Cisco ASA with FirePOWER Services. October 2014



Similar documents
Requirements When Considering a Next- Generation Firewall

Deploying Next Generation Firewall with ASA and Firepower services

SourceFireNext-Generation IPS

Cisco ASA und FirePOWER Services

Sourcefire Solutions Overview Security for the Real World. SEE everything in your environment. LEARN by applying security intelligence to data

Cisco Security: Moving to Security Everywhere. #TIGcyberSec. Stefano Volpi

Protection Against Advanced Persistent Threats

Threat-Centric Security for Service Providers

EXTENDING NETWORK SECURITY: TAKING A THREAT CENTRIC APPROACH TO SECURITY

Cisco Cybersecurity Pocket Guide 2015

Cisco Advanced Malware Protection

The Advanced Attack Challenge. Creating a Government Private Threat Intelligence Cloud

Cisco Advanced Malware Protection for Endpoints

How To Protect Your Network From Intrusions From A Malicious Computer (Malware) With A Microsoft Network Security Platform)

Cisco and Sourcefire. AGILE SECURITY : Security for the Real World. Stefano Volpi

Cisco Advanced Malware Protection. Ross Shehov Security Virtual Systems Engineer March 2016

Five Steps For Securing The Data Center: Why Traditional Security May Not Work

Cisco Advanced Malware Protection for Endpoints

Cisco Security Strategy Update Integrated Threat Defense. Oct 28, 2015

Braindumps QA

Cisco Cloud Web Security

Content Security: Protect Your Network with Five Must-Haves

REVOLUTIONIZING ADVANCED THREAT PROTECTION

Network as a Sensor and Enforcer Leverage the Network to Protect Against and Mitigate Threats

What s Next for Network Security - Visibility is king! Gøran Tømte March 2013

How To Protect Your Network From Attack From A Network Security Threat

WildFire. Preparing for Modern Network Attacks

Palo Alto Networks. October 6

McAfee Network Security Platform

FROM PRODUCT TO PLATFORM

Breaking the Cyber Attack Lifecycle

Sourcefire Next-Generation IPS

The Hillstone and Trend Micro Joint Solution

Unified Security, ATP and more

Integrated Network Security Architecture: Threat-focused Nextgeneration

you us MSSP are a Managed Security Service Provider looking to offer Advanced Malware Protection Services

High Performance NGFW Extended

SANS Top 20 Critical Controls for Effective Cyber Defense

Cisco & Big Data Security

BEFORE. DURING. AFTER. CISCO'S INTEGRATED SECURITY STRATEGY NIALL MOYNIHAN CISCO EMEAR

Palo Alto Networks and Splunk: Combining Next-generation Solutions to Defeat Advanced Threats

Security strategies to stay off the Børsen front page

Content-ID. Content-ID URLS THREATS DATA

Cisco Small Business ISA500 Series Integrated Security Appliances

Vulnerability Management

Threat-Centric Security Solutions. György Ács Security Consulting Systems Engineer 3 rd November 2015

How Attackers are Targeting Your Mobile Devices. Wade Williamson

IBM Security IBM Corporation IBM Corporation

Content-ID. Content-ID enables customers to apply policies to inspect and control content traversing the network.

Stallion SIA Seminar PREVENTION FIRST. Introducing the Enterprise Security Platform. Sami Walle Regional Sales Manager

Q1 Labs Corporate Overview

Addressing the Full Attack Continuum: Before, During, and After an Attack. It s Time for a New Security Model

Moving Beyond Proxies

Next Generation Enterprise Network Security Platform

Network Security Solution. Arktos Lam

The Cisco ASA 5500 as a Superior Firewall Solution

Решения HP по информационной безопасности

Introducing IBM s Advanced Threat Protection Platform

Securing the Virtualized Data Center With Next-Generation Firewalls

Cybercrime: evoluzione del malware e degli attacchi. Cesare Radaelli Regional Sales Manager, Italy cradaelli@paloaltonetworks.com

WHITE PAPER Cloud-Based, Automated Breach Detection. The Seculert Platform

Integrating MSS, SEP and NGFW to catch targeted APTs

Trend Micro. Advanced Security Built for the Cloud

Sourcefire Next-Generation IPS

WEBSENSE TRITON SOLUTIONS

Security Intelligence Services.

