Connection and Security-Related Connection Events

The following topics describe how to use connection and security events tables.

Connection events

A connection event is a log that records connections that your managed devices monitor. It includes Security-Related connection events. These are connections that the reputation-based Security Intelligence feature blocks. It also provides granular control over which connections to log, when to log them, and where to store the data.

Connection event detection sources

Connection events generally include transactions detected by:

  • Access control policies

  • Decryption policies

  • Prefilter policies (captured by prefilter or tunnel rules)

  • DNS Block lists

  • URL Block lists

  • Network (IP address) Block lists

Settings in rules and policies give you granular control over which connections you log, when you log them, and where you store the data.

For more information, refer to Connection Logging.

Connection vs. security-related connection events

A Security-Related connection event is a connection event that

  • is generated whenever a session is blocked or monitored by the reputation-based Security Intelligence feature, and

  • has an identical corresponding connection event that can be viewed and analyzed independently.

Event processing and storage

The system creates an identical connection event for every Security-Related connection event. You can view and analyze Security-Related connection events independently. The system stores and prunes these events separately.

The system enforces Security Intelligence before more resource-intensive evaluations. When Security Intelligence blocks a connection, the resulting event lacks information from subsequent evaluations, such as user identity.


Note


In this guide, information about connection events also pertains to Security-Related connection events, unless otherwise noted.


NetFlow connections

NetFlow connections are unidirectional end-of-connection events that

  • supplement connection data gathered by managed devices,

  • are generated from records broadcast by NetFlow exporters, and

  • are logged in the Secure Firewall Management Center database.

NetFlow connection characteristics

The system logs NetFlow records as unidirectional end-of-connection events in the Secure Firewall Management Center database. The available information for these connections differs somewhat from connections detected by your access control policy. For more information, refer to Differences between NetFlow and managed device data.

Connection summaries (aggregated data for graphs)

Connection summaries are collections of aggregated data that

  • aggregate connection data over 5-minute intervals,

  • generate connection graphs and traffic profiles, and

  • support custom workflows based on connection summary data.

The system aggregates connection data collected over five-minute intervals into connection summaries, which the system uses to generate connection graphs and traffic profiles. Optionally, you can create custom workflows based on connection summary data, which you use in the same way as you use workflows based on individual connection events.

To be aggregated, multiple connections must:

  • represent the end of connections

  • have the same source and destination IP addresses, and use the same port on the responder (destination) host

  • use the same protocol (TCP or UDP)

  • use the same application protocol

  • either be detected by the same managed device or by the same NetFlow exporter

Each connection summary includes total traffic statistics, as well as the number of connections in the summary. NetFlow exporters generate unidirectional connections. The system increments a summary's connection count by 2 for every NetFlow-based connection.

There are no connection summaries specifically for Security-Related connection events, although the system can aggregate corresponding end-of-connection events into connection summary data.


Note


Connection summaries do not contain all information associated with their aggregated connections. For example, because client information is not used to aggregate connections into connection summaries, summaries do not contain client information.


Long-running connections

A long-running connection is a monitored session that

  • spans two or more five-minute intervals during which the system aggregates connection data,

  • increases the connection count only when the session starts, and

  • uses estimated calculations based on constant rates rather than actual data for each interval.

Connection counting and traffic calculation behavior

When the system calculates the number of packets and bytes for long-running connections, it does not report actual transmission data for each five-minute interval. Instead, it uses a constant transmission rate and calculates estimates based on the total number of packets and bytes transmitted, connection length, and the connection portion in each interval.

Combined connection summaries from external responders

A combined connection summary is a data optimization technique that

  • reduces connection data storage space by aggregating summaries when one host is not on the monitored network,

  • improves connection graph rendering performance by combining connections that meet summary aggregation criteria, and

  • displays external instead of an IP address for non-monitored hosts in connection summaries and graphs.

