Security, Access, and Control
|
Recursive DNS-Layer Security
|
| Block access to domain with malware, phishing, botnet, and other high-risk items with low latency |
● |
● |
● |
● |
| Application discovery, monitoring, blocking, and risk scoring |
● |
● |
● |
● |
| Filtering by domain or category |
● |
● |
● |
● |
Application and Network Access/Monitoring
|
| SD-WAN integration and 3rd party support |
|
|
● |
● |
Secure Web Gateway (SWG)
|
| Custom block/allow lists of domains |
● |
● |
● |
● |
| Custom block/allow lists of URLs |
|
Partial |
● |
● |
| Proxy and inspect web traffic |
|
Partial |
● |
● |
| Secure Malware Analytics (sandbox suspicious files; block malicious files) |
|
|
500 samples/day |
● |
| Secure Malware Analytics - manual file submission, full glove box and full SMA console access |
|
|
|
● |
Roaming Security and Client Support
|
| Roaming user protection for DNS traffic and web traffic (via SWG), with Cisco Secure Client roaming module (* = DNS traffic only) |
●* |
●* |
●* |
●* |
Cloud Access Security Broker (CASB)
|
| Advanced visibility and control of cloud app usage (including gen AI, OAuth-approved apps, tenant controls). |
Limited |
Limited |
● |
● |
| Scan and remove malware from cloud-based file storage apps |
|
|
● up to 2 |
● |
| SaaS security posture management (SSPM) capabilities + Advanced capability via partnership with AppOmni (+ = partnership) |
●+ |
●+ |
●+ |
●+ |
Data Loss Prevention (DLP)
|
| Integrated inline/SaaS API (cloud) data inspection and blocking to protect against sensitive data loss |
|
|
Add-on |
● |
Firewall as a Service (FWaaS)
|
| Layer 3 and 4 control of IPs, ports, and protocols |
|
|
● |
● |
| Layer 7 control |
|
|
Add-on |
● |
| Intrusion Prevention System (IPS) with decryption |
|
|
|
limited to decryption |
Remote Browser Isolation (RBI)
|
| Isolated browsing provides a virtual air-gapped solution in those instances where users need to safely go to sites that present a risk |
|
|
Add-on |
Add-on |
Threat Intelligence
|
| Continuously updated threat intelligence from Cisco Talos |
● |
● |
● |
● |
| Deep domain, IP, and Autonomous System Number (ASN) data for rapid investigations (via Investigate API) |
|
● |
● |
● |
SIEM and XDR Interoperability
|
| Integrations with multiple tools, includ. Cisco Splunk and XDR |
● |
● |
● |
● |
Management, Reporting, and Support
|
Management
|
| Single management interface |
● |
● |
● |
● |
| Customize block page and warn page options |
● |
● |
● |
● |
Reporting and Logging
|
| Real-time activity search, plus API to extract key events |
● |
● |
● |
● |
| Choose North America or Europe log storage |
● |
● |
● |
● |
| Cisco-managed S3 buckets or customer AWS S3 buckets |
● |
● |
● |
● |
Support
|
| 24x7 Enhanced Software Support Service via email and phone (Premium upgrade available) |
Add-on |
Add-on |
Add-on |
Add-on |