<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AMP | How to block malware in sourcefire in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364101#M4840</link>
    <description>&lt;P&gt;Hello, we have configured the Antimalware policy to block malware, but when we do a test of antimalware test download from the below site, it gives an option to save the file in internet explorer, the antimalware is not blocking. it should not give an option to save.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Mar 2019 01:47:16 GMT</pubDate>
    <dc:creator>edwincharles</dc:creator>
    <dc:date>2019-03-09T01:47:16Z</dc:date>
    <item>
      <title>AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364101#M4840</link>
      <description>&lt;P&gt;Hello, we have configured the Antimalware policy to block malware, but when we do a test of antimalware test download from the below site, it gives an option to save the file in internet explorer, the antimalware is not blocking. it should not give an option to save.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364101#M4840</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2019-03-09T01:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364120#M4842</link>
      <description>Hello Edwin&lt;BR /&gt;&lt;BR /&gt;How do you set the policy for the same ? Is it in audit mode or quarantine ? Also please provide the link where you have downloaded the same so that we can try to check  the same.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Jetsy</description>
      <pubDate>Wed, 11 Apr 2018 09:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364120#M4842</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-04-11T09:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364121#M4844</link>
      <description>&lt;P&gt;set the policy as block malware&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.eicar.org/85-0-Download.html" target="_blank"&gt;http://www.eicar.org/85-0-Download.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 09:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364121#M4844</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2018-04-11T09:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364680#M4846</link>
      <description>Hello Edwin&lt;BR /&gt;&lt;BR /&gt;Just to clarify are you referring to to the AMP endpoints or Network AMP here ?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Jetsy</description>
      <pubDate>Thu, 12 Apr 2018 06:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364680#M4846</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-04-12T06:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364681#M4849</link>
      <description>&lt;P&gt;Network AMP&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 06:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3364681#M4849</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2018-04-12T06:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366179#M4851</link>
      <description>&lt;P&gt;please find the attached config snaps from FMC for the malware block&lt;/P&gt;</description>
      <pubDate>Sun, 15 Apr 2018 09:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366179#M4851</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2018-04-15T09:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366610#M4854</link>
      <description>&lt;P&gt;Hi Edwin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The rule looks correct. I would suggest to check the connection events first to find which rule the traffic is hitting on the firepower.&lt;/P&gt;
&lt;P&gt;Check analysis&amp;gt;events&amp;gt;connections and table view of connections and search for your test client IP.&lt;/P&gt;
&lt;P&gt;See if it actually hits the AMPPOLICY rule or no.&lt;/P&gt;
&lt;P&gt;If it hits that, then please make sure you download the test malware using http connection and not https.&lt;/P&gt;
&lt;P&gt;https require SSL decryption. You can also create a test rule to block something (like URL or IP) to check if it actually works. If its ASA with SFR module, check if the module(service -policy)&amp;nbsp; is configured in inline mode or passive (monitor-only)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 09:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366610#M4854</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-16T09:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366692#M4856</link>
      <description>&lt;P&gt;the config is inline mode as below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;class-map sfr&lt;BR /&gt;&amp;nbsp;match access-list sfr_redirect&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;&amp;nbsp;class sfr&lt;BR /&gt;&amp;nbsp; sfr fail-open&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Apr 2018 12:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3366692#M4856</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2018-04-16T12:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367218#M4858</link>
      <description>&lt;P&gt;Config seems correct from ASA redirection point of view. Please check the firewall-engine-debug from CLI or connection events and find which rule the traffic hits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 08:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367218#M4858</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-17T08:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367255#M4860</link>
      <description>&lt;P&gt;The images shows that, the server antivirus kaspersky is blocking malware, but asa is not blocking&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 09:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367255#M4860</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2018-04-17T09:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: AMP | How to block malware in sourcefire</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367290#M4863</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I would suggest to open TAC case for further investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2018 11:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-how-to-block-malware-in-sourcefire/m-p/3367290#M4863</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-04-17T11:13:44Z</dc:date>
    </item>
  </channel>
</rss>

