data types from Cisco FTD:
The same logical categories apply whether messages come from a managed FTD device or are relayed by FMC.
- Firewall connection traffic1: Session build, teardown, deny, and Snort connection records. Netflow-style telemetry.
- Intrusion and threat detection: Snort intrusion events, ACL-driven threat detections, and traffic anomaly attack detections. Network IDS-style telemetry and third-party security alert telemetry where Snort engine alerts apply.
- File and malware: Firepower file inspection and malware events. Antivirus and file protection telemetry.
- VPN authentication: Remote access, IPsec, IKE, AnyConnect/Secure Client, and SSL VPN login, logoff, and session events. Authentication telemetry.
- Device administration: Console, SSH, and management plane authentication events for administrators of the firewall. Authentication telemetry.
- DNS inspection: DNS-related inspection messages. DNS query telemetry.
- HTTP inspection: HTTP access and proxy-style inspection messages. HTTP telemetry.
- Configuration and audit: Audited configuration commits and command authorization records. Management-event telemetry.
- Other FTD system messages1: Remaining FTD/ASA syslog records that don't match a more specific category above. Generic telemetry.
Data provided by this integration
Data provided by Cisco FTD gets normalized to the following schemas:
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
- Best Practices for Configuring Security Event Syslog Messaging
- Configuring Syslog Servers
- Secure Firewall Management Center Configuration Guides
- Firepower Management Center Configuration Guide, Version 6.2: Connection logging
- Cisco Secure Firewall Threat Defense: Security Event Syslog Messages
-
Netflow and generic telemetry are only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩↩