Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Cisco Secure Firewall

Updated: February 5, 2026

Overview

Describes how Cisco Secure Firewall is a robust security platform that delivers advanced threat protection, application visibility, intrusion prevention, VPN, and centralized policy enforcement across branches, for secure, scalable SD-WAN network deployments.

This comprehensive offering greatly simplifies threat protection by enforcing consistent security policies across physical, private, and public cloud environments.

Furthermore, it grants extensive visibility into your network infrastructure, swiftly identifying the origin and activity of potential threats. Armed with this knowledge, you can promptly take action to stop attacks before they have a chance to disrupt your operations.

In addition to traditional firewall capabilities, it provides features as:

  1. Application visibility and control

  2. User identity awareness and control

  3. Intrusion prevention and intrusion detection

  4. SSL/TLS decryption

  5. Reputation based blocking

  6. File and malware protection

  7. Virtual Private Network (VPN)

To further secure network deployments, Cisco Secure Firewall provides additional security capabilities in its later releases such as:

  • Encrypted Visibility Engine (EVE) that enhance encrypted traffic inspection without the need to implement full main-in-the-middle (MITM) decryption.

  • Elephant Flow Detection to detect and remediate elephant flows (flows that are typically larger than 1 GB/10 seconds) and avoid high CPU utilization and packet drops.

  • Cisco Secure Dynamic Attribute Connector (CSDAC) that brings agility and intelligence into your security policy management by leveraging tags and labels for policy configuration rather than traditional IP/network-based policy configuration.