Chapter 7: Support & Integration
Supporting systems and integration requirements for comprehensive security
7.1 Supporting Systems Overview
A comprehensive network security solution requires integration with various supporting systems to provide end-to-end visibility, centralized management, and automated response capabilities. These systems work together to create a cohesive security ecosystem.
Core Supporting Systems
| System | Function | Integration Method | Data Exchanged |
|---|---|---|---|
| SIEM Platform | Centralized log collection, correlation, and analysis | Syslog, API, agents | Security events, alerts, logs |
| Network Management System | Monitor network health, performance, and availability | SNMP, NetFlow, API | Performance metrics, topology, status |
| Backup and Recovery | Configuration backup and disaster recovery | SFTP, SCP, API | Configurations, policies, certificates |
| Authentication System | Centralized user authentication and authorization | LDAP, RADIUS, SAML | User credentials, group memberships, policies |
7.2 SIEM Integration
Security Information and Event Management (SIEM) integration is critical for centralized visibility and correlation of security events across the entire infrastructure. The SIEM platform collects logs from all security devices, correlates events to detect complex attack patterns, and provides dashboards for security monitoring.
SIEM Integration Requirements
- Log Forwarding: Configure NGFW to send all security logs to SIEM via syslog (UDP 514 or TCP 6514 with TLS)
- Log Format: Use standardized formats such as CEF (Common Event Format) or LEEF for easier parsing
- Event Filtering: Configure filters to send only relevant events to avoid overwhelming SIEM with noise
- Time Synchronization: Ensure all devices use NTP to maintain accurate timestamps for correlation
- Bandwidth Considerations: Estimate log volume (typically 100-500 KB/sec per firewall) and ensure adequate network capacity
Key Events to Forward
| Event Category | Examples | Priority |
|---|---|---|
| Security Threats | IPS blocks, malware detections, exploit attempts | Critical |
| Authentication Events | Login failures, privilege escalation, account lockouts | High |
| Policy Violations | Blocked connections, unauthorized access attempts | Medium |
| System Events | Configuration changes, failover events, system errors | Medium |
7.3 Additional Integration Requirements
Beyond SIEM, several other systems require integration to provide comprehensive security management and operational efficiency.
Patch Management Integration
Integrate with patch management systems (e.g., WSUS, SCCM) to ensure security devices receive timely firmware updates. Configure automated update schedules during maintenance windows. Implement staged rollout to test updates on secondary devices before applying to production.
Ticketing System Integration
Connect security alerts to IT service management (ITSM) platforms like ServiceNow or Jira. Automatically create tickets for critical security events requiring investigation. Track incident response workflows and maintain audit trails for compliance.
Configuration Management Database (CMDB)
Register all security devices in the CMDB to maintain accurate asset inventory. Track device relationships, dependencies, and change history. Use CMDB data for impact analysis during incidents and change planning.
Network Access Control (NAC)
Integrate NGFW with NAC systems to enforce device compliance policies. Share threat intelligence to quarantine compromised devices automatically. Coordinate VLAN assignments based on device posture and user identity.