Create a Cisco cyber vision connector

This task creates a connector to send data from Cisco Cyber Vision to the firewall, enabling dynamic attribute integration between these systems.

This task discusses how to send data from Cisco Cyber Vision to the Security Cloud Control.

Before you begin

Cisco Cyber Vision must be reachable from the machine on which the dynamic attributes connector is running. You must know its IP address, port, and API key.

To find the API key in the Cyber Vision management console, click Admin > API > Token, then click Show to display the token and The Cisco Cyber Vision management console interface displays the steps to access the API key, including navigation to the Admin section and the option to show and copy the token. to copy the token to the clipboard.

Follow these steps to create a Cisco Cyber Vision connector:

Procedure


Step 1

Log in to Security Cloud Control.

Step 2

Click Firewall.

Step 3

Click Administration > Dynamic Attributes Connector > Connectors.

Step 4

Do any of the following:

  • Add a new connector: click Add icon (add icon), then click the name of the connector.

  • Edit a connector: click Edit icon (edit icon).

  • Delete a connector: click Delete icon (delete icon).

Step 5

Enter the required information.

Value

Description

Name

(Required) Enter a name to uniquely identify this connector.

Description

Optional description.

Cyber Vision Prefix

Enter an alphanumeric string to identify dynamic objects from this Cyber Vision's IP address when objects are sent to Security Cloud Control.

If you have one Cyber Vision IP address, you can enter any value such as 1 .

Pull Interval

(Default 60 seconds) Interval at which data mappings are retrieved from Cyber Vision.

The minimum value for Pull Interval is 1 second. You can set the maximum to any value you want. We recommend against setting the minimum to a low value because it can generate a lot of traffic, and, when applicable, can result in your being billed for the traffic.

Host

(Required) Enter the Cyber Vision fully qualified host name or IP address.

Port

(Required) Enter the Cyber Vision listen port.

Token

(Required) Enter the API token.

Score Type

Choices are CVSS and CSRS.

CVSS: Common vulnerability scoring system (CVSS) is an industry-standard system that retrieves values from the national vulnerability database to describe risk associated with vulnerabilities. CVSS scores power a vulnerability's severity and risk value.

CSRS: The Cisco Security Risk Score (CSRS) CSRS evaluates vulnerabilities beyond technical severity, focusing on how attackers might exploit them. Scores range from 0 to 100 and are based on factors such as existing vulnerabilities, threat intelligence, and the effectiveness of security controls. This score helps prioritize critical vulnerabilities and allocate resources effectively.

Severity

Click the minimum vulnerability severity level for the dynamic attributes connector to send IP addresses to the Secure Firewall Management Center. (For example, if you click high, IP addresses of hosts with either high or severe vulnerabilities are sent.)

Choices:

  • Critical

  • High

  • Medium

  • Low

Dynamic Object Name

Enter a name to identify the dynamic object created by this connector.

Certificate

You have these options:

  • Paste the certificate authority (CA) chain as discussed in Manually get a certificate authority (CA) chain.

  • Click Get Certificate > Fetch to automatically fetch the certificate. Ensure that you have specified a valid host and IP address that exactly matches the server certificate.

  • Click Get Certificate > Browse from file to upload a certificate chain you downloaded previously. Ensure that the host or IP address of the certificate you upload exactly matches the Common Name of the CA certificate you enter in host or IP address field.

  1. Click Test and make sure the test succeeds before you save the connector.

  2. Click Save.

    Status column displays Ok.

    Create an adapter