<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking hash on cisco FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3928641#M1004343</link>
    <description>&lt;P&gt;What does one do if the opposite needs to happen ? What if FirePower with AMP for files is blocking a file it shouldn't be ? We have the SHA256 hash that being blocked, its not malware, we know what the file is and what its behavior is. What needs to be done to, lay person's terms, " if Firepower detects a specific SHA256 file on the network, do nothing."&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2019 14:43:31 GMT</pubDate>
    <dc:creator>PatrickNicholls4606</dc:creator>
    <dc:date>2019-09-23T14:43:31Z</dc:date>
    <item>
      <title>Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705305#M1004205</link>
      <description>&lt;P&gt;Hello Experts -&lt;/P&gt;
&lt;P&gt;I need to know that we are using cisco ASA 5512 with firepower defense center. We have URL and malware license. I want to block the hashes like given below. Can anyone of you help me out in configuring this. looking forward for your positive response in this regards.&lt;/P&gt;
&lt;TABLE width="867"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="867"&gt;c48f5f5bghd34939c9e6cc1eff86db882f3e57d8e&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705305#M1004205</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2020-02-21T16:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705322#M1004206</link>
      <description>&lt;P&gt;You can do this by using a file list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/reusable_objects.html#ID-2243-00000833" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/reusable_objects.html#ID-2243-00000833&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The hash you provided though is only 43 characters. We need to provide a 64 character SHA-256 hash.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File List.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18507iFD68B35A02A0087E/image-size/large?v=v2&amp;amp;px=999" role="button" title="File List.PNG" alt="File List.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 06:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705322#M1004206</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-12T06:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705358#M1004207</link>
      <description>&lt;P&gt;Thank you that's exactly what I am looking for. Can you please tell me that I have three types of hashes i.e. MD5, SHA1, and SHA256, Can I add all of them and I cannot copy paste any SHA one by one I have a huge list of hashes can I add them as a text file (.txt) like we do in security intelligence.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 07:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705358#M1004207</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-12T07:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705363#M1004208</link>
      <description>&lt;P&gt;Firepower Management Center (and AMP console for that matter) only supports SHA-256 hashes. There's no way to import MD5 and SHA-1 hashes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can import a SHA-256 hash list in bulk. Please refer to the link I posted earlier - that page has detailed instructions on doing so by importing a csv file with up to 10,000 entries.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 08:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705363#M1004208</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-12T08:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705391#M1004209</link>
      <description>&lt;P&gt;Thank you so much. I appreciate your help.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 09:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705391#M1004209</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-12T09:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705407#M1004210</link>
      <description>&lt;P&gt;Dear Rhoads -&lt;/P&gt;
&lt;P&gt;Please also let me know that I have added the File list as per you guided. My question is do I need to do something else to start monitoring the hash like need to apply this created file list in some access policy or somewhere or is it enough just to create File List? If I need to do something else. Please let me know that steps/configuration. Waiting for your answer.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 09:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705407#M1004210</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-12T09:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705414#M1004211</link>
      <description>&lt;P&gt;Please read the note that is in the screenshot I provided earlier. It tells you what is required for the list to take effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitoring is via the widgets in the Files dashboard or also under Analysis &amp;gt; Files &amp;gt; Malware events (for detailed monitoring and analysis).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 10:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705414#M1004211</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-12T10:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705420#M1004212</link>
      <description>&lt;P&gt;I did with malware cloud lookup but at right top I am getting this note "no access control policies use this file policy". when I click on it, it shows the attached note and redirected me to access policy control page but I am confuse how to add it on access control policy. Please have a look of two attachments.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 10:40:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705420#M1004212</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-12T10:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705528#M1004213</link>
      <description>&lt;P&gt;Most policies are "underneath" your top level access control policy (ACP). You create an ACP and in it specify the Intrusion, File &amp;amp; Malware, DNS, Identity, SSL and Prefilter policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each rule in your ACP has the option, under the Inspection tab, to specify a File Policy. As you can see in my screenshot below we call out the File policy created earlier and associate it with the rule. File inspection is computationally "expensive" so we don't always turn it on for every single rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File policy callout.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18529i938A903951AC86EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="File policy callout.PNG" alt="File policy callout.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 12:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3705528#M1004213</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-12T12:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3706089#M1004214</link>
