<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firepower File Policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777746#M1039722</link>
    <description />
    <pubDate>Fri, 11 Jan 2019 13:39:30 GMT</pubDate>
    <dc:creator>ccna_security</dc:creator>
    <dc:date>2019-01-11T13:39:30Z</dc:date>
    <item>
      <title>Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776716#M1039682</link>
      <description>&lt;P&gt;Hi. I have just configured firepower file policy that is responsible for just detecting any file and block only encrypted archives when they pass through firepower.But when i send encrypted archive from one vlan to others it is either send or blocked that make the host get stuck for a while. Please see added screenshot that depicts my configuration. Please help me to resolve this problem.Moreover when the host freezes and needs restart, the blocked archives seen on logs.As if it is normally blocked.Please tell me where did i make mistake in the configuration. Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 11:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776716#M1039682</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-03-12T11:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776722#M1039691</link>
      <description>&lt;P&gt;in diagram 1.PNG you have not select any file. all are uncheck. also you need to understand the flow of packet in Firewpower.&lt;/P&gt;&lt;P&gt;you doing decryption on the box too? please the the diagram it will help you to build your rule according to packet flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="packet_flow.PNG" style="width: 632px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27484i261A63DF697DD630/image-size/large?v=v2&amp;amp;px=999" role="button" title="packet_flow.PNG" alt="packet_flow.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 09:40:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776722#M1039691</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-10T09:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776767#M1039698</link>
      <description>&lt;P&gt;thanks for your prompt reply. In diagram 1.png i have selected all files. When i select one by one po the left side it adds all category (all file type)to the Selected file categories and Types. then check box on the left side get back to the default condition (unchecked)I hope i could make it clear to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I havent created decryption policy yet (SSL policyis none). So decrypting wont work. do you thing that encrypted files must pass through ssl plicy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 09:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776767#M1039698</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-10T09:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776790#M1039702</link>
      <description>&lt;P&gt;check this link its explain in detail how file policy works&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Access_Control_Using_Intrusion_and_File_Policies.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Access_Control_Using_Intrusion_and_File_Policies.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Reference_a_wrapper_Chapter_topic_here.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 10:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776790#M1039702</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-10T10:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776833#M1039704</link>
      <description>&lt;P&gt;thanks for the link you sent. One more thing i want to mention. The encrypted file that is sent is rar,zip archive file. i read all materials you send but it only teaches how to configure file policy. It also say that if you want to block encrypted archive in the network check "Block Encrypted Archives" box. So again it wont block archive or blocks it&amp;nbsp; but make host get freezed.&lt;/P&gt;&lt;P&gt;Usually This problem occurs when users attemtp to take password protected rar,zip archive file from file server to their computers. then aforementioned problem occurs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please send me solution&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776833#M1039704</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-10T12:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776858#M1039707</link>
      <description>&lt;P&gt;could you please confirm that your File Policy is married to the ACP policy? Is the source and destination IP are in same subnet or in different subnet?&lt;/P&gt;&lt;P&gt;how about your default ACP rule is?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776858#M1039707</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-10T13:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776864#M1039711</link>
      <description>&lt;P&gt;Well, i created file policy that was shown on previous conversation. then i applied that file policy to access rule show on attachement.Furthermore file server is in different subnet than my host computer.&amp;nbsp; i mean both of them are not in the same subnet.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776864#M1039711</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-10T13:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776885#M1039713</link>
      <description>&lt;P&gt;just read in cisco documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Detect Files: This action detects a file trasfer and logs it as a file event without interruption the file transfer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tip: if you want to block a file, seclet the Rest Connecton option. it allows an application session to close before the connection time out by itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having said that, create your rule like this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="File_policy.PNG" style="width: 980px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27496i8549B66863AC1ABB/image-size/large?v=v2&amp;amp;px=999" role="button" title="File_policy.PNG" alt="File_policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776885#M1039713</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-10T13:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776913#M1039715</link>
      <description>&lt;P&gt;thanks so much for your help. i am about to solve the problem using your tips. i will try as u said. if any problem occurs i will turn u back . thank you&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3776913#M1039715</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-10T14:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777220#M1039717</link>
      <description>&lt;P&gt;did you mange to solve the issue?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 20:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777220#M1039717</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-10T20:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777512#M1039719</link>
      <description>&lt;P&gt;Hi. Unfortunately failed again. Lets explain what kind of task i am given exactly. I need to create a file policy that&amp;nbsp; blocks malware for all types of files (included unencrypted archives). Actually it is easy enough. But the hard part of this task is to block only encrypted archives. If possible could you please create such policy on your firepower and send me screenshot?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 07:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777512#M1039719</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-11T07:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777636#M1039720</link>
      <description>&lt;P&gt;Hi took me a long to read the documentation &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In order for you to block the encrypted archievs you need a Dynamic Analysis check you will find this under Malware Cloud/Block malware. which make sense as the encrypted traffic sha256 will sent to cisco cloud to check the if the file is legitimate. on the other part you can not only block the encrypted files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have attach some attachment for your reference.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27583i178081219B2F93C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.PNG" alt="3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27584i450452E02A433B39/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.2.PNG" alt="3.2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27585i32A06CC865C9F927/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.3.PNG" alt="3.3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.4.PNG" style="width: 947px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27586i9E18C7472F1AC1E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.4.PNG" alt="3.4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.5.PNG" style="width: 588px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27587iF7850E899055A7E2/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.5.PNG" alt="3.5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 10:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777636#M1039720</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-11T10:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777745#M1039721</link>
      <description>&lt;P&gt;first of all i want to say that i really appreciate your assistement.Thanks so much.&lt;/P&gt;&lt;P&gt;I tried again but faild as usual:) please see the attachment i posted. Block Malware function for all type of files wont block password protected archive&amp;nbsp;that has malware inside it. i have read several documentation about file policy but couldnt find any solution. When i send that archive file over different network it passes without inspecting or blocking.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am beginner in this field that is why&amp;nbsp; i have difficulty to solve the issue. I guess i have configured correctly but not sure that what makes the password protected archive file pass.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 13:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777745#M1039721</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-11T13:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower File Policy</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777746#M1039722</link>
      <description />
      <pubDate>Fri, 11 Jan 2019 13:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-file-policy/m-p/3777746#M1039722</guid>
      <dc:creator>ccna_security</dc:creator>
      <dc:date>2019-01-11T13:39:30Z</dc:date>
    </item>
  </channel>
</rss>

