|
Platform Features
|
|
Secure Firewall 3100.
|
We introduced the Secure Firewall 3110, 3120, 3130, and 3140.
You can hot swap a network module of the same type while the firewall
is powered up without having to reboot; making other module changes
requires a reboot. Secure Firewall 3100 25 Gbps interfaces support
Forward Error Correction as well as speed detection based on the SFP
installed. The SSDs are self-encrypting drives (SEDs), and if you
have 2 SSDs, they form a software RAID.
Note that the Version 7.1 device manager does not
include online help for these devices. See the documentation posted
on Cisco.com.
New/Modified screens:
New/Modified Firewall Threat Defense commands: configure network speed, configure raid, show raid, show ssd
|
|
FTDv for AWS instances.
|
FTDv for AWS adds support for these instances:
-
c5a.xlarge, c5a.2xlarge, c5a.4xlarge
-
c5ad.xlarge, c5ad.2xlarge, c5ad.4xlarge
-
c5d.xlarge, c5d.2xlarge, c5d.4xlarge
-
c5n.xlarge, c5n.2xlarge,
c5n.4xlarge
-
i3en.xlarge, i3en.2xlarge, i3en.3xlarge
-
inf1.xlarge, inf1.2xlarge
-
m5.xlarge, m5.2xlarge, m5.4xlarge
-
m5a.xlarge, m5a.2xlarge, m5a.4xlarge
-
m5ad.xlarge, m5ad.2xlarge, m5ad.4xlarge
-
m5d.xlarge, m5d.2xlarge, m5d.4xlarge
-
m5dn.xlarge, m5dn.2xlarge, m5dn.4xlarge
-
m5n.xlarge, m5n.2xlarge, m5n.4xlarge
-
m5zn.xlarge, m5zn.2xlarge, m5zn.3xlarge
-
r5.xlarge, r5.2xlarge, r5.4xlarge
-
r5a.xlarge, r5a.2xlarge, r5a.4xlarge
-
r5ad.xlarge, r5ad.2xlarge, r5ad.4xlarge
-
r5b.xlarge, r5b.2xlarge, r5b.4xlarge
-
r5d.xlarge, r5d.2xlarge, r5d.4xlarge
-
r5dn.xlarge, r5dn.2xlarge, r5dn.4xlarge
-
r5n.xlarge, r5n.2xlarge, r5n.4xlarge
-
z1d.xlarge, z1d.2xlarge, z1d.3xlarge
|
|
FTDv for Azure instances.
|
FTDv for Azure adds support for these instances:
-
Standard_D8s_v3
-
Standard_D16s_v3
-
Standard_F8s_v2
-
Standard_F16s_v2
|
|
Support ends for the ASA 5508-X and 5516-X. The last supported release is 7.0.
|
You cannot install Firewall Threat Defense 7.1 on an ASA 5508-X or 5516-X. The last supported release for these models is Firewall Threat Defense 7.0.
|
|
Firewall and IPS Features
|
|
Network Analysis Policy (NAP) configuration for Snort 3.
|
You can use Firewall Device
Manager to configure the Network Analysis Policy (NAP) when running Snort 3. Network analysis policies control traffic preprocessing
inspection. Inspectors prepare traffic to be further inspected by normalizing traffic and identifying protocol anomalies.
You can select which NAP is used for all traffic, and customize the settings to work best with the traffic in your network.
You cannot configure the NAP when running Snort 2.