Cisco Cloud Web Security Datasheet

Network that Know. Rasmus Andersen Lead Security Sales Specialist North & RESE

Modular Network Security. Tyler Carter, McAfee Network Security

Effective IDS/IPS Network Security in a Dynamic World with Next-Generation Intrusion Detection & Prevention

Securing Virtualization with Check Point and Consolidation with Virtualized Security

Cisco ASA with FirePOWER Services

Achieving Actionable Situational Awareness... McAfee ESM. Ad Quist, Sales Engineer NEEUR

Next Generation Firewall Capabilities Assessment

SECURITY ANALYTICS MOVES TO REAL-TIME PROTECTION

Advanced Threats: The New World Order

Concierge SIEM Reporting Overview

Integrated Approach to Network Security. Lee Klarich Senior Vice President, Product Management March 2013

Internal Network Firewall (INFW) Protecting your network from the inside out

Preparing for a Cyber Attack PROTECT YOUR PEOPLE AND INFORMATION WITH SYMANTEC SECURITY SOLUTIONS

ENABLING FAST RESPONSES THREAT MONITORING

Cisco Advanced Services for Network Security

How Network Virtualization can improve your Data Center Security

Symantec Endpoint Protection

What is Security Intelligence?

Networking for Caribbean Development

Agenda , Palo Alto Networks. Confidential and Proprietary.

Advanced Security and Risk Management for Cloud and Premise environments

You ll learn about our roadmap across the Symantec and gateway security offerings.

McAfee Next Generation Firewall Optimize your defense, resilience, and efficiency.

Securing Virtual Applications and Servers

Cisco ASA 5500 Series Firewall Edition for the Enterprise

Transcription:

Cisco ASA with FirePOWER Services October 2014

What We Are Announcing September 16, 2014 Industry s First Threat-Focused NGFW Proven Cisco ASA firewalling + Industry leading NGIPS and AMP Cisco ASA with FirePOWER Services Integrating defense layers helps organizations get the best visibility Enable dynamic controls to automatically adapt Protect against advanced threats across the entire attack continuum #1 Cisco Security announcement of the year! 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 Cisco Confidential 2

The Problem with Legacy Next-Generation Firewalls Focus on the Apps But miss the threat 0100 111001 1001 11 111 0 0100 1110101001 1101 111 0011 0 11100 011 1010011101 1000111010011101 10001110 10011 101 010011101 1100001110001110 1001 1101 1110011 0110011 101000 0110 00 111 0100 11101 1000111010011101 1000111010011101 1100001 1100 0111010011101 1100001110001110 1001 1101 1110011 0110011 101 0111100 011 1010011101 1 Legacy NGFWs can reduce attack surface area but advanced malware often evades security controls. Cisco Confidential 3

Threat Landscape Demands more than Application Control 60% of data is stolen in hours 54% of breaches remain undiscovered for months 100% of companies connect to domains that host malicious files or services It is a Community that hides in plain sight avoids detection and attacks swiftly Cisco Confidential 4

Defense-in-Depth Security Alone is Not Enough Siloed Approach Increased complexity and reduced effectiveness Poor Visibility Undetected multivector and advanced threats Manual and Static Slow, manual, inefficient response Cisco Confidential 5

Integrated Threat Defense Across the Attack Continuum Attack Continuum BEFORE Discover Enforce Harden DURING Detect Block Defend AFTER Scope Contain Remediate Firewall/VPN Granular App Control Modern Threat Control NGIPS Security Intelligence Web Security Visibility and Automation Advanced Malware Protection Retrospective Security IoCs/Incident Response Cisco Confidential 6

Cisco ASA with FirePOWER Services Industry s First Adaptive, Threat-Focused NGFW Features Cisco ASA firewalling combined with Sourcefire next-generation IPS Integrated threat defense over the entire attack continuum Best-in-class security intelligence, application visibility and control (AVC), and URL filtering Superior, multilayered threat protection Unprecedented network visibility Advanced malware protection Reduced cost and complexity Benefits Cisco Confidential 7

Superior Integrated & Multilayered Protection Clustering & High Availability Network Firewall Routing Switching Cisco Collective Security Intelligence Enabled Intrusion Prevention (Subscription) Application Visibility & Control FireSIGHT Analytics & Automation Cisco ASA Advanced Malware Protection (Subscription) Built-in Network Profiling WWW URL Filtering (Subscription) Identity-Policy Control & VPN World s most widely deployed, enterprise-class ASA stateful firewall Granular Cisco Application Visibility and Control (AVC) Industry-leading FirePOWER nextgeneration IPS (NGIPS) Reputation- and category-based URL filtering Advanced malware protection Cisco Confidential 8