Aggregation criteria and display behavior

To reduce the space required to store connection data and speed up the rendering of connection graphs, the system combines connection summaries when:

  • one of the hosts involved in the connection is not on your monitored network

  • except for the IP address of the external host, the connections in the summaries meet the summary aggregation criteria

When viewing connection summaries in the Analysis > Connections submenu pages, and when working with connection graphs, the system displays external instead of an IP address for the non-monitored hosts.


Note


As a consequence of this aggregation, if you attempt to drill down to the table view of connection data (that is, access data on individual connections) from a connection summary or graph that involves an external responder, the table view contains no information.


Connection and Security-Related Connection event fields

This reference provides the complete list of connection and security intelligence event fields that can be used for monitoring, logging, and analysis in Firepower systems. These fields help administrators track network connections and security-related events.

Connection and Security-Related Connection Event fields

In the Secure Firewall Management Center web interface, you can view and search connection and Security-Related connection events using tabular and graphical workflows under the Analysis > Connections > Security-Related Events.


Note


For each Security-Related connection event, there is an identical, separately stored connection event. All Security-Related connection event have a populated Security Intelligence Category field.

The information available for any individual event can vary depending on how, why, and when the system logged the connection.

Search constraints

Fields marked with an asterisk (*) on search pages constrain connection graphs and connection summaries. Because connection graphs are based on connection summaries, the same criteria that constrain connection summaries also constrain connection graphs.

If invalid search constraints are used for connection summaries, and the results are viewed in a connection summary page within a custom workflow, they are labeled as not applicable (N/A) and marked with a strikethrough.

Syslog fields

Most fields appear both in the Secure Firewall Management Center web interface and as syslog messages. Fields without a listed syslog equivalent are not available in syslog messages. A few fields are syslog-only, as noted, and few others are separate fields in syslog messages but are consolidated fields in the web interface or vice-versa.

Initiator and responder, source and destination, and sender and receiver fields

A field category is a classification of network event terminology that
  • distinguishes between different roles in network connections, security events, and file transfers,

  • applies to specific event types such as connection, intrusion, and file/malware events, and

  • represents different aspects of network communication flow that may not always align with each other.

Field terminology comparison

These field types have different relationships based on the event context.

Table 1. Comparison of terms

Fields

Event Type

Description

Initiator/Responder

Connection

The initiator and responder of the connection.

The connection initiator is not necessarily the same as the intrusion source or the malware file sender.

Source/Destination

Intrusion

The source and destination of the attack.

The source of an intrusion event can be the initiator or the responder of the connection.

Sender/Receiver

(Sending..., Receiving...)

File, Malware

The sender and receiver of a file or malware.

The file sender is not necessarily the connection initiator. Files may be uploaded or downloaded.

Connection event reasons

Lists the reasons for connection events logged by the system, including descriptions for each reason.

The Reason field in a connection event displays why the connection was logged. Each reason corresponds to specific actions or circumstances in the connection event.

The table lists each connection event reason logged by the system, with a description of what triggers each reason and the resulting system action.

Reason

Description

Content Restriction

The system modified the packet to enforce content restrictions related to the Safe Search feature.

DNS Block

The system denied the connection without inspection, based on the domain name and Security Intelligence data. A reason of DNS Block is paired with an action of Block, Domain not found, or Sinkhole, depending on the DNS rule action.

DNS Monitor

The system would have denied the connection based on the domain name and Security Intelligence data, but you configured the system to monitor, rather than deny, the connection.

Elephant Flow

The connection is large enough to be considered an elephant flow, which is a flow that can be large enough to affect overall system performance. By default, elephant flows are larger than 1GB/10 seconds. You can adjust the byte and time thresholds for identifying elephant flows in the Firewall Threat Defense CLI using the system support elephant-flow-detection command. For more information, see the Cisco Secure Firewall Threat Defense Command Reference .

Note

 

A flow is considered as elephant flow only when both the byte and time thresholds are surpassed.

You can create a custom dashboard to correlate elephant flows and other interrelated metrics, for example, CPU metrics such as Snort, System, and Physical Cores. For more information, refer to System Monitoring and Troubleshooting chapter.

