7.1 Supporting Systems Overview

A comprehensive network security solution requires integration with various supporting systems to provide end-to-end visibility, centralized management, and automated response capabilities. These systems work together to create a cohesive security ecosystem.

Supporting Systems Integration
Figure 7.1: Integrated Supporting Systems Architecture

Core Supporting Systems

System Function Integration Method Data Exchanged
SIEM Platform Centralized log collection, correlation, and analysis Syslog, API, agents Security events, alerts, logs
Network Management System Monitor network health, performance, and availability SNMP, NetFlow, API Performance metrics, topology, status
Backup and Recovery Configuration backup and disaster recovery SFTP, SCP, API Configurations, policies, certificates
Authentication System Centralized user authentication and authorization LDAP, RADIUS, SAML User credentials, group memberships, policies

7.2 SIEM Integration

Security Information and Event Management (SIEM) integration is critical for centralized visibility and correlation of security events across the entire infrastructure. The SIEM platform collects logs from all security devices, correlates events to detect complex attack patterns, and provides dashboards for security monitoring.

SIEM Integration Requirements

  • Log Forwarding: Configure NGFW to send all security logs to SIEM via syslog (UDP 514 or TCP 6514 with TLS)
  • Log Format: Use standardized formats such as CEF (Common Event Format) or LEEF for easier parsing
  • Event Filtering: Configure filters to send only relevant events to avoid overwhelming SIEM with noise
  • Time Synchronization: Ensure all devices use NTP to maintain accurate timestamps for correlation
  • Bandwidth Considerations: Estimate log volume (typically 100-500 KB/sec per firewall) and ensure adequate network capacity

Key Events to Forward

Event Category Examples Priority
Security Threats IPS blocks, malware detections, exploit attempts Critical
Authentication Events Login failures, privilege escalation, account lockouts High
Policy Violations Blocked connections, unauthorized access attempts Medium
System Events Configuration changes, failover events, system errors Medium

7.3 Additional Integration Requirements

Beyond SIEM, several other systems require integration to provide comprehensive security management and operational efficiency.

Patch Management Integration

Integrate with patch management systems (e.g., WSUS, SCCM) to ensure security devices receive timely firmware updates. Configure automated update schedules during maintenance windows. Implement staged rollout to test updates on secondary devices before applying to production.

Ticketing System Integration

Connect security alerts to IT service management (ITSM) platforms like ServiceNow or Jira. Automatically create tickets for critical security events requiring investigation. Track incident response workflows and maintain audit trails for compliance.

Configuration Management Database (CMDB)

Register all security devices in the CMDB to maintain accurate asset inventory. Track device relationships, dependencies, and change history. Use CMDB data for impact analysis during incidents and change planning.

Network Access Control (NAC)

Integrate NGFW with NAC systems to enforce device compliance policies. Share threat intelligence to quarantine compromised devices automatically. Coordinate VLAN assignments based on device posture and user identity.