We added the Network Analysis Policy to the settings dialog box, with an embedded JSON editor to
allow direct changes, and other features to let you upload
overrides, or download the ones you create.
|
|
Manual NAT support for fully-qualified domain name (FQDN) objects as
the translated destination.
|
You can use an FQDN network object, such as one specifying
www.example.com, as the translated destination address in manual NAT
rules. The system configures the rule based on the IP address
returned from the DNS server.
|
|
Improved active authentication for identity rules.
|
You can configure active authentication for identity policy rules to
redirect the user’s authentication to a fully-qualified domain name
(FQDN) rather than the IP address of the interface through which the
user’s connection enters the device. The FQDN must resolve to the IP
address of one of the interfaces on the device. By using an FQDN,
you can assign a certificate for active authentication that the
client will recognize, thus avoiding the untrusted certificate
warning users get when being redirected to an IP address. The
certificate can specify the FQDN, a wildcard FQDN, or multiple FQDNs
in the Subject Alternate Names (SAN) in the certificate.
We added the Redirect to Host Name option in
the identity policy settings.
|
|
VPN Features
|
|
Backup remote peers for site-to-site VPN.
|
You can configure a site-to-site VPN connection to include remote
backup peers. If the primary remote peer is unavailable, the system
will try to re-establish the VPN connection using one of the backup
peers. You can configure separate pre-shared keys or certificates
for each backup peer. Backup peers are supported for policy-based
connections only, and are not available for route-based (virtual
tunnel interface) connections.
We updated the site-to-site VPN wizard to include backup peer
configuration.
|
|
Password management for remote access VPN (MSCHAPv2).
|
You can enable password management for remote access VPN. This allows
AnyConnect to prompt the user to change an expired password. Without
password management, users must change expired passwords directly
with the AAA server, and AnyConnect does not prompt the user to
change passwords. For LDAP servers, you can also set a warning
period to notify users of upcoming password expiration.
We added the Enable Password Management option to the authentication
settings for remote access VPN connection profiles.
|
|
AnyConnect VPN SAML external browser.
|
When you use SAML as the primary authentication method for a remote
access VPN connection profile, you can elect to have the AnyConnect
client use the client’s local browser instead of the AnyConnect
embedded browser to perform the web authentication. This option
enables single sign-on (SSO) between your VPN authentication and
other corporate logins. Also choose this option if you want to
support web authentication methods, such as biometric
authentication, that cannot be performed in the embedded
browser.
We updated the remote access VPN connection profile wizard to allow
you to configure the SAML Login
Experience.
|
|
Administrative and Troubleshooting Features
|
|
Dynamic Domain Name System (DDNS) support for
updating fully-qualified domain name (FQDN) to IP address
mappings for system interfaces.
|
Upgrade impact. Redo FlexConfigs after upgrade.
You can configure DDNS for the interfaces on the system to send
dynamic updates to DNS servers. This helps ensure that FQDNs defined
for the interfaces resolve to the correct address, making it easier
for users to access the system using a hostname rather than an IP
address. This is especially useful for interfaces that get their
addresses using DHCP, but it is also useful for statically-addressed
interfaces.
After upgrade, if you had used FlexConfig to configure DDNS, you must redo your configuration using Firewall Device
Manager or the Firewall Threat Defense API, and remove the DDNS FlexConfig object from the FlexConfig policy, before you can deploy changes again.
If you configure DDNS using Firewall Device
Manager, then switch to Firewall Management
Center management, the DDNS configuration is retained so that Firewall Management
Center can find the system using the DNS name.
In Firewall Device
Manager, we added the page. In the Firewall Threat Defense API, we added the DDNSService and DDNSInterfaceSettings resources.
|
|
The dig command replaces the
nslookup command in the device
CLI.
|
To look up the IP address of a fully-qualified domain name (FQDN) in
the device CLI, use the dig command. The
nslookup command has been removed.
|
|
DHCP relay configuration using Firewall Device
Manager.
|
You can use Firewall Device
Manager to configure DHCP relay. Using DHCP relay on an interface, you can direct DHCP requests to a DHCP server that is accessible
through the other interface. You can configure DHCP relay on physical interfaces, subinterfaces, EtherChannels, and VLAN interfaces.
You cannot configure DHCP relay if you configure a DHCP server on any interface.
