History for Regular Firewall Interfaces

Provides a comprehensive history of interface-related features, including hardware support, protocol enhancements, and configuration changes for Secure Firewall devices.

History for Regular Firewall Interfaces

Feature

Minimum Cloud-Delivered Firewall Management Center

Minimum Firewall Threat Defense

Details

Recursive DNS Server (RDNSS) and DNS Search List (DNSSL) options to advertise a list of DNS servers and domains to IPv6 clients

10.0.0

20251121

10.0.0

You can now configure Recursive DNS Server (RDNSS) and DNS Search List (DNSSL) options to provide DNS servers and domains to SLAAC clients using router advertisements.

New/modified screens: Devices > Device Management > Interfaces > Add/Edit Interfaces > IPv6 > Settings

New/modified commands: show ipv6 nd detail , show ipv6 nd ra dns-search-list , show ipv6 nd ra dns server , show ipv6 nd summary

Secure Firewall 200 hardware switch support

10.0.0

20251121

10.0.0

The Secure Firewall 200 supports setting each Ethernet interface to be a switch port or a firewall interface.

Secure Firewall 1210CP IEEE 802.3bt support (PoE++ and Hi-PoE)

7.7.0

7.7.0

See the following improvements related to support for IEEE 802.3bt:

  • PoE++ and Hi-PoE—Up to 90W per port.

  • Single- and dual-signature powered devices (PDs).

  • Power budgeting is done on a first-come, first-served basis.

  • Power budget fields were added to show power inline .

New/Modified screens: Devices > Device Management > Interfaces > Edit Physical Interface > PoE

New/Modified commands: show power inline

For models with built-in-switches, subinterfaces can't use VLAN 1

7.6

7.6

For models with built-in switches, you cannot create a subinterface using VLAN 1. VLAN 1 is reserved for the logical VLAN interface for switch ports.

If you upgrade a 1010 to 7.6 or later, and you have assigned VLAN 1 to a subinterface, you must change the VLAN ID for your subinterface to a new VLAN. You will not be able to deploy the configuration using VLAN 1.

Secure Firewall supports Dual-Arm Deployment Mode on AWS with GWLB

7.6

7.6

The Secure Firewall supports the dual-arm deployment mode on AWS with GWLB. This mode enables the firewall to directly forward internet-bound traffic to the internet through the internet gateway after traffic inspection, while also performing network address translation (NAT).

Secure Firewall 1210/1220 hardware switch support

7.6

7.6

The Secure Firewall 1210/1220 supports setting each Ethernet interface to be a switch port or a firewall interface

Secure Firewall 1210CP PoE+ support on Ethernet ports 1/5-1/8

7.6

7.6

The Secure Firewall 1210CP supports Power over Ethernet+ (PoE+) on Ethernet ports 1/5-1/8.

VXLAN VTEP IPv6 support

7.4

Any

You can now specify an IPv6 address for the VXLAN VTEP interface. IPv6 is not supported for the threat defense virtual cluster control link or for Geneve encapsulation.

New/Modified screens:

  • Devices > Device Management > Edit > VTEP > Add VTEP

    Devices > Device Management > Edit > Interfaces > Add Interfaces > VNI Interface

Requires Firewall Threat Defense version 7.4.

You can specify an IPv6 address for the VXLAN VTEP interface for Secure Firewall 4200 Series devices only.

Loopback interface support for BGP and management traffic

7.4

Any

You can use a loopback interface for: AAA, BGP, DNS, HTTP, ICMP, IPsec Flow Offload, NetFlow, SNMP, SSH, and Syslog.

Requires Firewall Threat Defense version 7.4.

Loopback interface support for VTI

7.3

Any

You can now add a loopback interface. The loopback interface helps to overcome path failures. If an interface goes down, you can access all interfaces through the IP address assigned to the loopback interface. For VTI, in addition to setting a loopback interface as the source interface, support has also been added to inherit the IP address from a loopback interface instead of a statically configured IP address.

New/Modified screens: Devices > Device Management > Interfaces > Add Interfaces > Add Loopback Interface

IPv6 DHCP

7.3

Any

The Firewall Threat Defense now supports the following features for IPv6 addressing: DHCPv6 Address client, DHCPv6 Prefix Delegation client, BGP router advertisement for delegated prefixes, and DHCPv6 stateless server.

New/Modified screens:

  • Devices > Device Management > Interfaces > Add/Edit Interfaces > IPv6 > DHCP

  • Objects > Object Management > DHCP IPv6 Pool

New/Modified commands: show bgp ipv6 unicast , show ipv6 dhcp , show ipv6 general-prefix

Paired proxy VXLAN for the Firewall Threat Defense Virtual for the Azure Gateway Load Balancer

7.3

Any

You can configure a paired proxy mode VXLAN interface for the Firewall Threat Defense Virtual in Azure for use with the Azure Gateway Load Balancer (GWLB).

New/Modified screens: Devices > Device Management > Device > Interfaces > Add Interfaces > VNI Interface

Supported platforms: Firewall Threat Defense Virtual in Azure

VXLAN support

7.2

Any

VXLAN encapsulation support was added.

New/Modified screens: Devices > Device Management > Device > VTEP , Devices > Device Management > Device > Interfaces > Add Interfaces > VNI Interface , and Devices > Device Management > Device > Interfaces edit physical interface > General

Supported platforms: All.

Geneve support for the Firewall Threat Defense Virtual

7.1

Any

Geneve encapsulation support was added for the Firewall Threat Defense Virtual to support single-arm proxy for the Amazon Web Services (AWS) Gateway Load Balancer.

This feature requires Snort 3.

31-bit Subnet Mask

7.0

Any

For routed interfaces, you can configure an IP address on a 31-bit subnet for point-to-point connections. This feature is not supported for BVIs for bridge groups or with multicast routing.

New/Modified screens: Devices > Device Management > Interfaces

Synchronization between the Firewall Threat Defense operational link state and the physical link state for the Firepower 4100/9300

6.7

Any

The Firepower 4100/9300 chassis can now synchronize the Firewall Threat Defense operational link state with the physical link state for data interfaces.

Note

This feature is not supported for clustering, container instances, or Firewall Threat Defense with a Radware vDP decorator. It is also not supported for ASA.

New/Modified Firepower Chassis Manager screens: Logical Devices > Enable Link State

New/Modified FXOS commands: set link-state-sync enabled , show interface expand detail

Firepower 1010 hardware switch support

6.5

Any

The Firepower 1010 supports setting each Ethernet interface to be a switch port or a firewall interface.

Firepower 1010 PoE+ support on Ethernet 1/7 and Ethernet 1/8

6.5

Any

The Firepower 1010 supports Power over Ethernet+ (PoE+) on Ethernet 1/7 and Ethernet 1/8 when they are configured as switch ports.

VLAN subinterfaces for use with container instances

6.3.0

Any

To provide flexible physical interface use, you can create VLAN subinterfaces in FXOS and also share interfaces between multiple instances.

Data-sharing interfaces for container instances

6.3.0

Any

To provide flexible physical interface use, you can share interfaces between multiple instances.

Integrated Routing and Bridging

6.2.0

Any

Integrated Routing and Bridging provides the ability to route between a bridge group and a routed interface. The bridge group participates in routing by using a Bridge Virtual Interface (BVI) to act as a gateway for the bridge group.