Elephant Flow Exempted

IThis reason appears when an elephant flow is detected and matches the L4 ACL rules that exempt certain flows from remediation.

Encrypted Visibility Block

Connections that are blocked by the Encrypted Visibility Engine.

Encrypted Visibility IoC

Indications of Compromise (IoC) events detected by Encrypted Visibility Engine for connection events with high and very very high malware confidence level. IoC events are triggered for encrypted sessions generated from a host using a malicious client. You can view information, such as IP address, MAC address, and OS information of the malicious host, and the timestamp of the suspicious activity.

Encrypted Visibility Exempt

Connecitons allowed bypassing the Encrypted Visibility Engine block action.

File Block

The connection contained a file or malware file that the system prevented from being transmitted. File Block reason is always paired with an action of Block.

File Custom Detection

The connection contained a file on the custom detection list that the system prevented from being transmitted.

File Monitor

The system detected a particular type of file in the connection.

File Resume Allow

File transmission was originally blocked by a Block Files or Block Malware file rule. After a new access control policy allowing the file was deployed, the HTTP session automatically resumed. This reason only appears in inline deployments.

File Resume Block

File transmission was originally allowed by a Detect Files or Malware Cloud Lookup file rule. After a new access control policy blocking the file was deployed, the HTTP session automatically stopped. This reason only appears in inline deployments.

Intelligent App Bypass

The Intelligent Application Bypass (IAB) mode:

  • If the action is Trust, IAB was in bypass mode. Matching traffic passed without further inspection.

  • If the action is Allow, IAB was in test mode. Matching traffic was available for further inspection.

Intrusion Block

Snort2 Engine—The system blocked or would have blocked an exploit (intrusion policy violation) detected in the connection. A reason of Intrusion Block is paired with an action of Block for blocked exploits and Allow for would-have-blocked exploits.

Snort3 Engine—When there is a "would have dropped" result, the connection event reason is blank, instead of "Intrusion block". The "would have dropped" event is treated the same as “Allow” in regards to the connection event reason being populated.

Intrusion Monitor

The system detected, but did not block, an exploit detected in the connection. This occurs when the state of the triggered intrusion rule is set to Generate Events.

IP Block

The system denied the connection without inspection, based on the IP address and Security Intelligence data. A reason of IP Block is always paired with an action of Block.

IP Monitor

The system would have denied the connection based on the IP address and Security Intelligence data, but you configured the system to monitor, rather than deny, the connection.

SSL Block

The system blocked an encrypted connection based on the TLS/SSL inspection configuration. A reason of SSL Block is always paired with an action of Block.

URL Block

The system denied the connection without inspection, based on the URL and Security Intelligence data. A reason of URL Block is always paired with an action of Block.

URL Monitor

The system would have denied the connection based on the URL and Security Intelligence data, but you configured the system to monitor, rather than deny, the connection.

User Bypass

The system initially blocked a user’s HTTP request, but the user clicked through a warning page to view the site. A reason of User Bypass is always paired with an action of Allow.

Requirements for populating connection event fields

A connection event field population requirement is a system condition that

  • determines what information appears in connection events based on multiple system factors,

  • depends on appliance models, licensing, traffic characteristics, and detection methods, and

  • varies according to evaluation stage, logging method, and specific system configurations.

Factors affecting connection event field population

Several factors determine which fields are populated in connection events:

Appliance Model and License

Many features require that you enable specific licensed capabilities on target devices, and many features are only available on some models.

Traffic Characteristics

The system reports only information that is present and detectable in network traffic. For example, there could be no user associated with an initiator host, or no referenced host detected in a connection where the protocol is not DNS, HTTP, or HTTPS.

Origin/Detection Method: Traffic-Based Detection vs NetFlow

With the exception of NetFlow-only fields, the information available in NetFlow records is more limited than the information generated by traffic-based detection; see Differences between NetFlow and managed device data.

Evaluation Stage

Each type of traffic inspection and control occurs where it provides maximum flexibility and performance.

