Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Switch communications views

Want to summarize with AI?

Log in

Describes the switch communications views that show asset groups, protocols, and traffic observed for a selected switch.


On the Segmentation page, select a switch from the list to view the communications data observed on the switch. The Communications tab displays the asset groups, protocols, and traffic that Cyber Vision observed for the selected switch.

Communications views

Use this table to choose the communications view that matches what you need to inspect.

Table 1. Communications views

View

Shows

Use it to

Graph

Group relationships in a visual layout.

Understand how observed asset groups relate to each other.

Table

Group-to-group communications, protocols, and packet counts.

Inspect the protocol and traffic details behind the observed relationships.

Participating groups

Asset groups observed by the switch or manually added to the switch.

Confirm which groups are available for switch-specific rule review and simulation.


Segmentation recommendations

Cyber Vision proposes asset groups or rule changes from observed communication. You can accept, edit, or discard each recommendation.

Recommendation scope

Asset-group recommendations support microsegmentation inside one selected network group at a time. When Cyber Vision analyzes communications across a single switch, it first presents the networks that communicate across that switch. The clustering algorithm considers only assets in the selected network and checks communities using IP addresses that communicate through the switch.

Recommendations are based on observed communications, not inferred device intent. Review each recommendation before you accept it.

Cyber Vision does not need to place every interface in a new group. If it is not clear which child cluster an asset should belong to, Cyber Vision leaves that asset in the parent network group.

Existing grouped assets are not moved out of their groups. Only ungrouped assets can be recommended into existing groups.

Segmentation rules are recommendation at various levels.

Recommendation types and actions

Use this table to compare recommendation types and user responses.

Table 2. Recommendation types

Recommendation type

What you can do

Asset group recommendation

Accept as a global group, accept as a local group, edit the recommendation, or discard it.

New rule recommendation

Create an explicit rule when observed traffic would otherwise match the default rule, or discard the recommendation.

Rule update recommendation

Apply the recommended change to an existing rule, or discard the recommendation to keep the rule unchanged.

You can edit a saved rule at any time.


Create micro-segments from asset-group recommendations

Use micro-segmentation recommendations when you want to divide one network group into smaller logical zones before you model rules between groups.

Before you begin

Choose one network group whose observed communication patterns you want to review.

Procedure

  1. In Segmentation, open the switch context where Cyber Vision observed communication for the network group.

  2. Review the communication patterns for the selected network group.

  3. Run the asset-group recommendation workflow for the selected network group.

  4. Review the recommended clusters as a set.

    Cyber Vision presents the recommendations together and graphically so that you can review the relationships between the proposed groups.

  5. Edit, accept, or discard each recommendation.

  6. Accept a recommendation as global when the selected asset interfaces should move into a global group everywhere Cyber Vision observes those interfaces.

  7. Accept a recommendation as local when the selected asset interfaces should move into a local group only in the selected switch context.

  8. Leave unclear asset interfaces in the parent network group.

    Cyber Vision does not need to place every interface in a new micro-segment. Interfaces that do not form a distinct cluster continue to use the network group fallback identity.

Accepted asset-group recommendations create custom asset groups that act as micro-segments inside the selected network group. The new groups can be used by segmentation rules, recommendations, and simulation.