Cloud Access Security Inspection (CASI)

The Cloud Access Security Inspection (CASI) feature is now merged with Application Control resulting in changes to the GUI and the CLI.

GUI Changes

  • Toggle option added to quickly filter CASI signatures in the Application Signatures list.
  • Application Overrides table now shows any parent-child hierarchy using the --parent metadata on signatures. Deleting a parent app also deletes its child apps. And conversely, adding a child app will add all its parent apps but with implicit filter action.
  • A policy breakdown is shown on existing application control profiles for policies using the profile. The breakdown indicates which policies are using a deep inspection.
  • A breakdown is shown for application categories and filter overrides to indicate the number of CASI and non-CASI signatures. A lock icon is shown for applications requiring deep inspection.

CLI Changes

Commands removed:

  • config application casi profile
  • casi profile in config firewall policy
  • casi profile in config firewall policy6
  • casi-profile-status and casi-profile under config firewall sniffer
  • casi-profile-status and casi-profile under config firewall interface-policy