<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Firepower getting ignored in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165024#M1074623</link>
    <description>&lt;P&gt;&lt;U&gt;Update:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Apparently this is a problem with some objects suddenly missing from the main network objects group.&lt;/P&gt;&lt;P&gt;This is fixable, so it was not a serious issue.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2020 09:25:36 GMT</pubDate>
    <dc:creator>Infuscomus</dc:creator>
    <dc:date>2020-10-12T09:25:36Z</dc:date>
    <item>
      <title>ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165010#M1074616</link>
      <description>&lt;P&gt;After receiving some user reports, apparently all Firepower rules are getting ignored in my ASA-5508X.&lt;/P&gt;&lt;P&gt;I was unable to find what is wrong.&lt;/P&gt;&lt;P&gt;Nothing related to Firepower was recently modified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The SFR policy is the same and enabled. It matches all LAN segments towards any IP.&lt;/P&gt;&lt;P&gt;But Access Control Policy seems to be completely ignored/bypassed.&lt;/P&gt;&lt;P&gt;Using the packet tracer shows that any IP that suppose to be blocked in the ACP goes through without any problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I properly identify the problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 08:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165010#M1074616</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2020-10-12T08:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165021#M1074620</link>
      <description>&lt;P&gt;Well, packet tracer will only provide the result of the ASA verdict of the traffic and does not include what Firepower will do to the traffic.&amp;nbsp; If you jump to the Firepower CLI and issue the command &lt;STRONG&gt;system support diagnostic-cli&lt;/STRONG&gt;, enter the client IP and leave everything else blank, and then run a test.&amp;nbsp; What rule are you hitting.&amp;nbsp; If you se no traffic at all, then traffic is not being redirected to Firepower.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165021#M1074620</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-10-12T09:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165024#M1074623</link>
      <description>&lt;P&gt;&lt;U&gt;Update:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Apparently this is a problem with some objects suddenly missing from the main network objects group.&lt;/P&gt;&lt;P&gt;This is fixable, so it was not a serious issue.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165024#M1074623</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2020-10-12T09:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165027#M1074624</link>
      <description>&lt;P&gt;I think Marius meant to say&amp;nbsp;&lt;STRONG&gt;system support firewall-engine-debug&lt;/STRONG&gt; command to capture the traffic subnet to the ACP. Check if snort is engine is running, if not, try to restart it with the command &lt;STRONG&gt;pmtool restartbytype snort&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:33:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165027#M1074624</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-12T09:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165033#M1074626</link>
      <description>&lt;P&gt;D'OH!&amp;nbsp; Correct Aref, I meant firewall-engine-debug.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165033#M1074626</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-10-12T09:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165035#M1074627</link>
      <description>&lt;P&gt;Objects that suddenly go missing should not happen.&amp;nbsp; If this continues, I suggest opening a TAC case as this sounds a lot like a bug.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 09:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165035#M1074627</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-10-12T09:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165084#M1074639</link>
      <description>&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;The last serious problem I encountered was licenses suddenly not correctly detected witch of course caused lack of certain licensed functionality.&lt;/P&gt;&lt;P&gt;I will follow closely to see if similar anomalies occur.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 11:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165084#M1074639</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2020-10-12T11:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165179#M1074643</link>
      <description>&lt;P&gt;What version of ASA/SFR are you running?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 13:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165179#M1074643</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-12T13:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firepower getting ignored</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165803#M1074684</link>
      <description>&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.8(2)&lt;BR /&gt;Firepower Extensible Operating System Version 2.2(2.52)&lt;BR /&gt;Device Manager Version 7.13(1)&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 10:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-getting-ignored/m-p/4165803#M1074684</guid>
      <dc:creator>Infuscomus</dc:creator>
      <dc:date>2020-10-13T10:24:46Z</dc:date>
    </item>
  </channel>
</rss>

