Cisco FMC
Visualize your Cisco Secure Firewall Management Center (FMC) deployment in JupiterOne — the FTD firewalls it manages, the access control and NAT policies assigned to each device and the rules inside them, and the hosts and network vulnerabilities discovered by FMC network discovery — so you can see which rules apply to which firewall, find exposed services and vulnerable hosts, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
Installation
This integration connects to your on-premises Cisco Secure Firewall Management Center (FMC) using the FMC REST API and ingests managed FTD devices, access control policies and their access rules, FTD NAT policies and their NAT rules, and the hosts and vulnerabilities discovered by FMC network discovery. The FMC is usually on your own network, so the integration normally runs on a JupiterOne Collector that can reach the FMC over HTTPS.
Cloud-delivered FMC (cdFMC) is not supported. The integration only works with an on-premises or virtual FMC appliance.
Configuration in Cisco FMC
Before you configure the integration in JupiterOne, prepare the following in your FMC:
-
The base URL of your FMC, for example
https://fmc.example.com. The JupiterOne Collector must be able to reach it. -
The REST API enabled. It is enabled by default; to confirm, choose System > Configuration > REST API Preferences and check that Enable REST API is selected.
-
A dedicated FMC user for the integration, with a read-only role that can use the REST API and view devices, access control policies, NAT policies, and network discovery hosts and vulnerabilities. The integration only makes read (
GET) requests, plus thePOSTthat generates its access token.Do not reuse an account that people sign in to the FMC web interface with. FMC does not allow the same credentials to be used for the web interface and the REST API at the same time, and logs the other session out without warning. Cisco also recommends keeping UI users and API users separate and not using an admin account for the API.
-
The username and password of that user. The integration sends them as HTTP Basic authentication to
POST /api/fmc_platform/v1/auth/generatetokenand then uses the returnedX-auth-access-tokenfor every other request. Access tokens are valid for 30 minutes; the integration requests a new one automatically when a token expires during a run. -
If the FMC presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.
Once you have obtained the information above, proceed to JupiterOne to finalize the integration.
Configuration in JupiterOne
To install the Cisco FMC integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Cisco FMC. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Cisco FMC account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The FMC Base URL of your on-premises FMC, for example
https://fmc.example.com(required). -
The API Username and API Password of the dedicated read-only FMC user created above (required).
-
Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended).
When you save the instance, JupiterOne validates the credentials by requesting an access token from the FMC.
Data Sources
Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest. The account (cisco_fmc_account) and service (cisco_fmc_service) entities are always created.
| Data Source | Description | Entities Created |
|---|---|---|
| Managed Devices | FTD devices managed by the FMC, with hostname, model, software version, FTD mode, health status, and deployment status | cisco_fmc_device |
| Access Control Policies | Access control policies with their default action, and the access rules inside each policy (action, enabled state, logging, source and destination networks and ports, and applications) | cisco_fmc_access_policy, cisco_fmc_access_rule |
| NAT Policies | FTD NAT policies and their auto and manual NAT rules (NAT type, section, original and translated source, and source and destination interfaces) | cisco_fmc_nat_policy, cisco_fmc_nat_rule |
| Discovered Hosts | Hosts discovered by FMC network discovery, with IP and MAC addresses, hostname, operating system, exposed services, and detected applications | cisco_fmc_host |
| Host Findings | Network vulnerabilities (CVEs) that FMC network discovery detected on hosts, one finding per CVE, host IP address, and port | cisco_fmc_host_finding |
The relationships between data sources are built only when both sides are enabled:
- Device to access control policy (
ASSIGNED) requires Managed Devices and Access Control Policies. - Device to NAT policy (
ASSIGNED) requires Managed Devices and NAT Policies. Only policies assigned directly to a device are linked; NAT policies assigned to a high-availability pair or a cluster are not linked to the member devices. - Discovered host to host finding (
HAS) requires Discovered Hosts and Host Findings. Findings are matched to hosts by IP address.
