History for zero trust network access

This reference provides the minimum Firewall Management Center and Threat Defense versions needed to support zero trust application policies and monitoring.

Feature

Minimum Cloud-Delivered Firewall Management Center

Minimum Firewall Threat Defense

Details

Universal Zero Trust Network Access (universal ZTNA).

10.1.0

10.1.0

Universal ZTNA integrates with the Lina datapath, improving performance, scalability, and serviceability without requiring dedicated CPU cores or device reboots.

This release supports mixed-mode IPv4 and IPv6 combinations for outer and inner connections, along with IPv6 Source NAT and hardware acceleration for outer tunnels.

The system automatically enrolls Secure Access certificates as trustpoints, simplifying deployment.

Upgrade Impact:

Following a Threat Defense device upgrade, the system automatically reverts the core profile, clears stale certificates, and disables the UZTNA feature in the LINA configuration. You must perform a mandatory deployment from the Firewall Management Center to push new trustpoints, re-enable the feature, and restore universal ZTNA traffic handling.

Universal Zero Trust Network Access (universal ZTNA).

7.7.10

7.7.10

Universal Zero Trust Network Access (universal ZTNA) is a comprehensive solution that provides secure access to internal network resources based on user identity, trust, and posture. It ensures that access to one application does not implicitly grant access to the entire network, as with remote access VPN.

New/modified screens: Policies > Security policies > Zero Trust Application

Requires Cisco Secure Access and Security Cloud Control.

Deployment restrictions: Not supported with clustered devices, container instances, or transparent mode.

Supported platforms: Secure Firewall 1150, 3100, 4100, 4200, and Firewall Threat Defense Virtual.

Clientless zero-trust access.

20230929

7.4.0 with Snort 3

Zero Trust Access allows you to authenticate and authorize access to protected web based resources, applications, or data from inside (on-premises) or outside (remote) the network using an external SAML Identity Provider (IdP) policy.

The configuration consists of a Zero Trust Application Policy (ZTAP), Application Group, and Applications.

New/modified screens: Policies > Zero Trust Application

New/modified CLI commands:

  • show running-config zero-trust application

  • show running-config zero-trust application-group

  • show zero-trust sessions

  • show zero-trust statistics

  • show cluster zero-trust statistics

  • clear zero-trust sessions application

  • clear zero-trust sessions user

  • clear zero-trust statistics