Skip to main content

Distributed Cloud Firewall Supported Capabilities

Since Controller Version 6.8, DCF has been supported in AWS, AWS GovCloud, Azure, Azure Government, and GCP.

Ranges

Capability6.86.97.07.17.28.08.18.2
Number of SmartGroups5005005005001,2001,2001,2001,200
Number of Domains per WebGroup3,0003,0003,0003,0003,000
Number of CIDRs per Group3,0003,0003,0003,00010,00010,00010,00010,000
Total Number of CIDRs10,00010,000300,000300,000300,000300,000
Number of DCF Rules2,0002,0002,0002,0005,0005,0005,0005,000

Supported Features

The following are supported on AWS, Azure and GCP unless otherwise noted.
  • PV = feature is in Preview
  • GA = feature is Generally Available
  • If a cell is blank the feature was not supported in that release.
Feature6.86.97.07.17.28.08.18.2
DCF on Edge Spoke (L4)PVPV
DCF on Edge Transit S2C (L4)PVPV
DCF Rules
Layer 4 RulesGAGAGAGAGAGAGA
Rules with Domain WebGroupsPVGAGAGAGAGA
Rules with URL WebGroupsPVPVPVPVPVPV
Rules with ExternalGroups (formerly GeoGroups and ThreatGroups)GAGAGAGA
DCF on Public Subnet Filtering GatewaysPVPVGAGA
DCF on Site2Cloud (L4 only on Transit)PVPVGAAWS (+Gov) GA, Azure (+Gov) GA, GCP PV, OCI PV
DCF on Site2Cloud (AWS, AWS GovCloud)PVPVGAAzure (+Gov) GA, AWS (+Gov) GA, GCP PV, OCI PV
DCF on Transit EgressPVPV
Security Group Orchestration (not supported on GCP)PV (Azure)PV (Azure, AWS)PV (AWS) GA (Azure)PV (AWS) GA (Azure)PV (AWS) GA (Azure)PV (AWS) GA (Azure)
DCF RulesetsGAGAGA
Deep Packet Inspection
Transparent TLS DecryptionPVPVPVPVPV
Suricata IDS (Egress only)PVPVPVPVPV
Advanced Features
Dynamic Signature UpdatePVPVPVPV
Import Decryption CertificatePVPVPVPVPV
Logging
Layer 4 logging (+Domain)GAGAGAGAGAGAGA
IDS/IPS loggingPVPVPVPVPVPV
Log export via SyslogGAGAGAGAGAGAGA
Asset Groups/SmartGroups
SmartGroups (VM/VPC/Subnet)GAGAGAGAGAGAGA
DNS Hostname SmartGroupsPVPVGAGA
Kubernetes SmartGroups (Workloads and Nodes)PVPV
Domain WebGroupsPVGAGAGAGAGA
URL WebGroupsPVPVPVPVPVPV
SNI Verification (valid with WebGroups)PVPVPV
ExternalGroups (includes Threat Feeds and Countries)PVPVGAGA
SmartGroups (S2C)GAGAGAGA
SaaS-Based Services
SaaS-Based Services (Azure and GitHub)PVAzure (GA) GitHub (PV)

Additional Capabilities

  • Overlapping IPs have been supported since Controller Version 7.0. Distributed Cloud Firewall (DCF) understands any defined SNAT/DNAT rules and updates the address for each gateway, enforcing the DCF rules.
  • DCF auto-prunes all rules and pushes only related rules to specific gateways.
  • SmartGroups dynamically change the resources inside the groups by tracking EC2 changes (AWS, Azure, GCP).
Shared VPC instance tags are not supported in GCP-based SmartGroups.
  • Log Export to Splunk HTTP Event Collector