      <description>&lt;P&gt;Thank you for your quick help. I really appreciate it.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 09:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3706089#M1004214</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-13T09:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713230#M1004215</link>
      <description>&lt;P&gt;Hello Marvin -&lt;/P&gt;
&lt;P&gt;Just one more thing that how many entries can we add in security intelligence on list to block ip's and URL's.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 03:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713230#M1004215</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-26T03:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713231#M1004216</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRIKE&gt;I believe the limit is currently 10,000 each.&lt;/STRIKE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT - see my later reply.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 06:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713231#M1004216</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-26T06:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713234#M1004333</link>
      <description>&lt;P&gt;Thank you, I am adding IP's and URL in one list and this list has limit of 10,000 entries. Can you confirm this?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 04:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713234#M1004333</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-26T04:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713266#M1004334</link>
      <description>&lt;P&gt;Sorry - the 10,000 number is the limit for a file list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;URL and IP lists are limited to 500 MB per list. You can add them as separate lists.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The number of entries you can include is limited by the maximum size of the file. For example, a URL list with no comments and an average URL length of 100 characters (including Punycode or percent Unicode representations and newlines) can contain more than 5.24 million entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is all spelled out in the Configuration Guide. The above paragraph is a direct quote.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 06:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713266#M1004334</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-26T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713360#M1004335</link>
      <description>&lt;P&gt;Marvin this is very kind of you for being so helpful. If I add total of both URL and IP's 40,000 entries in single txt. file and if txt. file size does not reach to 500 MB then I am allowed to add more in the same list. Please correct me if I am wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 09:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713360#M1004335</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-26T09:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713362#M1004336</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's correct.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 09:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713362#M1004336</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-26T09:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713944#M1004337</link>
      <description>&lt;P&gt;Marvin I am facing a problem in FMC security intelligence that when I add list in txt. format which has URL in it. list got uploaded and after that when I download the list from SI to check, The URL will not appear in that list which was added earlier also it is not blocking when I add that list in blacklist mode. I am Using FMC software version: 5.4.1.6. Kindly suggest.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 05:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3713944#M1004337</guid>
      <dc:creator>Muhammad Amin Zia</dc:creator>
      <dc:date>2018-09-27T05:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3714013#M1004339</link>
      <description>&lt;P&gt;I'm not sure what might be wrong with your file. I've tested blacklist based on uploading a text file and it worked fine for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using the most recent Firepower versions but did this test as far back as 6.1. Is there a reason why you are running a VERY old version of Firepower? If you contact TAC they will almost undoubtedly ask that you upgrade to a current release and try it again.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 07:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3714013#M1004339</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-27T07:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3928641#M1004343</link>
      <description>&lt;P&gt;What does one do if the opposite needs to happen ? What if FirePower with AMP for files is blocking a file it shouldn't be ? We have the SHA256 hash that being blocked, its not malware, we know what the file is and what its behavior is. What needs to be done to, lay person's terms, " if Firepower detects a specific SHA256 file on the network, do nothing."&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3928641#M1004343</guid>
      <dc:creator>PatrickNicholls4606</dc:creator>
      <dc:date>2019-09-23T14:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking hash on cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3929082#M1004345</link>
      <description>&lt;P&gt;AMP for Networks (i.e. on FMC or Firepower device) does not allow you to create policies based on a specific file's SHA-256. That requires AMP for endpoints where it is done on the AMP console.&lt;/P&gt;
&lt;P&gt;The best you can do is open a ticket with TAC (or Talos - I find TAC more interactive and responsive) and request the incorrect SHA-256 be remedied in AMP cloud.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 04:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-hash-on-cisco-fmc/m-p/3929082#M1004345</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-24T04:07:30Z</dc:date>
    </item>
  </channel>
</rss>