The integration does not create relationships to entities from other integrations.
Keep the following in mind:
- Only one FMC domain is ingested. The integration collects the domain that the FMC returns for the API user when it signs in (the
DOMAIN_UUIDof the token response) and does not enumerate or query any other domain. - "Access lists" means access control policies and their rules. Extended ACL objects are not ingested.
- Host findings carry no severity or CVSS score. The FMC network map does not return one, so every finding is ingested with
severity: informationalandnumericSeverity: 0, along with itscveIdand an NVD reference link. - Large deployments take a while. Cisco documents a REST API limit of 120
GETrequests per minute from a single IP address. The integration paces all of its requests just below that (about 114 per minute) on every FMC release, requests up to 1000 objects per page, and fetches access and NAT rules one policy at a time, so a run against a FMC with many policies, rules, or discovered hosts can take a long time.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
- Secure Firewall Management Center REST API Quick Start Guide, Version 7.4.1
- About the Management Center REST API — enabling the REST API and API user best practices
- Connecting with a Client — token generation and session behavior
- Objects in the REST API — rate limits, paging, and the endpoints this integration reads
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (9)
/api/fmc_config/v1/domain/{domainUUID}/assignment/policyassignments/api/fmc_config/v1/domain/{domainUUID}/devices/devicerecords/api/fmc_config/v1/domain/{domainUUID}/policy/accesspolicies/api/fmc_config/v1/domain/{domainUUID}/policy/accesspolicies/{containerUUID}/accessrules/api/fmc_config/v1/domain/{domainUUID}/policy/ftdnatpolicies/api/fmc_config/v1/domain/{domainUUID}/policy/ftdnatpolicies/{containerUUID}/natrules/api/fmc_netmap/v1/domain/{domainUUID}/hosts/api/fmc_netmap/v1/domain/{domainUUID}/vulns/api/fmc_platform/v1/auth/generatetoken
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (2)
- https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/REST/secure_firewall_management_center_rest_api_quick_start_guide_741/Connecting_with_a_Client.html
- https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/REST/secure_firewall_management_center_rest_api_quick_start_guide_741/Objects_In_The_REST_API.html
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (3)
| Step | Endpoints |
|---|---|
| Build Device Assigned NAT Policy Relationships | /api/fmc_config/v1/domain/{domainUUID}/assignment/policyassignments |
| Fetch Access Rules | /api/fmc_config/v1/domain/{domainUUID}/policy/accesspolicies/{containerUUID}/accessrules |
| Fetch NAT Rules | /api/fmc_config/v1/domain/{domainUUID}/policy/ftdnatpolicies/{containerUUID}/natrules |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Access Control Policy | cisco_fmc_access_policy | Ruleset |
| Access Rule | cisco_fmc_access_rule | Rule |
| Account | cisco_fmc_account | Account |
| Discovered Host | cisco_fmc_host | Host |
| Host Finding | cisco_fmc_host_finding | Finding, Vulnerability |
| Managed Device | cisco_fmc_device | Firewall |
| NAT Policy | cisco_fmc_nat_policy | Ruleset |
| NAT Rule | cisco_fmc_nat_rule | Rule |
| Service | cisco_fmc_service | Service |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
cisco_fmc_access_policy | HAS | cisco_fmc_access_rule |
cisco_fmc_account | PROVIDES | cisco_fmc_service |
cisco_fmc_account | HAS | cisco_fmc_device |
cisco_fmc_account | HAS | cisco_fmc_access_policy |
cisco_fmc_account | HAS | cisco_fmc_nat_policy |
cisco_fmc_device | ASSIGNED | cisco_fmc_access_policy |
cisco_fmc_device | ASSIGNED | cisco_fmc_nat_policy |
cisco_fmc_host | HAS | cisco_fmc_host_finding |
cisco_fmc_nat_policy | HAS | cisco_fmc_nat_rule |
Cisco Fmc Access Policy
cisco_fmc_access_policy inherits from Ruleset
| Property | Type | Description | Specifications |
|---|---|---|---|
