Firepower 10.0

 Firepower 10.0


Release Notes:

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/release-notes/threat-defense/100/management-center-release-notes-10-0.html

The ability to limit an access control policy (ACP) rule to an application's Application Default ports was introduced in Cisco Secure Firewall Threat Defense (FTD) and Management Center (FMC) version 10.0


When building an ACP rule, a new "Application Default" option on the Applications tab automatically limits the rule to the application's standard ports. 

These port definitions are managed dynamically by Cisco via Vulnerability Database (VDB) updates.

Previous Behavior: Prior to version 10.0, adding an application to a rule implicitly meant it matched on Any port, which required the firewall to let initial packets through for Layer 7 inspection. You can still manually toggle back to "Any" port or apply custom port overrides

Comments