For example, the system enforces Security Intelligence before more resource-intensive evaluations. When a connection is blocked by Security Intelligence, the resulting event does not contain the information that the system would have gathered from subsequent evaluation, for example, user identity.

Logging Method: Beginning or End of Connection

When the system detects a connection, whether you can log it at its beginning or its end (or both) depends on how you configure the system to detect and handle it.

Beginning-of-connection events do not have information that must be determined by examining traffic over the duration of the session; for example, the total amount of data transmitted or the timestamp of the last packet in the connection. Beginning-of-connection events are also not guaranteed to have information about application or URL traffic in the session, and do not contain any details about the session’s encryption. Beginning-of-connection logging is usually the only option for blocked connections.

Connection Event Type: Individual vs Summary

Connection summaries do not contain all of the information associated with their aggregated connections. For example, because client information is not used to aggregate connections into connection summaries, summaries do not contain client information.

Keep in mind that connection graphs are based on connection summary data, which use only end-of-connection logs. Configure your system to log end-of-connection data for connection graphs and summaries to display data.


Note


Security-related connection events include security intelligence events and other connection events, such as the ones that triggered intrusion or malware events. The Security Intelligence Summary workflow groups the security-related connection events that do not have a security intelligence category and displays the count without a Security Intelligence Category value.


Other Configurations

Other configurations that affect connection logging include, but are not limited to:

  • ISE-related fields are populated only if you configure ISE, in connections associated with users who authenticate via an Active Directory domain controller. Connection events do not contain ISE data for users who authenticate via LDAP, RADIUS, or RSA domain controllers.

  • The Security Group Tag (SGT) fields are populated only if you configure ISE as an identity source or add custom SGT rule conditions.

  • Prefilter-related fields (including tunnel zone information in security zone fields) are populated only in connections handled by a prefilter policy.

  • TLS/SSL-related fields are populated only in encrypted connections handled by a decryption policy. You can view the values of the fields using a Do Not Decrypt rule action if you do not need to decrypt the traffic.

  • File information fields are populated only in connections logged by access control rules associated with file policies.

  • Intrusion information fields are populated only in connections logged by access control rules either associated with intrusion policies or using the default action.

  • QoS-related fields are populated only in connections subject to rate limiting.

  • The Reason field is populated only in specific situations, such as when a user bypasses an Interactive Block configuration.

  • The Domain field is only present if you have ever configured the Secure Firewall Management Center for multitenancy.

  • An advanced setting in the access control policy controls the number of characters the system stores in the connection log for each URL requested by monitored hosts in HTTP sessions. If you use this setting to disable URL logging, the system does not display individual URLs in the connection log, although you can still view category and reputation data, if it exists.

  • For the connection event to display URL category and reputation, you must include the applicable URL rules in an access control policy and configure the rule with URL category and URL reputation under the URLs tab. URL category and reputation do not appear in an event if the connection is processed before it matches a URL rule.

Information available in connection event fields

The table lists the conditions in which the system populates connection and security intelligence fields. Columns represent different event types:

  • Origin: Direct (events representing connections detected and handled by a system-managed device)

  • Origin: NetFlow (events representing connections exported by a NetFlow exporter)

  • Logging: Start (events representing connections logged at their beginning)

  • Logging: End (events representing connections logged at their end)

A "yes" in the table means the system can populate a field but only reports detectable information in network traffic. For example, TLS/SSL-related fields populate only for encrypted connections handled by a decryption policy.

Connection Event Field

Origin: Direct

Origin: NetFlow

Logging: Start

Logging: End

Access Control Policy

yes

no

yes

yes

Access Control Rule

yes

no

yes

yes

Action

yes

no

yes

yes

Application Protocol

yes

yes

if available

yes

Application Protocol Category & Tag

yes

yes

if available

yes

Client Application

yes

no

if available

yes

Client Application Category & Tag

yes

no

if available

yes

Payload Application

yes

no

if available

yes

Payload Application Category & Tag

yes

no

if available

yes

Web Application

yes

no

if available

yes

Web Application Category & Tag

yes

no

if available

yes

Using Connection and Security-Related Connection Event Tables

You can use the Secure Firewall Management Center to view a table of connection or Security-Related connection events. Then, you can manipulate the event view depending on the information you are looking for.

