Because the wants and complexity of organizational networks increase, there’s a higher want to supply risk protections that span numerous use circumstances, architectures, and assault vectors. These new capabilities present in our newest firewall software program launch, Cisco Safe Firewall model 10.0, increase the scope of safety to incorporate beforehand unidentified threats, extra precisely match safety guidelines to customers and functions, and supply higher risk detection capabilities for clustered firewall architectures.
You may check drive these capabilities as we speak with Safe Firewall Check Drive, an instructor-led course that can information you thru the Safe Firewall and its highly effective roles in cybersecurity in your group.
Expanded Protections for ML-based Intrusion Prevention
SnortML enhances the sturdy capabilities of Safe Firewall’s intrusion prevention engine, Snort3, by detecting and analyzing zero-day threats in-line. As a result of this know-how makes use of machine studying to actively establish threats as an alternative of pattern-matching guidelines, it is ready to detect threats for which there could not but be a pattern-based conventional rule.
With the discharge of Cisco Safe Firewall model 10.0, expanded protections overlaying SQL injection assaults, Command Injection assaults, Cross-Web site Scripting exploits at the moment are obtainable. You may be taught extra about SnortML within the Cisco Safe Necessities SnortML Part.

AppID Default Port Specs
Cisco AppID permits for the fast computerized classification of community visitors pertaining to particular functions, vastly simplifying the creation and upkeep of insurance policies controlling entry to them. Cisco Safe Firewall model 10.0 now gives default port specs for functions in order that new insurance policies set for these functions will be scoped to the default ports they use. This bolsters safety by guaranteeing guidelines are correctly scoped and never making use of unintentionally to unrelated visitors by specified with functions solely making use of to visitors on the ports the applying is prone to use. It additionally could enhance efficiency in busy networks with extra complicated safety insurance policies. This conduct will be altered in order that the insurance policies apply to all ports if desired. To make sure constant operations, current AppID guidelines is not going to be modified.
DNS Guidelines with Safety Group Tag Attributes
Fashionable customers incessantly transfer between networks, altering VLANs, IP addresses, and gadget profiles, making it difficult to supply DNS filtering guidelines to scoped teams of customers. DNS filtering guidelines are a important a part of organizational safety, offering the flexibility to dam or redirect domains based mostly on particular person domains, identified dangerous actor domains, or classes of websites.
Safety Group Tags (SGTs) deal with the shifting nature of recent customers’ connections by anchoring to a verified person id as an alternative of the ever-changing community attributes. Cisco Safe Firewall model 10.0 ties DNS filtering to SGTs, enabling seamless and correct coverage software because the person strikes throughout networks.
Portscan Detection and Prevention for Clustered Firewalls
Cisco Safe Firewall protects organizations in opposition to undesired portscans, the place instruments quickly probe 1000’s of ports throughout community gadgets to go looking out open communication paths and doable exploit vectors. Cisco Safe Firewall model 10.0 brings new capabilities for clustered firewall configurations, permitting identification of portscan makes an attempt even when the connections are distributed amongst firewalls in a cluster. This ensures clustered configurations can quickly establish and enact protections in opposition to these doubtlessly exploitative efforts.
It is Simpler Than Ever to Improve
Utilizing AIOps in Cisco Safety Cloud Management, the method to improve your Safe Firewall software program is streamlined and device-personalized. Improve workflows at the moment are 90% sooner. Safety Cloud Management is a unified administration interface that gives superior safety, simplified operations, and real-time intelligence for a safer, scalable future.
Take a Fingers-On Have a look at Cisco Safe Firewall 10.0
Need to dive deeper into Cisco firewalls? Join the Cisco Safe Firewall Check Drive, an instructor-led, four-hour hands-on course the place you’ll expertise the Cisco firewall know-how in motion and be taught concerning the newest safety challenges and attacker methods.
We’d love to listen to what you assume! Ask a query and keep linked with Cisco Safety on social media.
Cisco Safety Social Media
LinkedIn
Fb
Instagram
