Add specific applications
for the Security policy rule. If an application has multiple functions,
you can select the overall application or individual functions.
If you select the overall application, all functions are included
and the application definition is automatically updated as future functions
are added. If you are using application groups, filters, or
containers in the Security policy rule, you can view details of
these objects by hovering over the object in the Application column,
opening the drop-down, and selecting Value. This
allows you to view application members directly from the policy
without having to navigate to the Object tab.
Always specify one or more applications so
that only applications you want on your network are allowed, which
reduces the attack surface and gives you greater control over network
traffic. Don’t set the application to any,
which allows any application’s traffic and increases the attack
surface.
|