What's New in R82.10
R82.10 Release Notes
What's New in R82.10
Introduction
Enterprises are rapidly adopting AI to achieve impressive productivity gains. However, AI systems also introduce unprecedented new security challenges. Traditional detection and response frameworks are no longer enough to protect today’s distributed, hybrid mesh networks. It is imperative that enterprises shift left to prevention-first security. R82.10 enables security for the AI transformation, Hybrid Mesh Network, and advanced threats.
R82.10 delivers stronger threat prevention, higher scalability & performance, and greater operational simplicity.
Architectural Updates: R82.10 features an upgraded OS based on Linux kernel 5.14 versus 4.xx in previous releases. This release runs exclusively in UPPAK mode (User Space Performance Pack).
Stronger Threat Prevention
Threat Prevention Insights: Provides administrators with clear insights into the effectiveness and coverage of Threat Prevention and IPS, featuring visualizations, metrics, and recommendations to refine rules and profiles.
Advanced Zero Phishing: Zero Phishing now protects encrypted traffic from phishing attacks at the domain level - enabling domain analysis by ThreatCloud AI without requiring SSL Inspection or decryption.
Protection from HTML Smuggling: Zero Phishing introduces a powerful new capability to detect and block HTML smuggling, an advanced cyberattack technique that avoids firewall detection by building malware locally within a target's web browser.
Expanded DNS Protection: Introduces DNS-over-TLS threat prevention to block malicious DNS activity over encrypted channels.
Hardened Encryption: HTTPS Inspection now supports Hardware Security Module (HSM) for TLS 1.3, making it considerably harder for attackers to compromise encrypted traffic.
MCP Detection and Visibility: Introduces MCP (Model Context Protocol) detection and visibility to ensure that only authorized MCP communications are allowed across the network.
Enhanced Drop Templates: New drop templates improve resilience by reducing CPU usage to enable blocking a much higher volume of denial of service (DoS) attacks while maintaining maximum throughput for permitted traffic.
4 New ThreatCloud AI Engines: PDF security with advanced image and text analysis, malicious GitHub-hosted account and repository detection, automatic creation of file and IPS protection rules, and a new web security model with enhanced decision-making capabilities.
Adaptive IPS: A new optimized IPS defense profile is tailored to fit an organization’s exact requirements. This enables IPS to be turned on with minimal CPU performance impact, for improved resiliency and threat detection.
Scalability & Performance
- Scalable Identity Management: Improved identity awareness across the enterprise for unified policy enforcement and scalable identity sharing.
- Each Policy Decision Point ( PDP) can now manage up to 1M identities, reducing the number of required PDPs by up to 5X.
- A single PDP can share identities with up to 300 Policy Enforcement Point ( PEP) gateways, even across multiple domains.
- Direct PDP to PEP sharing works across Multi-Domain Security Management without an Identity Broker, simplifying configuration.
- Support for SD-WAN in MaestroSecurity Groups: Enables higher scalability in branch office networks while providing the highest system reliability and redundancy.
- Security Management Scalability: Increases the maximum number of managed Security Gateways to 1,500 per management domain. Users can further scale to 10,000 gateways in a Multi-Domain Security Management Server configuration.
Operational Simplicity
- Centralized Identity Management: Identity and Trust is a cloud service that integrates with on-premises network security, provides the option of integrating with multiple identity providers, and eliminates the need for separate management portals.
- New Access Policy Log Generation Modes: New logging mode enables streamlined control over daily log output, with improved granularity into log levels and analytics on high-volume rules. The Aggregated mode greatly reduces daily log volume by up to 70%, reducing storage needs accordingly.
- Simplified Route-Based VPN: Automatically configures Site to Site VPN based on network topology, enabling one-click setup and dynamic routing with BGP.
- Enhanced Web-based UI: New web-based UI allows users to manage common security use cases from the web for more flexibility.
