Skip to content
Notifications
Clear all

Thoughts on Cisco's push for Secure Firewall - just a rebrand?

2 Posts
2 Users
0 Reactions
2 Views
(@cloud_watcher_99)
Reputable Member
Joined: 1 month ago
Posts: 172
Topic starter   [#21063]

Hey everyone, been deep in AWS security and cost monitoring lately, but our on-prem/edge stuff still runs on Firepower. Saw Cisco's big push for "Secure Firewall" and it got me thinking.

From the docs and announcements, it looks like a lot more than just a paint job on Firepower Threat Defense (FTD). They're really pushing the cloud-managed aspect with Secure Firewall Management Center (SFMC) and tying it into their broader security suite (SecureX, etc.). The move to more flexible licensing (pay-as-you-go, bring-your-own-license to cloud) feels like a direct response to how we all operate now.

But honestly, my first thought was: is this mainly a rebrand to distance themselves from the... let's say *rocky* early FTD releases? The performance and management headaches a few years back were real. I'm curious if the core engine and resource usage have fundamentally changed, or if the big shifts are in the orchestration layer and pricing models.

For those who've moved from traditional FTD to this new "Secure Firewall" world, especially in hybrid setups:
* Is the management experience actually snappier, or is it the same backend with a new portal?
* How's the integration for telemetry into tools like Splunk or even Datadog? Are the logs any more structured/less verbose?
* Any noticeable impact on throughput or latency with the new software versions?

Trying to decide if this is a meaningful evolution or mostly a marketing reset. The cloud-native angle is tempting for operational consistency.


cost first, then scale


   
Quote
(@data_diver_dan)
Estimable Member
Joined: 3 months ago
Posts: 126
 

You're right to focus on the telemetry integration, because that's where the real pivot is for hybrid environments. The new backend pipelines for syslog and NetFlow into SFMC are actually more structured, allowing for better aggregation of policy hit counts and threat events into their data lake.

Whether the core engine has changed, I'd argue the resource usage improvements come from shifting more analytical load to the cloud side. The local enforcement point still does pattern matching, but behavioral analytics and historical correlation are offloaded. That reduces the on-prem footprint for the same rule set.

If you're already piping logs to a SIEM, test the new telemetry feeds against your existing dashboards. The schema changes can break existing Looker or Tableau reports if you're not careful, especially around how they're handling NAT'd addresses now.


Garbage in, garbage out.


   
ReplyQuote