Cisco Firepower 4100 Series introduction

Today in this article I am going to talk about the Cisco Firepower 4100 series. As in my earlier articles I talk about the Cisco Firepower 2100 series and Cisco Firepower 9300 series which is one of the most powerful box in security domain.

Before we start with the Cisco 4100 series Firewall, A next generation firewall with NGFW image, below are the Cisco Firepower 2100 and Cisco Firepower 9300 articles. You can go to that articles as well for your references.

Cisco Firepower 9300 Series
Cisco 2100 Series Firepower
Cisco Firepower 2100 BOQ guide

Cisco Firepower 4100 Series is a family of four threat-focused NGFW security platforms. Their throughput range addresses data center and internet edge use cases. They deliver superior threat defense, at faster speeds, with a smaller footprint.  

Fig 1.1- Cisco Firepower 4100 Series

Cisco Firepower 4100 Series supports flow-offloading, programmatic orchestration, and the management of security services with RESTful APIs. Network Equipment Building Standards (NEBS)-compliance is supported by the Cisco Firepower 4120 platform.

Cisco Firepower 4100 series comes in various models and these models are 
  • Cisco Firepower 4110
  • Cisco Firepower 4120
  • Cisco Firepower 4140
  • Cisco Firepower 4150
Let's talk about the basic features of Continue reading

Cisco Firepower 9300 Series Introduction

Today I am going to talk about the Cisco Firepower 9300 series which is one of the most powerful box by Cisco systems. Cisco Firepower 9300 is a Next Generation Firewall and has various capabilities of AVC, IPS, AMP and URL filtering with the high throughput value.

Cisco Launches 3 different series in the Firepower services which is called as Next generation Firewalls with all the above mentioned services within a box. The Firepower series are
In this article, I will only talk about Cisco 9300 Firepower next generation firewalls. Although you can have two different images in the box. You can use ASA image or NGFW image in all these 3 boxes as per the requirement in your network. 

Cisco Firepower 9300 is a highly scalable with carrier-grade, modular platform designed for service providers, high-performance computing centres, large data centres, campuses, high-frequency trading environments, and other environments that require low (less than 5-microsecond offload) latency and exceptional throughput. 

Fig 1.1- Cisco Firepower 9300 NGFW

Technology Short Take 88

Welcome to Technology Short Take #88! Travel is keeping me pretty busy this fall (so much for things slowing down after VMworld EMEA), and this has made it a bit more difficult to stick to my self-imposed biweekly schedule for the Technology Short Takes (heck, I couldn’t even get this one published on Friday!). Sorry about that! Hopefully the irregular schedule is outweighed by the value found in the content I’ve collected for you.

Networking

Our Fellows Speak: “The Internet of the Future is Feminist“

The Internet Society invited four fellows from Latin America to the Forum on Internet Freedom in Africa 2017, which was held 27-29 September in Johannesburg. Two of the fellows, Veronica Vera and Anais Cordova-Paez of the ISOC Ecuador Chapter, shared their focus of work related to Internet freedom.

By Veronica Vera and Anais Cordova-Paez, ISOC Ecuador Chapter

Actions online are equally important toactions offline, which is why talking about freedom in the Internet is talking about human rights. In a world that is reproducing violence in all fields we need to talk about freedom embracing women’s rights; in this point of history seeking freedom is seeking gender equality.

Can we talk about Internet freedom if we don’t think about how we want Internet to be? And what do we have to do to achieve it? This is a conversation we need to have, because violence against women is everywhere, in all dimensions. In the cyberspace, human rights defenders, activists, or any woman who speaks out loud about her rights becomes a target of abuse, cyberstalking, revenge pornography, body shaming, and all kinds of violence that make us realize why it is really important to have a discussion about the principles of Continue reading

