Sitting through SASE and firewall demos for a refresh and every single one has the same slide now. Dynamic threat prevention, AI this and behavioral that, stops threats as they evolve. Every vendor. Same slide. When I ask what is under it, it comes back to IPS and anti-malware and a DNS filter which is what we already run on the firewall.
Which leaves me stuck on whether I am getting a capability we do not have or just paying more for the same three engines with a new sticker. Our signature IPS catches the commodity junk fine. Anything a bit off shape walks straight through it and that is exactly what the dynamic engines are supposed to fix.
I have been burned by this pitch before so I am not taking the deck at face value. If you run one of these in prod, I want to know whether the behavioral side ever caught something real that your signatures missed and how bad the false positives got living with it day to day. Trying to work out what is worth paying for before I sign anything.
Source: r/Cisco · by /u/WolfShoddy7443