Always Learning

Advanced Search

Cisco Firepower Threat Defense (FTD)

Cisco Firepower Threat Defense (FTD)

Configuration and Troubleshooting Best Practices for the Next-Generation Firewall (NGFW), Next-Generation Intr

Nazmul Rajib

Dec 2017, Paperback, 800 pages
ISBN13: 9781587144806
ISBN10: 1587144808
Special online offer - Save 30%
Was 51.99, Now 36.39Save: 15.60
  • Print pagePrint page
  • Email this pageEmail page
  • Share

This is the definitive guide to best practices and advanced troubleshooting techniques for the newest versions of Cisco’s flagship Firepower Threat Defense (FTD) system running on Cisco ASA, VMWare ESXi, and FXOS platforms.

The authors draw on unsurpassed personal experience supporting Cisco Firepower customers worldwide, presenting detailed knowledge for configuring Firepower features to maximize performance and avoid trouble. Writing for consultants, service providers, and enterprise or government technical and security professionals, they show how to use Firepower’s robust tools to investigate a wide variety of technical issues. Readers will also find expert guidance on other technologies that integrate Sourcefire capabilities, including ACS, ISE, and Splunk. Coverage includes:

  • Best practices for installation and hardware troubleshooting
  • Best practices and troubleshooting of deployment issues, traffic control policies, system administration, user identity, and access control
  • Best practices for generating log, report and troubleshoot data

Each consistently-organized chapter contains definitions, flowcharts or architectural diagrams, best practices, configuration steps (with detailed screenshots), troubleshooting tools and techniques, and FAQs drawn directly from issues raised by customers at Cisco Technical Assistance Centers.

The first Cisco guide to cover Firepower material that will be included in the new CCIE Security v5 exams, Cisco Firepower Threat Defense (FTD) also includes quizzes to help CCIE candidates prepare.

Part I: Best Practices for Installation and Hardware Troubleshooting
1. Firepower Threat Defense (FTD) on ASA
2. Firepower Threat Defense (FTD) Deployment on VMWare ESXi
3. Firepower Threat Defense (FTD) on FXOS
4. Management of Firepower Threat Defense

Part II: Best Practices and Troubleshooting of Deployment Issues
5. Issues with Device Registration and Communication
6. Issues with Licensing a Firepower Device
7. Interface and Zones
8. High Availability

Part III: Best Practices and Troubleshooting of Traffic Control Policies
9. Issues with Network Discovery and Vulnerability Database (VDB)
10. IP Address and Location Based Access Control
11. Intelligence and Reputation Based Traffic Control
12. Decryption and Inspection of SSL Encrypted Traffic
13. Routing, and Network Address Translation (NAT)

Part IV: Best Practices and Troubleshooting of System Administration
14. Issues with Update
15. Process and Task Management
16. Issues with Network and System Performance
17. Issues with Time Synchronization
18. Managing the Disk Space and the Disk Health

Part V: Best Practices and Troubleshooting of User Identity and Access Control
19. Issues with User Management
20. Issues with Integration of Firepower with ISE and ACS
21. Issues with User Agent
22. Issues with Integration of Splunk or Any Event Streamer (eStreamer)

Part VI: Best Practices for Generating Log, Report and Troubleshoot Data
23. Real Time Logging, Alerting, and Correlation
24. Searching, Reporting, and Generating Troubleshooting Data

Nazmul Rajib is a senior engineer and leader of the Cisco Global Technical Services organization focusing on next-generation security technologies. He leads cybersecurity training initiatives, develops internal training programs, and trains the current generation of Cisco engineers who support Cisco security solutions around the world. He also reviews design specifications, tests security software, and provides solutions to businesscritical networking issues. Nazmul has authored numerous technical publications at Cisco.com and in the Cisco support community.


Nazmul is a veteran engineer of Sourcefire, Inc., which developed Snort–the most popular open-source intrusion prevention system in the world. He created and managed the global knowledge base for Sourcefire and designed Sourcefire security certifications for partner enablement. Nazmul trained security engineers from many managed security service providers (MSSP) in the United States. He supported the networks of numerous Fortune 500 companies and U.S. government agencies.


Nazmul has a master of science degree in internetworking. He also holds many certifications in the areas of cybersecurity, information technology, and technical communication. He is a Sourcefire Certified Expert (SFCE) and Sourcefire Certified Security Engineer (SFCSE).

Normal 0 false false false EN-US X-NONE X-NONE