<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deny internet access on our domain controller in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648700#M576105</link>
    <description>&lt;P&gt;Check below guide of configuration.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;make sure you are sending all traffic via FP module using ASA service policy&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2022 11:09:46 GMT</pubDate>
    <dc:creator>Kasun Bandara</dc:creator>
    <dc:date>2022-07-12T11:09:46Z</dc:date>
    <item>
      <title>deny internet access on our domain controller</title>
      <link>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648682#M576101</link>
      <description>&lt;P&gt;i have installed firepower on my ASA 5516 as SFR module,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am using ASDM to manage rules ,&lt;/P&gt;&lt;P&gt;any idea how to block internet access on my domain controller, and please note that this domain controller is the DNS server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried deny any any on DCs IP addresses than I allowed port 53 and didn't work .&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 10:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648682#M576101</guid>
      <dc:creator>VOLUS</dc:creator>
      <dc:date>2022-07-12T10:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: deny internet access on our domain controller</title>
      <link>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648684#M576102</link>
      <description>&lt;P&gt;Is this FW also facing Internet and you do NAT ?&lt;/P&gt;
&lt;P&gt;on your DC DNS Server, what DNS server external configured ?&lt;/P&gt;
&lt;P&gt;so your rule should allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source : your local DNS&lt;/P&gt;
&lt;P&gt;Destination : 8.8.8.8 4.4.4.4&lt;/P&gt;
&lt;P&gt;service 53 allow.&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/firewall/asa-914-firewall-config/access-umbrella.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/firewall/asa-914-firewall-config/access-umbrella.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 10:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648684#M576102</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-07-12T10:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: deny internet access on our domain controller</title>
      <link>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648687#M576103</link>
      <description>&lt;P&gt;hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please share the config from firepower and not ASA as i redirected all traffic to firepower&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 10:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648687#M576103</guid>
      <dc:creator>VOLUS</dc:creator>
      <dc:date>2022-07-12T10:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: deny internet access on our domain controller</title>
      <link>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648700#M576105</link>
      <description>&lt;P&gt;Check below guide of configuration.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;make sure you are sending all traffic via FP module using ASA service policy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 11:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/deny-internet-access-on-our-domain-controller/m-p/4648700#M576105</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-12T11:09:46Z</dc:date>
    </item>
  </channel>
</rss>