BrandPost: More SMB Love Needed

By Kevin Jackson In a recent post, titled “10 Surprising Facts About Cloud Computing and What It Really Is”, Zac Johnson highlighted some interesting facts about cloud computing in the SMB marketplace: Cloud Computing is up to 40 times more cost-effective for an SMB, compared to running its own IT system. 94% of SMBs have experienced security benefits in the cloud that they didn’t have with their on-premises service Recovery times for SMB are four times faster for businesses using cloud computing when compared to those not utilizing cloud services. For SMB, energy use and carbon emissions could be cut by 90% by using cloud computing, saving the environment and energy costs. These advantages show a strong indication that SMB information technology should be dominated by the adoption of cloud computing services.  Although one of the most prominent of these cloud services is Microsoft’s Office 365 (O365), a recent survey cited by CIO.com suggests that 83% of U.S. small and medium businesses (SMBs) have yet to use any form of O365.  If cloud services can deliver such remarkable improvements, why are SMBs holding back?According to the survey, part of the reason is that SMBs often Continue reading

Cisco brings intent-based networking to the data center

A decade ago, one of the big knocks on Cisco was that its products were difficult to deploy and often even harder to manage. Over the past few years, though, particularly since Chuck Robbins took the helm as CEO, the company has been laser focused on making its products simpler to operate.It’s important to understand that making products easy to use is actually much more difficult than those that are hard to use. As an example, Cisco’s network-intuitive, intent-based networking solution enables the operations for the campus network to be fully automate, dramatically cutting the operational overhead required by network engineers.MORE ON NETWORK WORLD: What is intent-based networking? This week, Cisco is bringing the benefits of intent-based networking to the data center with the 3.0 version of its Application Centric Infrastructure (ACI) software-defined networking (SDN) product. The latest release of ACI will increase network automation, simplify operational tasks and make it easier to secure agile workloads regardless of whether they are in containers, in virtual machines, on bare metal or in on-premises data centers. To read this article in full or to leave a comment, please click here

Cisco brings intent-based networking to the data center

A decade ago, one of the big knocks on Cisco was that its products were difficult to deploy and often even harder to manage. Over the past few years, though, particularly since Chuck Robbins took the helm as CEO, the company has been laser focused on making its products simpler to operate.It’s important to understand that making products easy to use is actually much more difficult than those that are hard to use. As an example, Cisco’s network-intuitive, intent-based networking solution enables the operations for the campus network to be fully automate, dramatically cutting the operational overhead required by network engineers.MORE ON NETWORK WORLD: What is intent-based networking? This week, Cisco is bringing the benefits of intent-based networking to the data center with the 3.0 version of its Application Centric Infrastructure (ACI) software-defined networking (SDN) product. The latest release of ACI will increase network automation, simplify operational tasks and make it easier to secure agile workloads regardless of whether they are in containers, in virtual machines, on bare metal or in on-premises data centers. To read this article in full or to leave a comment, please click here

New Optimizations Improve Deep Learning Frameworks For CPUs

Today, most machine learning is done on processors. Some would say that acceleration of learning has to be done on GPUs, but for most users that is not good advice for several reasons. The biggest reason is now the Intel Xeon SP processor, formerly codenamed “Skylake.”

Up until recently, the software for machine learning has been often more optimized for GPUs than anything else. A series of efforts by Intel have changed that – and when coupled with Platinum version of the Intel Xeon SP family, the top performance gap is closer to 2X than it is to 100X. This

New Optimizations Improve Deep Learning Frameworks For CPUs was written by Timothy Prickett Morgan at The Next Platform.

Stuff The Internet Says On Scalability For October 13th, 2017

Hey, it's HighScalability time: 

 

Tech is transforming how food is being grown. Lots of opportunity for local nerdy production. Greenhouses even look like dartacenters! (This Tiny Country Feeds the World)

 

If you like this sort of Stuff then please support me on Patreon.

