Cisco Secure Firewall 10.0 introduces four major security observability features: simplified decryption with Easy Decrypt for managing encrypted traffic inspection, QUIC protocol decryption to handle the growing adoption of UDP-based encrypted connections, shadow traffic reporting to identify privacy technologies causing visibility loss (multihop proxies, encrypted DNS, fake TLS, evasive VPNs, domain fronting), and advanced logging with application metadata, intelligent PCAPs, and protocol deviation detection. These enhancements address the challenge of inspecting encrypted traffic, which now carries most threats, and provide deeper insights for security monitoring and threat detection.
Table of contents
Simplified decryptionQUIC decryptionShadow traffic reportingIncluded “Loss of Visibility” reportsAdvanced loggingSplunk correlation with advanced loggingTake a hands-on look at Cisco Secure Firewall 10.022 Impressions