In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.

The page you see when you access connection graphs differs depending on the workflow you use. You can use a predefined workflow, which terminates in a table view of events. You can also create a custom workflow that displays only the information that matches your specific needs.

When you are using a connection or Security Intelligence workflow table, you can perform many common actions.

Note that when you constrain connection events on a drill-down page, the packets and bytes from identical events are summed. However, if you are using a custom workflow and did not add a Count column to a drill-down page, the events are listed individually and packets and bytes are not summed.

Note that Connection Events table view displays 1 of Many instead of how many pages of events are available if your system generates more than 25 connection events.

Before you begin

You must be an Admin or Security Analyst user to perform this task.

Procedure


Step 1

Choose either of the following:

  • Analysis > Connections > Events (for connection events)
  • Analysis > Connections > Security-Related Events

Note

 

If a connection graph appears instead of a table, click (switch workflow) by the workflow title, and choose the predefined Connection Events workflow, or a custom workflow. Note that all predefined connection event workflows—including connection graphs—terminate in a table view of connections.

Step 2

You have the following choices:

  • Time Range — To adjust the time range, which is useful if no events appear, see Change the time window.

  • Data Source — If data is stored remotely using Security Analytics and Logging (On Premises), and you have good reason to change the data source, choose a data source. For important information about this option, see Work in Secure Firewall Management Center with Connection Events Stored on a Secure Network Analytics Appliance.

  • Field Names — To learn more about the contents of the columns in the table, see Connection and Security-Related Connection event fields.

    Tip

     

    In the table view of events, multiple fields are hidden by default. To change the fields that appear, click the Disable Column Disable column icon in any column name to display a field chooser.

  • Additional information — To view data in available sources external to your system, right-click an event value. The options you see depend on the data type and include public sources; other sources depend on the resources you have configured. For information, see Event investigation using web-based resources

  • External intelligence — To gather intelligence about an event, right-click an event value in the table and choose from a Cisco or third-party intelligence source. For example, you can get details about a suspicious IP address from Cisco Talos. The options you see depend on the data type and the integrations that are configured on your system. For more information, see Event investigation using web-based resources.

  • Host Profile — To view the host profile for an IP address, click Host Profile or, for hosts with active indications of compromise (IOC) tags, Compromised Host that appears next to the IP address.

  • User Profile — To view user identity information, click the user icon that appears next to the User Identity, or for users associated with IOCs, Red User.

  • Files and Malware —To view the files, including malware, detected or blocked in a connection, click View Files and proceed as described in View files and malware detected in a connection.

  • Intrusion Events — To view the intrusion events associated with a connection, as well as their priority and impact, click Intrusion Events in the Intrusion Events column and proceed as described in View intrusion events for a connection.

    Tip

     

    To quickly view intrusion, file, or malware events associated with one or more connections, check the connections using the check boxes in the table, then choose the appropriate option from the Jump to drop-down list. Note that because they are blocked before access control rule evaluation, there can be no files or intrusions associated with connections blocked by Security Intelligence. You can only see this information for a Security Intelligence event if you configured Security Intelligence to monitor, rather than block, connections.

  • Certificate — To view details about an available certificate used to encrypt a connection, click Enabled Lock in the SSL Status column.

  • Constrain — To constrain the columns that appear, click Close (close icon) in the column heading that you want to hide. In the pop-up window that appears, click Apply.

    Tip

     

    To hide or show other columns, check or clear the appropriate check boxes before you click Apply. To add a disabled column back to the view, expand the search constraints, then click the column name under Disabled Columns.

  • Delete Events — (Security-Related connection event tables only) To delete some or all items in the current constrained view, check the check boxes next to items you want to delete and click Delete or click Delete All.

  • Drill Down — See Use drill-down pages.

    Tip

     

    To drill down using one of several Monitor rules that matched a logged connection, click an N  Monitor Rules value. In the pop-up window that appears, click the Monitor rule you want to use to constrain connection events.

