Strict Default Ports for Decrypted Applications,
Including Web-Browsing | Application default—which enables you to
allow applications only on their most commonly-used ports—now enforces
standard port usage for certain applications that use a different
default port when encrypted: web-browsing, SMTP, FTP, LDAP, IMAP
and POP3. This means that, if you’re decrypting SSL traffic,
a security policy that allows web-browsing on the application default
ports now strictly enforces web-browsing on port 80 and SSL-tunneled web-browsing
on port 443. To enhance security, if you currently have a
security policy rule configured to allow web-browsing on service-HTTP and service-HTTPS,
you might consider updating the rule to instead allow web-browsing
on the application-default ports:
|