Threat Prevention
Threat Prevention Insights
- Provides clear insight into Threat Prevention and IPS effectiveness and coverage, with visualizations, metrics, and recommendations to refine policy and profiles. A tuned policy enhances coverage, reduces noise, and maintains Security Gateway performance predictable and manageable.
Key Features:
- Misconfigurations & Optimizations:
- Detects misconfigured IPS profile, for example, disabled protections, conflicting exceptions, and outdated profiles).
- Surfaces overly permissive settings and hitless items, with guidance to remediate safely.
- Prioritizes changes by security impact and performance benefit.
- IPS Profile Tuning:
- Highlights noisy signatures, false-positive candidates, and protections generating excessive logs.
- Suggests severity-aware tuning to cut noise while preserving critical coverage.
Zero Phishing
- Zero Phishing provides prevention for customers without HTTPS Inspection, utilizing Server Name Indication (SNI) in TLS handshake.
- Zero Phishing introduces a powerful new capability to detect and block HTML Smuggling, a technique used by threat actors to bypass traditional Network Threat Prevention systems.
ThreatCloud AI Engines
- Threat Emulation PDF Engine: Combines advanced image and text analysis.
- Image analysis: QR code extraction, page-layout parsing, brand misuse detection.
- Text analysis: SLM (Small Language Model) flags social-engineering patterns in forms, lures, and conversational tone.
- GitHub Abuse Engine: Detects malicious GitHub-hosted accounts and repositories used for credential theft and drive-by malware downloads.
- AI Web Security: Features enhanced decision-making capabilities across web traffic by combining DNS metadata, certificate attributes, and behavioral signals.
- Generative AI Protections Engine: Automates the creation of File and IPS protection rules, reducing analysis time from days to hours.
DNS Security
- Introducing DoT (DNS over TLS) - Threat Prevention capabilities for malicious DNS activity over the TLS protocol.
HTTPS Inspection
- Added support for the hybrid PQC-safe key exchange group "X25519MLKEM768" within HTTPS Inspection.
- HTTPS Inspection now supports Hardware Security Module (HSM) integration for TLS 1.3, ensuring secure storage and management of private keys during encrypted traffic inspection.
IPS
- New capability that automatically detects and remediates CPU-intensive IPS protections with a dedicated SmartView dashboard displaying IPS statistics.
Security Gateway
Identity Awareness
- Introducing Scalable Identity Sharing that allows more flexible and efficient identity distribution.
- Improved PDP Performance - Policy Decision Point (PDP) gateways can now handle up to 1 million identities each.
URL Filtering
- The URL FilteringSoftware Blade now supports automatic categorization of websites listed in the "Terrorism" category of the CTIRU list.
Site to Site VPN
- Added support for standard ML-KEM as required by the FIPS 203 standard.
- Simplified Route-based VPN - Automatically configures route-based VPNs.
SD-WAN
- Added support for SD-WAN in Maestro Security Groups.
Security Gateway Enhancement
- New MCP Detection and Visibility feature designed to monitor and manage Model Context Protocol (MCP) traffic within your network.
Dynamic Routing
- Added support for these Dynamic Routing features:
- Support for up to 256 PIM interfaces.
- Support for up to 500 BGP peers.
- Support for BGP Large Communities.
Cluster and Scalability
- The ElasticXL clustering and Maestro Security Group now support SecureXL in the User Mode (UPPAK).
Internal CA
- Increased RSA Key Size for Internal CA – The default RSA key size for the Root CA has been increased from 2048 bits to 3072 bits.
Gaia OS Security
- In Gaia Clish, you can configure the number of hashing rounds for new passwords.
Security Management
Logging and Monitoring
- New Access Policy Log Generation Modes: Standard and Aggregated. The Aggregated mode significantly reduces the daily log volume.
Compliance
- Added support for new regulations:
- CSA CCoP 2.0
- DORA 2023
- ISO 27002 2022
- NIST800-82r3
Cloud Firewall Security
CloudGuard Controller
- New CloudGuard Controller scanner for Proxmox Virtual Environment.