<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Module 6.4 - If I block traffic sourced by geolocation will it block returning traffic requested from inside the network? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184988#M1075903</link>
    <description>&lt;P&gt;Thank you. For now just want to block inbound but will eventually block outbound to prevent C2 to these locations so it sounds like just from source will work for now!&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2020 23:50:48 GMT</pubDate>
    <dc:creator>N3t-Guy</dc:creator>
    <dc:date>2020-11-17T23:50:48Z</dc:date>
    <item>
      <title>Firepower Module 6.4 - If I block traffic sourced by geolocation will it block returning traffic requested from inside the network?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184921#M1075899</link>
      <description>&lt;P&gt;Hello, I am wanting to set an access rule in my default policy that blocks traffic from certain geolocations. If I block traffic sourced by these geolocations to "any" will it drop web traffic initiated by my internal users? I know that returning traffic that is initiated from inside the network will normally be allowed but how will Firepower handle web traffic from my users destined to websites in these countries? Thank-you!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 21:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184921#M1075899</guid>
      <dc:creator>N3t-Guy</dc:creator>
      <dc:date>2020-11-17T21:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Module 6.4 - If I block traffic sourced by geolocation will it block returning traffic requested from inside the network?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184947#M1075901</link>
      <description>&lt;P&gt;A L3 access control is applied on the initial SYN packet of a brand new session; your return traffic is a SYN+ACK packet on an existing session, so no, the return traffic won't be dropped. For you to block, you need to place a restriction using these geolocations as "destination", which will match a SYN packet of a brand new session from your internal users.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 22:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184947#M1075901</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2020-11-17T22:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Module 6.4 - If I block traffic sourced by geolocation will it block returning traffic requested from inside the network?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184988#M1075903</link>
      <description>&lt;P&gt;Thank you. For now just want to block inbound but will eventually block outbound to prevent C2 to these locations so it sounds like just from source will work for now!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 23:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-module-6-4-if-i-block-traffic-sourced-by-geolocation/m-p/4184988#M1075903</guid>
      <dc:creator>N3t-Guy</dc:creator>
      <dc:date>2020-11-17T23:50:48Z</dc:date>
    </item>
  </channel>
</rss>