  • Navigate This Page — See Workflow page traversal tools.

  • Navigate Between Pages — To navigate between pages in the current workflow, keeping the current constraints, click the appropriate page link at the top left of the workflow page.

  • Navigate Between Event Views — To navigate to other event views to view associated events, click Jump to and choose the event view from the drop-down list.

  • Sort — To sort data in a workflow, click the column title. Click the column title again to reverse the sort order.


View files and malware detected in a connection

View file events associated with connections that match access control rules with file policies to identify detected files and malware.

If you associate a file policy with one or more access control rules, the system can detect files (including malware) in matching traffic. Use the Analysis > Connections > Events menu options to see the file events, if any, associated with the connections logged by those rules. Instead of a list of files, the Secure Firewall Management Center displays view files (The image illustrates a user interface displaying a list of files and detected malware associated with a specific network connection, highlighting the importance of monitoring for security threats.) in the Files column. The number on the view files indicates the number of files (including malware files) detected or blocked in that connection.

Not all file and malware events are associated with connections. Specifically:

  • Malware events detected by Secure Endpoint ("endpoint-based malware events" ) are not associated with connections. Those events are imported from your Secure Endpoint deployment.

  • Many IMAP-capable email clients use a single IMAP session, which ends only when the user exits the application. Although long-running connections are logged by the system, files downloaded in the session are not associated with the connection until the session ends.

In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.

Before you begin

You must be an Admin or Security Analyst user to perform this task.

Follow these steps to view files and malware detected in a connection:

Procedure


Step 1

Go to Analysis > Connections > Events and choose the relevant option.

Step 2

While using a connection event table, click View Files.

A pop-up window appears with a list of the files detected in the connection as well as their types, and if applicable, their malware dispositions.

Step 3

You have the following choices:

  • View: To view a table view of file events, click a File's View.

  • View: To view details in a table view of malware events, click a Malware File’s View.

  • Track: To track the file’s transmission through your network, click a File’s Trajectory.

  • View: To view details on all of the connection’s detected file or malware events detected by Malware Defense ("network-based malware events"), click View File Events or View Malware Events.


You can now view files and malware detected in connections and access detailed file events, malware events, or track file trajectories through your network.

View intrusion events for a connection

Enable detailed analysis of intrusion events linked to active or logged connections, including their priority and the potential impact to your network.

If you associate an intrusion policy with an access control rule or default action, the system can detect exploits in matching traffic. Use the Analysis > Connections > Events menu options to see the intrusion events, if any, associated with logged connections, as well as their priority and impact.

In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.

Before you begin

You must be an Admin or Security Analyst user to perform this task.

Follow these steps to view intrusion events for a connection:

Procedure


Step 1

Go to Analysis > Connections > Events and choose the relevant option.

Step 2

While using a connection event table, click Intrusion Events in the Intrusion Events column.

Step 3

In the pop-up window that appears:

  • Click a Listed Event’s View to view details in the packet view.
  • Click View Intrusion Events to view details on all of the connection's associated intrusion events.

You can now view the intrusion events associated with the selected connection, including their priority and impact details.

Encrypted connection certificate details

You can use options under the Analysis > Connections menu to display the public key certificate (if available) used to encrypt a connection handled by the system. The certificate contains the information listed in this reference.

The table lists and describes the certificate attributes you can view when displaying the public key certificate for encrypted connections handled by the system.

Table 2. Encrypted connection certificate details

Attribute

Description

Subject/Issuer Common Name

The host and domain name of the certificate subject or certificate issuer.

Subject/Issuer Organization

The organization of the certificate subject or certificate issuer.

Subject/Issuer Organization Unit

The organizational unit of the certificate subject or certificate issuer.

Not Valid Before/After

The dates when the certificate is valid.

Serial Number

The serial number assigned by the issuing CA.

Certificate Fingerprint

The SHA hash value used to authenticate the certificate.

Public Key Fingerprint

The SHA hash value used to authenticate the public key contained within the certificate.