FirePOWER Delivers Best Threat Effectiveness Security Value Map for Intrusion Prevention System (IPS) Security Value Map for Breach Detection Cisco Confidential 9

NSS Labs Next-Generation Firewall Security Value Map The NGFW Security Value Map shows the placement of Cisco ASA with FirePOWER Services and the FirePOWER 8350 as compared to other vendors. All three products achieved 99.2 percent in security effectiveness and now all can be confident that they will receive the best protections possible regardless of deployment. Source: NSS Labs 2014 Cisco Confidential 10

Unprecedented Network Visibility Categories FirePOWER Services Typical IPS Typical NGFW Threats ü ü ü Users ü û ü Web Applications ü û ü Application Protocols ü û ü File Transfers ü û ü Malware ü û û Command & Control Servers ü û û Client Applications ü û û Network Servers ü û û Operating Systems ü û û Routers & Switches ü û û Mobile Devices ü û û Printers ü û û VoIP Phones ü û û Virtual Machines ü û û Cisco Confidential 11

Impact Assessment IMPACT FLAG ADMINISTRATOR ACTION WHY 1 Act Immediately, Vulnerable Event corresponds to vulnerability mapped to host 2 Investigate, Potentially Vulnerable Relevant port open or protocol in use, but no vuln mapped 3 Good to Know, Currently Not Vulnerable Relevant port not open or protocol not in use 4 Good to Know, Unknown Target Monitored network, but unknown host Correlates all intrusion events to an impact of the attack against the target 0 Good to Know, Unknown Network Unmonitored network Cisco Confidential 12

Automated, Integrated Threat Defense Superior Protection for Entire Attack Continuum Context and Threat Correlation Multi-vector Correlation Priority 1 Admin Request 5 IoCs Host A Priority 2 Priority 3 Mail PDF Admin Request PDF Mail 3 IoCs Host B Impact Assessment Early Warning for Advanced Threats Host C Dynamic Security Control Retrospective Security http:// WWW WEB http:// WWW WWW Adapt Policy to Risks Shrink Time between Detection and Cure Cisco Confidential 13

Reduced Cost and Complexity Multilayered protection in a single device Highly scalable Automates security tasks - Impact assessment - Policy tuning - User identification Integrates with third-party security solutions $144,000 Annual Costs of IPS Maintenance $24,300 Cisco s FirePOWER Next-Generation IPS collectively saves this customer $230,100 per year. $72,000 $18,000 $59,400 $3,000 Impact Assessment of IPS Events IPS Tuning Linking IPS Events to Users Typical IPS Next-Generation IPS Cisco Confidential 14

Indications of Compromise (IoCs) IPS Events SI Events Malware Events Malware Backdoors CnC Connections Connections to Known CnC IPs Malware Detections Malware Executions Exploit Kits Admin Privilege Escalations Office/PDF/Java Compromises Dropper Infections Web App Attacks Cisco Confidential 15

AMP Provides Continuous Retrospective Security Breadth of Control Points Email Endpoints WWW Web Network IPS Devices Telemetry Stream File Fingerprint and Metadata File and Network I/O Continuous Feed 1000111010011101 1100001110001110 1001 1101 1110011 0110011 101000 0110 00 0001110 1001 1101 1110011 0110011 101000 0110 00 0111000 111010011 101 1100001 110 0100001100001 1100 0111010011101 1100001110001110 1001 1101 1110011 0110011 101000 0110 00 Process Information Continuous Analysis Cisco Confidential 16

Protection Before, During, and After an Attack BEFORE Discover Enforce Harden DURING Detect Block Defend AFTER Scope Contain Remediate Point-in-Time Continuous With Unmatched Visibility, Control, and Advanced Threat Remediation Functionality Cisco Confidential 17

Integrated Threat Defense at Work Threat intelligence led to identifying and stopping the extensive String of Paerls malware campaign Cisco detects, analyzes and protects against known and emerging threats Key Techniques: Leveraged data sources across Email, Web, and Advanced Malware Protection products Used Big Data analytics to link disparate events and malware activity Result: Endpoint behavior Malware deconstruction Multiple Indications of Compromise (IoCs) identified the malware infection Learn More: http://blogs.cisco.com/security/a-string-of-paerls 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Cisco Confidential 18 18

