Security Lab — Cisco BFSI portfolio map
A placement-oriented mind map of Cisco offerings for large BFSI environments.
This page maps Cisco product families to the places they usually occupy in a large banking, financial services, and insurance environment. It is a learning guide, not a bill of materials.
Executive Map
Cisco in BFSI
├── Data center and private cloud
│ ├── Nexus 9000 / NX-OS
│ ├── ACI / APIC
│ ├── Nexus Dashboard / NDFC / NDO / Insights
│ ├── MDS 9000 SAN
│ ├── UCS / Intersight
│ └── Secure Workload
├── Campus, branch, and workplace
│ ├── Catalyst switching and wireless
│ ├── Catalyst Center
│ ├── ISE
│ └── Meraki
├── WAN, branch edge, and cloud edge
│ ├── Catalyst SD-WAN
│ ├── Catalyst 8000 / 8000V
│ ├── Meraki MX SD-WAN
│ └── Secure Access / SASE
├── Security architecture
│ ├── Secure Firewall / FMC / FTDv
│ ├── ISE / TrustSec / segmentation
│ ├── Duo / Identity Intelligence
│ ├── Secure Access / Umbrella / SSE
│ ├── XDR / Secure Endpoint
│ └── Secure Workload
├── Observability and operations
│ ├── Splunk Enterprise / Cloud
│ ├── Splunk Observability
│ ├── Splunk AppDynamics
│ ├── ThousandEyes
│ └── Nexus Dashboard / Catalyst Center / Meraki assurance
└── Collaboration, CX, and facilities
├── Webex / Webex Contact Center
├── Industrial Ethernet / IoT routers
└── Meraki cameras and sensors
Placement Model
| Domain | BFSI placement | Cisco families | Why it matters |
|---|---|---|---|
| Core data centers | Primary DC, DR DC, private cloud, payment and core banking networks | Nexus 9000, NX-OS, ACI, Nexus Dashboard, MDS, UCS, Intersight | Low latency, high availability, segmentation, predictable change |
| Branch and campus | HQ, operations centers, branches, call centers | Catalyst, Catalyst Center, ISE, Meraki | User access, NAC, wireless assurance, branch resilience |
| WAN and cloud edge | MPLS, DIA, SD-WAN, colocation, cloud on-ramps | Catalyst SD-WAN, Catalyst 8000/8000V, Meraki MX, ThousandEyes | Secure branch connectivity, SaaS performance, cloud reachability |
| Perimeter and segmentation | Internet edge, DMZ, partner edge, east-west controls | Secure Firewall, FMC, FTDv, ASAv, Secure Workload, ISE | PCI zones, partner isolation, zero-trust segmentation |
| Identity and access | Workforce access, privileged access, network admission, remote access | ISE, Duo, Secure Access, Identity Intelligence | MFA, device trust, NAC, ZTNA, least privilege |
| SOC and SecOps | SIEM, XDR, endpoint response, incident response | Splunk, Cisco XDR, Secure Endpoint, Talos | Detection, investigation, compliance evidence |
| Observability | Digital banking, payments, mobile apps, internet paths | Splunk Observability, AppDynamics, ThousandEyes, Nexus Dashboard Insights | Customer experience and root-cause isolation |
| Collaboration and CX | HQ, branches, operations rooms, contact centers | Webex, Webex Contact Center, room devices | Regulated collaboration and customer support |
| Facilities and edge | Buildings, cameras, sensors, remote sites, ATM-support networks | Industrial Ethernet, industrial routers, Meraki cameras/sensors | Physical security and remote-site visibility |
Learning Tracks
| Track | Start with | Then add |
|---|---|---|
| Data center fabric | Nexus 9300v, NX-OS, underlay routing, MP-BGP EVPN, VXLAN | Multisite border gateways, Nexus Dashboard, NDFC, then ACI |
| Branch and WAN | IOS XE routing and Catalyst 8000V concepts | Catalyst SD-WAN, policies, segmentation, cloud on-ramp |
| Identity and segmentation | ISE policy, 802.1X, MAB, TACACS+ | TrustSec/SGT, firewall integration, pxGrid |
| Security edge | Firewall policy, NAT, IPS, VPN, logging | FMC/FTDv, ASAv, Secure Access, Duo, XDR |
| Security operations | Wazuh, Security Onion, Greenbone lab loops | Splunk, Cisco XDR, Secure Endpoint, Talos mapping |
| Observability | App and network telemetry concepts | ThousandEyes, AppDynamics, Splunk Observability |
Current Lab Mapping
| Cisco offering | Lab analog or target | Priority |
|---|---|---|
| Nexus 9300v | Imported into EVE-NG | Now |
| Nexus Dashboard | Downloaded, standalone VM pending | After manual fabric |
| NDFC | Evaluate inside Nexus Dashboard if entitlement allows | After Nexus Dashboard |
| ACI Simulator | Future virtual appliance | After NX-OS fundamentals |
| Catalyst 8000V | Future KVM/EVE image | WAN track |
| ISE | Future VM/ISO/OVA | Identity track |
| FTDv/FMCv | Future security VM pair | Firewall track |
| ASAv | Future classic firewall VM | Optional |
| Splunk | Trial/free option or map to Wazuh first | SOC and observability |
| ThousandEyes | Trial/licensed agents or conceptual mapping | Assurance |
| Meraki | Dashboard/API concepts unless hardware or trial is available | Branch operations |
Recommended Order
- NX-OS fundamentals and EVPN/VXLAN.
- Multisite EVPN/VXLAN and DCI.
- Nexus Dashboard and NDFC.
- Catalyst SD-WAN and Catalyst 8000V.
- ISE and network access control.
- Secure Firewall and FMC.
- Secure Workload microsegmentation.
- ACI/APIC after NX-OS is understood.
- Splunk, ThousandEyes, and AppDynamics placement.
- Secure Access, Duo, XDR, and AI-era security offerings.
Source Notes
The private lab repository keeps the fuller source-backed analysis at:
/home/ze/codex-security-lab-agent/docs/CISCO_BFSI_PORTFOLIO_MINDMAP.md