<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable remote access traffic? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173788#M1075204</link>
    <description>&lt;P&gt;Thanks Marvin for your great solution. I did so but it does not take effect! Users can still use Anydesk, for example. I saved the rules as well.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firepower.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86932i000C01CEB2E0713A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="firepower.png" alt="firepower.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2020 16:20:03 GMT</pubDate>
    <dc:creator>majid3612</dc:creator>
    <dc:date>2020-10-26T16:20:03Z</dc:date>
    <item>
      <title>How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172720#M1075099</link>
      <description>&lt;P&gt;I am going to disable remote access traffic across my network except my whitelist. I am using Cisco Firepower as well as Cisco ASA in my network perimeter. How and where should I put my rule/policy to enable this capability?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 17:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172720#M1075099</guid>
      <dc:creator>majid3612</dc:creator>
      <dc:date>2020-10-23T17:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172741#M1075103</link>
      <description>&lt;P&gt;Can you elaborate more with an example and post what configuration you have, and give some external IP you like to block and allow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 17:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172741#M1075103</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-10-23T17:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172807#M1075107</link>
      <description>&lt;P&gt;For example, I want to permit remote traffic by RDP and Teamviewer but not other tools (Anydesk, VNC, etc.). Also, any backdoor which establish a remote connection between internal and external networks.&lt;/P&gt;&lt;P&gt;As mentioned, we have deployed ASA, Firepower, Umbrella and Meraki.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 21:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4172807#M1075107</guid>
      <dc:creator>majid3612</dc:creator>
      <dc:date>2020-10-23T21:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173091#M1075120</link>
      <description>&lt;P&gt;You should use the policy in the Firepower service module to block the applications via an application level policy. Two rules will be needed:&lt;/P&gt;
&lt;P&gt;1. First allow RDP and TeamViewer&lt;/P&gt;
&lt;P&gt;2. Second block all other applications in the "Remote Desktop Control" category.&lt;/P&gt;
&lt;P&gt;It should look something like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Example Policy" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86839iFCE0DEFB77B204BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC example - Block remote control.PNG" alt="Example Policy" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Example Policy&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2020 04:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173091#M1075120</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-10-25T04:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173788#M1075204</link>
      <description>&lt;P&gt;Thanks Marvin for your great solution. I did so but it does not take effect! Users can still use Anydesk, for example. I saved the rules as well.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firepower.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86932i000C01CEB2E0713A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="firepower.png" alt="firepower.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 16:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173788#M1075204</guid>
      <dc:creator>majid3612</dc:creator>
      <dc:date>2020-10-26T16:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173846#M1075209</link>
      <description>&lt;P&gt;It could be that those apps are using SSL and if FTD isn't decrypting it might not recognize the inner contents of the encrypted session as the app. In that case you might need to fall back on something like URL filter (if you have that licensed) or DNS security (e.g. via Umbrella) to prevent the clients from ever even resolving the address of the service to connect.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 17:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173846#M1075209</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-10-26T17:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173870#M1075211</link>
      <description>&lt;P&gt;Also, please note that the block might not happen straightaway, the Firepower might allow some packets to pass through before it can learn the application and apply the policy accordingly.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 17:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4173870#M1075211</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-26T17:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable remote access traffic?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4174480#M1075241</link>
      <description>&lt;P&gt;Could you please be more specific about how to do so through URL filtering as well as DNS Security (Umbrella)? I looked at the both but not sure if that's exactly what I want. For example, you can block specific apps or URLs whereas I want to block a category of apps (remote access tools) which is not in their list.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 16:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-remote-access-traffic/m-p/4174480#M1075241</guid>
      <dc:creator>majid3612</dc:creator>
      <dc:date>2020-10-27T16:59:26Z</dc:date>
    </item>
  </channel>
</rss>

