Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Cyber Vision Segmentation

Want to summarize with AI?

Log in

Introduces Cyber Vision Segmentation in Release 5.6.0 and explains how asset groups, segmentation rules, recommendations, simulation, and switch capability fit together.


Segmentation for industrial networks is introduced in Cyber Vision Release 5.6.0 to help you define, recommend, and simulate segmentation policy on IE3300, IE3400, IE3500, and IE9300 switches.

Use Segmentation to plan policy with observed network evidence. You can review global policy objects, inspect what a switch observes, evaluate recommendations, and simulate the impact of the segmentation rules you want to apply, before applying the rules.

  • Asset groups provide segmentation identities, and segmentation rules define the permissions between those identities.

  • Asset group identities map to Security Group Tags (SGTs), and permissions map to Security Group ACLs (SGACLs).

You cannot deploy SGT mappings, generate switch-ready SGACL configuration, manage active policy state, or synchronize policy to switches in this release.

You can create and edit asset group membership, review and accept group recommendations, create and edit logical segmentation rules, define common-service relationships, and simulate policy impact.

You can evaluate a segmentation model against one year of observed traffic and review logical pseudo-SGACL output for training and simulation.

Cyber Vision filters the switches displayed on the Segmentation page according to the selected organization hierarchy level. Selecting a lower sensor-based hierarchy level limits the list to switches associated with that level and hides switches outside the selected context. If you select a network-based organization hierarchy, the Segmentation page does not display segmentation data. In the switches table, Cyber Vision shows whether each switch has Simulation or Enforcement capability in later releases of Cisco Cyber Vision.

  • IE3300 and IE3400 only support simulation. Data from these switches can only be used for simulation.

  • IE3500 and IE9300 can support enforcement. You can apply segmentation rules on these devices in later releases of Cyber Vision.

  • After upgrading to Cisco Cyber Vision Release 5.6.x, wait a few days before enabling segmentation. This delay allows Cyber Vision to populate the sensor-to-communication link data required for segmentation.

Table 1. Feature History Table

Feature

Release

Feature Description

Cyber Vision segmentation

Release 5.6.0

Introduces tools to model industrial network segmentation using observed switch communications. You can create and manage asset groups, review segmentation recommendations, configure inter-group, intra-group, default, and common-service rules, and simulate policy impact on supported switches.


Segmentation workspace

The Segmentation pages separate global definitions from switch detail pages.

Workspace areas

Global definitions represent reusable policy objects. In the Segmentation page, select the dashlets for groups or segmentation rules to view all the groups and rules available.

Switch detail pages display the rules and communications associated with the selected switch. The simulation results provided apply to the selected switch.

The switches that are listed on the Segmentation page are filtered by the organization hierarchy applied in Cyber Vision Center.

Only sensor-based organization hierarchies apply to Segmentation pages. If you apply a network organization hierarchy, the Segmentation pages do not display any data.

Use this table to understand the Segmentation pages in Cyber Vision Center.

Table 2. Segmentation workspace areas

Area

Use it to

Segmentation page

Review global definition counts and segmentation-capable switches.

Global definitions: Asset groups

Review custom groups, network groups, SGTs, and the switches that a rule is used in.

Global definitions: Segmentation rules

Review global inter-group, intra-group, and common-service rules.

Switch detail: Communications

Inspect observed group-to-group communications in map, table, and participating-groups views.

Switch detail: Segmentation rules

Review the rules that apply to the selected switch.

Switch detail: Simulation

Simulate the effect of the current policy model on observed traffic from a switch.

Disabled-switch state

Select Enable segmentation only when you intend to include a disabled switch in segmentation analysis.


Enable segmentation on switches

You must enable segmentation on a switch to include the data from the device in the recommendation and simulation workflows.

By default, segmentation is disabled on switches.

Procedure

  1. From the Cyber Vision menu, choose Segmentation.

  2. Select one or more switches from the list.

  3. Select Enable segmentation.


Using Cyber Vision segmentation

Summary

Use the observed communications for a selected switch to define zones and conduits, review group-to-group communications, build rules, and simulate the rules before refining them.

Workflow

For each switch, carry out the following process.

  1. Select a switch to review the communications observed on the device.

  2. Use the map view to build zones and conduits, and create asset groups. The asset groups define the zones, by network group, common services, or recommended micro-segments.

  3. Review the communications between asset groups.

  4. Build the segmentation rules.

  5. Simulate the rules and review the impact of the designed rules. You can adjust the rules as needed before finally applying them on the target device.

Result

After you adjust the rules based on the simulation, repeat the process for the next switch.