Cisco ASA with FirePOWER Services Base Hardware New ASA 5585-X Bundle SKUs with FirePOWER Services Module New ASA 5500-X SKUs running FirePOWER Services Software FirePOWER Services Spare Module/Blade for ASA 5585-X Series FirePOWER Services Software Hardware includes Application Visibility and Control (AVC) Security Subscription Services IPS, URL, Advanced Malware Protection (AMP) Subscription Services One- and Three-Year Term Options Management FireSIGHT Management Center (HW Appliance or Virtual) Cisco Security Manager (CSM) or ASDM Support SmartNET Software Application Support plus Upgrades Cisco Confidential 19

Accelerate Migration to Cisco ASA with FirePOWER Services with Professional and Technical Services SMARTnet Technical Support Keep security solutions available by providing access to broad Cisco support tools and expertise Migration Services Move more quickly to new capabilities and with minimal disruption Managed Services Provide full-time, proactive, systematic threat monitoring and management Cisco Confidential 20

Cisco ASA with FirePOWER Services A New, Adaptive, Threat-Focused NGFW Superior Visibility Integrated Threat Defense Best-in-class, multilayered protection in a single device Full contextual awareness to eliminate gaps Automation Simplified operations and dynamic response and remediation Cisco Confidential 21

Demonstration Cisco Confidential 22

Migration Opportunity Cisco Confidential 23

Huge Migration Opportunity! $2.5 Billion ASA Install Base up for Refresh in the Next Five to Seven Years Resulting Annual Revenue Hardware Refresh Opportunity: >$400 Million per Year for the Next Five to Seven Years $ There Are Over 650,000 ASA Units Sold FirePOWER Services Increases the Deal Size Cisco Confidential 24

Why Upgrade? 5 models to meet varied throughput demands ASA 5555-X 4 Gbps FW Throughput ASA 5545-X 3 Gbps FW Throughput ASA 5525-X 2 Gbps FW Throughput ASA 5515-X 1.2 Gbps FW Throughput ASA 5512-X 1 Gbps FW Throughput High Performance Up to 4X faster than legacy ASA Increased throughput, CPS, sessions Accelerated, integrated services Integrated security acceleration hardware No extra hardware required (security services enabled with software licenses) Next-generation security Application control (AVC) Next-Generation IPS Security intelligence and URL Filtering Advanced Malware Protection *VPN and IPS acceleration hardware available on select ASA models (ASA 5525-X, 5545-X, 5555-X) Cisco Confidential 25

Never Sell a Naked Firewall AGAIN! +2-7% $0 ASA-5500-X ASA-5500-X + SSD ASA 5500-X FirePOWER Services Bundle (ships with Application Visibility and Control) 100% of Midrange ASAs should go out as NGFWs Protect your customers and equip them upfront Cisco Confidential 26

Ignite Your Sales with Multi-Year FirePOWER Services +157% Bookings +31% Firewall Only Next-Gen Firewall + 1 year IPS Next-Gen Firewall + 3 year IPS, AMP, URL Cisco Confidential 27

Super Size your Deal! IPS + AMP + URL Filtering Cisco Confidential 28

Increase Your Profits with Multi-Year, Multi-Services Firewall Only NG Firewall + 1 year IPS NG Firewall + 3 year IPS, AMP, URL Hardware (10 x ASA5545) $ 86,376 $ 92,136 $ 92,136 License $ 21,192 $ 129,696 Security Ignite discount $ 14,166 $ 27,728 VIP Rebate $ 2,591 $ 6,588 $ 18,498 Security Ignite discount + VIP Rebate $ 2,591 $ 20,754 $ 46,226 * Assumes OIP discount for new opportunities 18 times increase!! Cisco Confidential 29

Upgrading from ASA with Classic IPS to FirePOWER Services for ASA When upgrading from classic IPS to FirePOWER Services, adding new features can require a platform change. Generally each new major feature is a step up, assuming the box is near capacity. Model 5512-X 5515-X 5525-X 5545-X 5555-X 5585-10 5585-20 5585-40 5585-60 Classic IPS Module FirePOWER AVC or IPS FirePOWER IPS + AVC FirePOWER IPS + AVC + AMP 150 250 400 600 850 1150 1500 3000 5000 100 150 375 575 725 1200 2000 3500 6000 75 100 255 360 450 800 1200 2100 3500 60 85 205 310 340 550 850 1500 2300 This is a general approximation! Cisco Confidential 30