 

  • 320 trillion: ops/second in Nvidia driverless-car computer; .25%: Lambda invocations impacted by cold starts; $30,000: monthly take hijacking computers to mine cryptocurrency; 400 gbps: Ethernet standard to be ratified this year; 2.1 million: MySQL 8.0 query/second; 100,000: Kiva robots owned by Amazon; 50,000: greenhouses in Egypt's new farm city; 100 petabytes: new hard drives ordered by Backblaze; 20 million: max Bitcoin users per month; 662 million: unused vacation days in US; 92 billion: Pornhub views per year; 1,000: new Facebook hires to review ads; 12 milion: Tinder matches per day; $1 billion: Google training grants; 

  • Quotable Quotes: 
    • @toddmotto: Space X sends a rocket up into space. Lands back on its feet back on earth 7minutes later. I can't even run an npm install in that time.
    • nappy-doo: Years ago, I started at Google, and was in Charlie's Continue reading

A Celebration of Learning at Grace Hopper

A Celebration of Learning at Grace Hopper

A Celebration of Learning at Grace Hopper Photo by Cloudflare Staff

Over the course of my career, I’ve been to many conferences, interacted with thousands of candidates, and attended countless keynotes, roundtables, and sessions. I can say without a doubt, that the Grace Hopper Celebration, stood out from the rest. And I think my team would agree.

During the three day event, we screened more than 50 candidates, conducted 24 onsite interviews, and had more than 600 people visit our booth. Not bad for a booth near the back competing with an AirBnB booth that had a literal house on top of it.

Before the conference, we were expecting about 200 visitors to our booth, so the turnout clearly exceeded our expectations. More importantly, we couldn’t have predicted the breadth of talent we would interact with at the conference. That’s not to say that I was surprised; Grace Hopper attracts women from all over the world, including students, seasoned professionals, hackers, engineers, and business leaders. This year was the biggest yet, with more than 12,000 attendees from across all tech sectors, backgrounds, and interests. So I certainly wasn’t surprised to meet all of these women, but I was definitely inspired.

A Celebration of Learning at Grace Hopper Photo by Cloudflare Staff

My team Continue reading

Pre-Provisioning Your FEXen For Fun and Profit

In this post, I’ll discuss how to protect your income by using the FEX pre-provisioning capability of NXOS. I discovered the hard way that not pre-provisioning your FEX can have catastrophic side effects. What better story to post on Friday the 13th?

Pre-Provisioning your Cisco FEX

FEXy Time

Attaching a FEX to a Nexus switch is relatively simple; a few commands on each of the two switches the FEX connects to and it’s up and running. It’s also possible to pre-provision the FEX modules in the configuration. The documentation doesn’t make it entirely clear why this would be desirable, beyond the rather cryptic:

In some Virtual Port Channel (vPC) topologies, pre-provisioning is required for the configuration synchronization feature. Pre-provisioning allows you to synchronize the configuration for an interface that is online with one peer but offline with another peer.

Got that? In other words, pre-provisioning makes it possible to configure a FEX module that isn’t there yet, or that is powered down, or is only connected to one side of a VPC pair for some inexplicable reason. Maybe I’ve ordered some
(plural of FEX) and want to configure the ports ahead of time? Whatever the rationale for doing so, I’ve never previously needed pre-provisioning Continue reading

Strong Encryption Is Essential to Our Security, Not a Barrier

Encryption technologies help protect user data from theft and they help secure critical infrastructure and services that societies depend on. But, encryption is also available to criminals and terrorists. This puts law enforcement agencies in a difficult position. In effect, they are faced with the dilemma of how to gather evidence on criminals and other adversaries who may be using encryption, while at the same time, not putting the safety of law-abiding citizens at greater risk. While we at the Internet Society recognize the challenges facing law enforcement, we believe that strong encryption should be available to all Internet users as it is an important technical solution to protect their communications and data.

This dilemma was voiced by U.S. Deputy Attorney General Rod Rosenstein in a recent speech. He argued that “Encrypted communications that cannot be intercepted and locked devices that cannot be opened are law-free zones that permit criminals and terrorists to operate without detection by police and without accountability by judges and juries.”

This problem, claimed Rosenstein, can be solved with what he calls “responsible encryption.” To Rosenstein, “responsible encryption” could “involve effective, secure encryption that allows access only with judicial authorization.” Unfortunately, if Continue reading