<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower GeoBlocking Not Working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177011#M1075365</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;If you are using GEO blocking, then you should see 'IP Block' instead of&lt;BR /&gt;Malware signature. It seems that your GEO is not working. When you see that&lt;BR /&gt;it originated from China was this location identified by FMC in the event&lt;BR /&gt;log or another method.&lt;BR /&gt;&lt;BR /&gt;Do you have a scheduled task to update Geo-DB in FMC and are these updates&lt;BR /&gt;installed successfully. You should be able to see this from the FMC tasks.&lt;BR /&gt;Also, can you confirm that Geo-DB is updated successfully on FTD.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Sun, 01 Nov 2020 16:07:45 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2020-11-01T16:07:45Z</dc:date>
    <item>
      <title>Firepower GeoBlocking Not Working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4176989#M1075363</link>
      <description>&lt;P&gt;I have China geo-blocked, both as a source and destination (separate rules of course), yet still see Intrusion Event blocks for traffic originating in China.&amp;nbsp; Is this working as designed?&amp;nbsp; The intrusion event based block is based on a malware signature being matched, so is it possible traffic hits this filter first, but otherwise would would get blocked via the geo-block policy?&amp;nbsp; Just want to be sure this is working/configured properly and hoping I'm just not clear on the order of operations, so to speak.&amp;nbsp; Thx,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 14:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4176989#M1075363</guid>
      <dc:creator>gpowlin</dc:creator>
      <dc:date>2020-11-01T14:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower GeoBlocking Not Working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177011#M1075365</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;If you are using GEO blocking, then you should see 'IP Block' instead of&lt;BR /&gt;Malware signature. It seems that your GEO is not working. When you see that&lt;BR /&gt;it originated from China was this location identified by FMC in the event&lt;BR /&gt;log or another method.&lt;BR /&gt;&lt;BR /&gt;Do you have a scheduled task to update Geo-DB in FMC and are these updates&lt;BR /&gt;installed successfully. You should be able to see this from the FMC tasks.&lt;BR /&gt;Also, can you confirm that Geo-DB is updated successfully on FTD.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sun, 01 Nov 2020 16:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177011#M1075365</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-01T16:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower GeoBlocking Not Working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177018#M1075368</link>
      <description>&lt;P&gt;Mohammed, thanks for the response!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried a more refined search (which I should have done in the first place) and can see blacklist, IPS, and I think geo based blocks for China.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For "Reason" I see "IP Block" associated with addresses included in my Global-Blacklist, then &amp;lt;blank&amp;gt; for events that look to be geo-blocked, and then "Intrusion Block" for those events IPS (signature-based) blocked.&amp;nbsp; And, I am getting the source location of "China" from the event log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have a scheduled task to update the Geo-DB, so that looks to be good and it is current.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, maybe it all is working, and I just wasn't filtering properly.&amp;nbsp; Do you know if the IPS is triggered before geo-blocking?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 16:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177018#M1075368</guid>
      <dc:creator>gpowlin</dc:creator>
      <dc:date>2020-11-01T16:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower GeoBlocking Not Working</title>
      <link>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177030#M1075369</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes I agree it seems to be working. By default IPS isn't done before identifying traffic unless you have the option "&lt;SPAN&gt;Intrusion Policy used before Access Control rule is determined&lt;/SPAN&gt;" is set. In this case, IPS is done before ACP. This can be checked&amp;nbsp;&lt;SPAN&gt;In the access control policy editor, click&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Advanced&lt;/SPAN&gt;&lt;SPAN&gt;, then click edit&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;next to the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="ph b"&gt;Network Analysis&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="ph b"&gt;Intrusion Policies&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;section.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;**** please remember to rate useful posts&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 17:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-geoblocking-not-working/m-p/4177030#M1075369</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-01T17:28:09Z</dc:date>
    </item>
  </channel>
</rss>

