Okay...maybe it doesn't do EVERYTHING the ASA does...but it's definitely a step forward in the Firewall Feature Set of the IOS. Routers running this version of code now support zone-based policies, which really helps with multi-interface restrictions (rather than just one outside & one inside interface with individual access list applications). Likewise, it now supports application inspection to catch those scandalous peer-to-peer programs.
Check out the whole scoop here.
Much thanks to Joshua Walton for sending me an email on this and slightly brightening the most dismal CiscoWorks installation day I've ever had. Oh look - CD #12 is done...on to 13. |