Positioning and Targeting Cisco Confidential 31

Threat-focused Value Positioning Framework Meraki ASA CX Cisco ASA with FirePOWER Services FirePOWER Appliances UTM for distributed small office / branch office convenience. First-gen NGFW for medium sized business Internet Edge Deployments Sophisticated NG anti-threat & advanced malware protection trusted by security ops worldwide Sophisticated NG antithreat & advanced malware protection trusted by security ops worldwide Lowest deployment time investment; cloudmanaged. Up to 4 Gbps (5585-X SSP60) Threat-inspected Position for: - On Box SSL - On Box Manager Up to 6 Gbps on (5585-X SSP60) Threat-inspected Position for: - Edge and Enterprise Networks - Clustered DC Up to 60 Gbps FP8390, stackable to 120Gbps Threat-inspected Position for: - Data Center (DC-CVD) - Very High Throughput - IPS-only Refresh Lead with this Cisco Confidential 32

When To Sell What? Cisco ASA with FirePOWER Services NGFW focused projects, FW integration Cisco data center designs Where features, e.g. clustering matters Cisco FirePOWER Appliances IPS is a separate project Not changing / consolidating firewalls Customer requires separate solution Know what the customer wants to do position the best approach for their needs Cisco Confidential 33

Competition Cisco Confidential 34

ASA with FirePOWER Services vs. Typical NGFW Feature Cisco ASA with FirePOWER Services Typical NGFW NSS NGFW Security Value Map, Gartner IPS MQ Superior Partial or Not Available Reputation-Based Proactive Protection Superior Not Available Intelligent Security Automation Superior Not Available File Reputation, File Trajectory, Retrospective Analysis Superior Not Available Application Visibility and Control Superior Available Acceptable Use/URL Filtering Superior Available Remote Access VPN Superior Not Enterprise-Grade Stateful Firewall, HA, Clustering Superior *Available *HA Capabilities vary from NGFW vendor Only Check Point and McAfee Support Clustering Cisco Confidential 35

How Cisco Appears Competitively Correlated SIEM Eventing Incident Control System Vulnerability Management Sandboxing NG Sandbox for Evasive Malware URL and IP Reputation Malware File Trajectory Host Trajectory Open APP-ID 2 1 Collective Security Intelligence (CSI) Adaptive Security NGIPS Threat Hunting User Identity AV and Basic Protections Web URL Controls Application Visibility Gen1 IPS Classic Stateful Firewall NGFW Forensics and Log Management Auto-Remediation / Dynamic Policies Dynamic Outbreak Controls Retrospective Detection Retrospective Analysis SNORT Open IPS Contextual Device, Network and End-Point Visibility Behavioral Indications of Compromise Network Anti- Malware Controls (AMP) *Client Anti- Malware (AMP) BEFORE DURING AFTER Cisco Only n *Agent Cisco and Our Competitors Management Interfaces Cisco Confidential 36

By Way of Comparison can do this can do this can do this and many others Requires 10 unique products and 8 unique management interfaces There is minimal correlation of information, of course Requires four 3 rd - party products and 7 unique management interfaces no correlation Like Palo Alto they need 3 rd -party help at minimum there will be 5 unique management interfaces You guessed it no correlation Can t do this without using one of solutions to the left! (or Cisco) Cisco Confidential 37

How Palo Alto Does It: 1 3 PanOS or Panorama NGFW Manager 2 4 GlobalProtect / Cyvera Client Agent (Windows Only) 3 WildFire Portal (VERY basic Sandbox) PickYourFav Vulnerability Mgmt. QualysGuard 5 6 Bit9 for the rest PickYourFav Remediation (Sophos)Optional But Recommended Choose a Working 8 Sandbox tool Like FireEye PickYourFav SIEM Logging - Splunk 7 PickYourFav Anti-Malware Remediation Cisco Confidential 38

How Cisco Does it 1 NetOPS Workflows - CSM 4.6 or ASDM-ASA-On-Box FireAMP Connector (Managed by FMC) 2 SecOPS Workflows -FireSIGHT Management Center NGFW/NGIPS Management Forensics / Log Management Network AMP / Trajectory Vulnerability Management Incident Control System Adaptive Security Policy Retrospective Analysis Correlated SIEM Eventing Network-Wide / Client Visibility Visibility Categories Threats Users Web Applications Application Protocols File Transfers Malware Command & Control Servers Client Applications Network Servers Operating Systems Routers & Switches Mobile Devices Printers VoIP Phones Virtual Machines Cisco Confidential 39

FY15: Kick PAN in the Teeth with Threat Last Gen IPS 3 Management Consoles Minimum for Threat (Panaroma, Wildfire, Cyvera) Plus 7 Third parties with no correlation to match FireSIGHT Nowhere to be seen at NSS. Cisco Confidential 40

