Introduces Cyber Vision Segmentation in Release 5.6.0 and explains how asset groups, segmentation rules, recommendations, simulation, and switch capability fit together.
Segmentation for industrial networks is introduced in Cyber Vision Release 5.6.0 to help you define, recommend, and simulate segmentation policy on IE3300, IE3400, IE3500, and IE9300 switches.
Use Segmentation to plan policy with observed network evidence. You can review global policy objects, inspect what a switch observes, evaluate recommendations, and simulate the impact of the segmentation rules you want to apply, before applying the rules.
-
Asset groups provide segmentation identities, and segmentation rules define the permissions between those identities.
-
Asset group identities map to Security Group Tags (SGTs), and permissions map to Security Group ACLs (SGACLs).
You cannot deploy SGT mappings, generate switch-ready SGACL configuration, manage active policy state, or synchronize policy to switches in this release.
You can create and edit asset group membership, review and accept group recommendations, create and edit logical segmentation rules, define common-service relationships, and simulate policy impact.
You can evaluate a segmentation model against one year of observed traffic and review logical pseudo-SGACL output for training and simulation.
Cyber Vision filters the switches displayed on the Segmentation page according to the selected organization hierarchy level. Selecting a lower sensor-based hierarchy level limits the list to switches associated with that level and hides switches outside the selected context. If you select a network-based organization hierarchy, the Segmentation page does not display segmentation data. In the switches table, Cyber Vision shows whether each switch has Simulation or Enforcement capability in later releases of Cisco Cyber Vision.
-
IE3300 and IE3400 only support simulation. Data from these switches can only be used for simulation.
-
IE3500 and IE9300 can support enforcement. You can apply segmentation rules on these devices in later releases of Cyber Vision.
-
After upgrading to Cisco Cyber Vision Release 5.6.x, wait a few days before enabling segmentation. This delay allows Cyber Vision to populate the sensor-to-communication link data required for segmentation.
|
Feature |
Release |
Feature Description |
|---|---|---|
|
Cyber Vision segmentation |
Release 5.6.0 |
Introduces tools to model industrial network segmentation using observed switch communications. You can create and manage asset groups, review segmentation recommendations, configure inter-group, intra-group, default, and common-service rules, and simulate policy impact on supported switches. |