defaultAction | string | null | The policy default action (BLOCK, TRUST, PERMIT, NETWORK_DISCOVERY, INHERIT_FROM_PARENT). |
Cisco Fmc Access Rule
cisco_fmc_access_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
action | string | null | The rule action (ALLOW, TRUST, BLOCK, MONITOR, BLOCK_RESET, ...). | |
applications | array | null | Summarized application names matched by the rule. | |
destinationNetworks | array | null | Summarized destination network object names and inline literal values. | |
destinationPorts | array | null | Summarized destination port object names and literal values. | |
isEnabled | boolean | null | Whether the rule is enabled. | |
isLogBeginEnabled | boolean | null | Whether logging at the start of the connection is on. | |
isLogEndEnabled | boolean | null | Whether logging at the end of the connection is on. | |
section | string | null | The rule section (mandatory, default), when reported. | |
sourceNetworks | array | null | Summarized source network object names and inline literal values. | |
sourcePorts | array | null | Summarized source port object names and literal values. |
Cisco Fmc Account
cisco_fmc_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
domainUuid * | string | The FMC domain UUID this account represents. | |
fmcHost | string | null | The on-prem FMC host, or null for a cloud-delivered FMC (cdFMC) tenant. |
Cisco Fmc Device
cisco_fmc_device inherits from Firewall
| Property | Type | Description | Specifications |
|---|---|---|---|
deploymentStatus | string | null | The device policy deployment status reported by FMC. | |
ftdMode | string | null | The FTD deployment mode (e.g. ROUTED, TRANSPARENT), when reported. | |
healthStatus | string | null | The device health status reported by FMC. | |
hostName | string | null | The device hostname reported by FMC. | |
ipv4Addresses | array | null | IPv4 addresses of the device, when the name/hostName is an address. | |
model | string | null | The device hardware model reported by FMC. | |
osVersion | string | null | The device software version (sw_version) reported by FMC. |
Cisco Fmc Host
cisco_fmc_host inherits from Host
| Property | Type | Description | Specifications |
|---|---|---|---|
applications | array | null | Applications detected on the host, name and version (R6). | |
criticalityLevel | string | null | The host criticality level reported by FMC RNA (e.g. High, Medium, Low). Named criticalityLevel to avoid the base Entity numeric criticality property (ADR-012). | |
services | array | null | Exposed services as "{protocol}/{port}" strings (R4). |
Cisco Fmc Host Finding
cisco_fmc_host_finding inherits from Finding, Vulnerability
| Property | Type | Description | Specifications |
|---|---|---|---|
port | number | null | The port the vulnerability was detected on, when reported. | |
protocol | string | null | The protocol the vulnerability was detected on, when reported. | |
source | string | null | The detection source reported by FMC (e.g. RNA for passive detection). |
Cisco Fmc Nat Policy
cisco_fmc_nat_policy inherits from Ruleset
Cisco Fmc Nat Rule
cisco_fmc_nat_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
destinationInterface | string | null | The destination interface/zone object name. | |
isEnabled | boolean | null | Whether the rule is enabled. | |
natType | string | null | The NAT type (DYNAMIC, STATIC). | |
originalSource | string | null | The original (pre-translation) source object name: originalSource for manual NAT, originalNetwork for auto NAT. | |
ruleType | string | null | The rule object type (FTDAutoNatRule or FTDManualNatRule). | |
section | string | null | The NAT section (BEFORE_AUTO, AUTO, AFTER_AUTO). | |
sourceInterface | string | null | The source interface/zone object name. | |
translatedSource | string | null | The translated source object name: translatedSource for manual NAT, translatedNetwork for auto NAT. |
Cisco Fmc Service
cisco_fmc_service inherits from Service