The firewall tracks the state of connections passing through it and permits return traffic that belongs to an established session while dropping unsolicited packets. Access control rules match on source and destination addresses, ports, protocols, zones, and interfaces. The connection table is used for handling of related protocol channels and is synchronized to a peer in high availability configurations.
02
Next-generation intrusion prevention system (NGIPS) based on Snort inspection engine
Traffic is inspected by an intrusion prevention engine built on Snort, which reassembles streams, normalizes protocol traffic, and matches it against rules that detect exploit and attack traffic. Matching traffic generates intrusion events and, in inline deployments, can be dropped. Intrusion policies are attached to access control rules so different traffic can be inspected with different rule sets.
03
Vulnerability-focused IPS rules with Talos threat intelligence updates
Intrusion rules are written against the underlying vulnerabilities rather than only specific exploit samples, so one rule covers multiple attack variants. Rule sets and detection updates are produced by Cisco Talos and delivered to the device on a recurring schedule. Administrators can schedule automatic update downloads and deployment of the new rules to managed devices.
04
Application Visibility and Control (AVC) identifying 4,000+ applications
The device identifies the applications in use on the network by inspecting traffic, recognizing several thousand applications along with their types, risk, business relevance, and categories. Detected applications appear in event and dashboard reporting for visibility. Access control rules and QoS rules can match on the identified application or its attributes, so a specific application can be allowed, blocked, or rate limited regardless of port.
05
Custom application detectors via OpenAppID
Administrators can create their own application detectors when an application is not covered by the shipped set, using the OpenAppID detector language. Custom detectors define the patterns that identify the application in traffic and are imported into the management platform and pushed to devices. Once active, the custom application can be used in access control and other policies like a built-in one.
Your plan caps how many capabilities are shown — upgrade to see the full list