View the connection summary page

Display summary graphs of network connections to analyze activity by time interval, device, or other criteria.

The connection summary page provides aggregated graphs that help monitor network activity. Only users with specific role permissions can access this page. Graphs are organized by criteria such as connection count over chosen intervals; however, you cannot drill down into individual connection events from these summaries.

You can perform almost all the same actions on connection summary graphs that you can perform on connection graphs. However, because the graphs on the connection summary page are based on aggregated data, you cannot examine the individual connection events on which the graphs are based. In other words, you cannot drill down to a connection data table view from a connection summary graph.

In a multidomain deployment, you can view data for the current domain and for any descendant domains. You cannot view data from higher level or sibling domains.

Procedure


Step 1

Choose Overview > Dashboards heading > Dashboard.

Step 2

Click (switch dashbaord), and then choose Connection Summary.

Step 3

From the Select Device list, choose the device whose summary you want to view, or choose All to view a summary of all devices.

Step 4

To manipulate and analyze the connection graphs, proceed as described in Use connection event graphs.

Tip

 

To detach a connection graph so you can perform further analysis without affecting the default time range, click View.


The connection summary page displays with graphs showing network activity organized by your selected criteria and device scope.

History for Connection and Security Intelligence Events

Documents the history and details of connection and security intelligence events, including feature updates and changes across various versions.

Feature

Minimum Firewall Management Center

Minimum Firewall Threat Defense

Details

New Connection Event Reason - Elephant Flow.

7.1

Any

Refer to Connection event reasons.

NAT Translated IP Address and Port

7.1

Any

Four new fields are added to the connection and security intelligence event table:

  • NAT Source IP

  • NAT Destination IP

  • NAT Source Port

  • NAT Destination Port

Ability to choose a data source when working with certain events stored remotely

7.0

Any

Refer to History for workflows.

DNS filtering

7.0

6.7 (Beta feature)

Any

When DNS filtering is enabled:

  • The DNS Query field may hold the domain associated with DNS filtering matches.

  • If the URL field is empty but DNS Query, URL Category, and URL Reputation have values, the event was generated by the DNS filtering feature, and the category and reputation apply to the domain specified in DNS Query.

  • Refer to DNS Filtering and Events in the Cisco Secure Firewall Management Center Device Configuration Guide .

Removal of support for custom tables for connection events

6.6

Any

You can no longer create custom tables for connection events. If you upgrade, any pre-existing custom tables for connection events are still available but always return no results.

There is no change to other types of custom tables.

New/Modified screens: The Tables option on Analysis > Advanced Custom Tables

Platform: Firewall Management Center

Removal of ability to Delete and Delete All connection events

6.6

Any

The Delete and Delete All buttons have been removed from connection events table pages.

To purge all connection events, see Data Purge and Storage .

New/Modified screens: Analysis > Connections > Events

Platform: Firewall Management Center

New fields for VRF and SGT

6.6

Any

  • Ingress Virtual Router (Syslog: IngressVRF)

  • Egress Virtual Router (Syslog: EgressVRF)

  • DestinationSecurityGroupType (Syslog only)

  • SourceSecurityGroupType (Syslog only)

New and changed Security Group Tag fields

6.5

Any

Changes to fields in the Firewall Management Center web interface:

  • Changed fields: Security Group Tag is now Source SGT

  • New fields: Destination SGT

Changes to syslog fields:

  • Changed fields:

    SecurityGroup is now SourceSecurityGroupTag

  • New fields:

    • SourceSecurityGroup

    • DestinationSecurityGroup

    • DestinationSecurityGroupTag

Supported Platforms: Firewall Management Center , managed devices

New syslog field: Event Priority

6.5

Any

This field identifies connection events as High priority when they are associated with intrusion, file, malware, or Security Intelligence events.

Unique identifier for connection event in syslogs

6.4.0.4

Any

The following syslog fields collectively uniquely identify a connection event: DeviceUUID, First Packet Time, Connection Instance ID, and Connection Counter.