3rd-Party Validation Note: This table format is for example purposes only due to strict NSS Labs rules, only official reports may be shown to customers Cisco Confidential 41

How to Order Cisco Confidential 42

Order Structure 1. New Appliance or Upgrade ASA 5585-X with FirePOWER Services ASA 5500-X with FirePOWER Services SMARTnet Service FirePOWER Services Blade SMARTnet Service SSD + FirePOWER Services Upgrade License One of the Five IPS, URL Filtering, Advanced Malware Subscription packages 1 and 3 year term options 2. Security Subscriptions Cisco FireSIGHT Manager Virtual or FireSIGHT Appliance (required) Cisco Security Manager (CSM) (optional) SMARTnet / SASU 3. Management Systems Must run ASA 9.2.2.4+, FirePOWER Services 5.3.1+ Cisco Confidential 43

Five Subscription Packages to Choose From for Each Appliance 1 and 3 year terms URL AVC is part of the default offering AVC updates are included in SMARTnet URL IPS URL IPS AMP IPS AMP IPS URL TA TAC TAM TAMC Cisco Confidential 44

Incentives and Programs Cisco Confidential 45

Incentives SECURITY IGNITE INCENTIVE Up-front Margin Additional discount on next generation security products registered through OIP or TIP for new business (not available in all countries) Increase your profitability Incentives can be stacked VALUE INCENTIVE (VIP) INVESTMENT PROTECTION (IPP) TECHNOLOGY MIGRATION (TMP) Back-end Rebates Unused Subscriptio n $ Credits Trade-in Credits 6% on ASA 5500-X with FirePOWER Services (with SSD) 10% on bundle subscriptions 5% on 1-Year subscriptions 10% on 3-Year subscriptions Prorated credits for unused subscription & SMARTnet contract term for ASA 5585-X CX SSP module & subscriptions Prorated credits for unused ASA IPS (Cisco IPS) contract term 10% or higher off list price when you trade-in a competitive firewall 15% off list price when you trade-in an ASA 5500 20% off list price when you trade-in your ASA IPS or ASA CX SSP modules for ASA 5585-X http://www.cisco.com/web/partners/incentives_and_promotions/index.html; Restrictions apply to each program Cisco Confidential 46

Partner Seed Unit Program Cisco Provides ( Gets ) Comprehensive sales and hands-on training workshop Cisco ASA with FirePOWER Services Seed Units ASA 5515-X NGFW with SSD 45 day FirePOWER Services evaluation licenses (IPS, URL, AMP) and software download Virtual Cisco FireSIGHT Management Center Sales support from local Cisco team Technical assistance Partner Provides ( Gives ) Attend training workshop Identify install base seed unit install opportunities Engage with local Cisco sales team Configure system and ensure working order, deploy Provide periodic reports on status of units deployment Book sales! Cisco Confidential 47

Partner Seed Unit Program: Terms & Conditions Partners must complete a Cisco ASA with FirePOWER Services training workshop Partner agrees that seed units are owned by Cisco & loaned to partners for: Training Customer PoV (Proof of Value) Demo Partners agree to install seed unit equipment in multiple prospect or install base opportunities Partners takes complete responsibility for: Onsite installation, equipment readiness testing, issue/problem resolution After a customer PoV is complete, partner must wipe customer configs/data and pick up unit Resolve any technical issues working with Partner Help and engage local Cisco team when needed Partners to provide weekly update to local Cisco team or Fast Lane on status of PoV Cisco has the right to withdraw any seed unit if any of the agreed T&Cs are not met by the partner Cisco Confidential 48

Cisco Demo Cloud (dcloud) Complete, LIVE environment Live traffic, clients and threats Easy to use Demo script in your dashboard Visit: dcloud.cisco.com Cisco Confidential 49

Summary Advocate threat-centric Integrated Threat Defense Capitalize $2.5 Billion ASA 5500 Migration Opportunity! Sell new bundled SKUs for ASA refresh and new sales deals Sell add-on FirePOWER Services Out with for Old, ASA for existing ASA customers In with the New Yesterday = Old SKUs Today = New SKUs ASA 5500-X AVC Sold Separately ASA 5500-X with FirePOWER Services New SKUs optimized and ready for FirePOWER Services! Partner Opportunity/Cisco Incentives IGNITE (6% OIP discount) VIP (Hardware: 5%, Subscriptions 5 10%) *Updates require SMARTnet Service Cisco Confidential 50

https://communities.cisco.com/ docs/doc-53978 Thank you.