We added the page, and moved DHCP Server under the new DHCP
heading.
|
|
Key type and size for self-signed certificates in Firewall Device
Manager.
|
You can specify the key type and size when generating new self-signed internal and internal CA certificates in Firewall Device
Manager. Key types include RSA, ECDSA, and EDDSA. The allowed sizes differ by key type. We now warn you if you upload a certificate
whose key size is smaller than the minimum recommended length. There is also a weak key pre-defined search filter to help
you find weak certificates, which you should replace if possible.
|
|
Usage validation restrictions for trusted CA certificates.
|
You can specify whether a trusted CA certificate can be used to
validate certain types of connections. You can allow, or prevent,
validation for SSL server (used by dynamic DNS), SSL client (used by
remote access VPN), IPsec client (used by site-to-site VPN), or
other features that are not managed by the Snort inspection engine,
such as LDAPS. The primary purpose of these options is to let you
prevent VPN connections from getting established because they can be
validated against a particular certificate.
We added Validation Usage as a property for
trusted CA certificates.
|
|
Generating the admin password in Firewall Device
Manager.
|
During initial system configuration in Firewall Device
Manager, or when you change the admin password through Firewall Device
Manager, you can now click a button to generate a random 16 character password.
|
|
Startup time and tmatch compilation status.
|
The show version command now includes
information on how long it took to start (boot) up the system. Note
that the larger the configuration, the longer it takes to boot up
the system.
The new show asp rule-engine command shows
status on tmatch compilation. Tmatch compilation is used for an
access list that is used as an access group, the NAT table, and some
other items. It is an internal process that can consume CPU
resources and impact performance while in progress, if you have very
large ACLs and NAT tables. Compilation time depends on the size of
the access list, NAT table, and so forth.
|
|
Enhancements to show access-list
element-count output.
|
The output of the show access-list
element-count command has been enhanced. When used
with object-group search enabled, the output includes details about
the number of object groups in the element count.
In addition, the show tech-support output
now includes the output from show access-list
element-count and show asp
rule-engine .
|
|
Use Firewall Device
Manager to configure the Firewall Threat Defense for management by a Firewall Management
Center.
|
When you perform initial setup using Firewall Device
Manager, all interface configuration completed in Firewall Device
Manager is retained when you switch to Firewall Management
Center for management, in addition to the Management and Firewall Management
Center access settings. Note that other default configuration settings, such as the access control policy or security zones, are
not retained. When you use the Firewall Threat Defense CLI, only the Management and Firewall Management
Center access settings are retained (for example, the default inside interface configuration is not retained).
After you switch to Firewall Management
Center, you can no longer use Firewall Device
Manager to manage the Firewall Threat Defense.
New/Modified screens:
|
|
Automatically update CA
bundles.
|
Upgrade impact. The system connects to Cisco for something
new.
The local CA bundle contains certificates to access several
Cisco services. The system now automatically queries Cisco
for new CA certificates at a daily system-defined time.
Previously, you had to upgrade the software to update CA
certificates. You can use the CLI to disable this
feature.
New resources: https://cisco.com/security/pki/
New/modified CLI commands: configure cert-update
auto-update , configure
cert-update run-now ,
configure cert-update
test , show
cert-update
Version restrictions: Requires Version 7.0.5, 7.1.0.3, or
7.2.4+.
See: Cisco Secure Firewall Threat
Defense Command Reference
|
|
FTD REST API version 6.2 (v6).
|
The Firewall Threat Defense REST API for software version 7.1 is version 6.2. You can use v6 in the API URLs, or preferentially, use /latest/ to signify
you are using the most recent API version that is supported on the device. Note that the URL version path element for 6.2
is the same as 6.0/1: v6.
Please re-evaluate all existing calls, as changes might have been mode to the resource models you are using. To open the API
Explorer, where you can view the resources, log into Firewall Threat Defense, then click the more options button ( ) and choose API Explorer.
|