<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD url blocked with notification &amp;quot;You are attempting to access a forbidden site.&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318269#M1079859</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Marvin is right, you’ll need to call TAC.&lt;/P&gt;
&lt;P&gt;However, if you want to run it or take a look at it, you can go on the folder&amp;nbsp;/ftd/app_bin/root/ngfw/var/sf/bin and run the script&amp;nbsp;url_cache_tool.pl&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to make sure the folder is the right now, once logged on your FTD using SSH, you will need to go into expert mode and then go into sudo su (use your admin password to enter sudo space).&lt;/P&gt;
&lt;P&gt;Then, you can run the command:&amp;nbsp;find / -name url_cache_tool.pl&lt;/P&gt;
&lt;P&gt;The output will show you the full path. You can just run it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let us know if that works&lt;/P&gt;</description>
    <pubDate>Sun, 04 Apr 2021 02:13:15 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2021-04-04T02:13:15Z</dc:date>
    <item>
      <title>FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4317876#M1079843</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using FTD on ASA 5506x v&lt;SPAN&gt;6.2.3.16-59&amp;nbsp;&lt;/SPAN&gt;(managed by&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;Firepower Device Management&lt;/STRONG&gt;) with updates:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1331.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108004i2C17013DE44535F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1331.png" alt="Screenshot_1331.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Two days ago I've reported to BrighCloud support that&amp;nbsp;&lt;A href="http://www.szachypolskie.pl/" target="_blank" rel="noopener"&gt;http://www.szachypolskie.pl/&lt;/A&gt;&amp;nbsp;should be categorize (it was under Uncatogorized category). I've got confirmation from them that&amp;nbsp; they have updated the site to the Sports categories. This change is now published in the BrightCloud Service and is available in &lt;STRONG&gt;Database version 7.704.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone help me to troubleshoot why this site is still blocked?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems to me that troubleshooting from Events section of&amp;nbsp;&lt;SPAN&gt;Firepower Device Management is VERY limited.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I couldn't find event related to this particular&amp;nbsp;issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do I really need FMC to manage properly my FTD? seriously ? for home deployment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm looking for you advice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Slawek&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 15:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4317876#M1079843</guid>
      <dc:creator>slv_slv</dc:creator>
      <dc:date>2021-04-02T15:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318072#M1079847</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Talos Intelligence, the site is categorized as sports and recreation, so it should go through.&lt;/P&gt;
&lt;P&gt;You should see the log under monitoring/event menu. Can you share the log of that traffic and also the rule you created please?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 02:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318072#M1079847</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2021-04-03T02:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318080#M1079848</link>
      <description>&lt;P&gt;Francesco Cisco only transitioned to Talos for Firepower 6.5 and later. The 6.2.3.16 used by the poster still uses Brightcloud.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 03:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318080#M1079848</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-03T03:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318081#M1079849</link>
      <description>&lt;P&gt;Yes you’re right and I didn’t noticed the version.&lt;/P&gt;
&lt;P&gt;Anyways, the category is fine on both cloud services. So the question to get the traffic event and rule configuration is still valid.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 03:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318081#M1079849</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2021-04-03T03:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318132#M1079855</link>
      <description>&lt;P&gt;Hi Francesco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that my FTD is still using outdated BrighCloud database version. Under events we can see:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_59.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108072i7246D0FE2AB26E53/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_59.jpg" alt="Screenshot_59.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;so URL filtering rule was hit - that's good. Why&amp;nbsp; still there is wrong category? Why there is no geolocation detected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My rule set looks like:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_60.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108073iA34E341F94E72D00/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_60.jpg" alt="Screenshot_60.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_61.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108074iD0EDDB0CA61C0A06/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_61.jpg" alt="Screenshot_61.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know if I should modify my rule set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once when I enabled Security inteligence with balanced security it blocked dns traffic at all. No idea why. Any idea what was wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward for your advcies&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 09:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318132#M1079855</guid>
      <dc:creator>slv_slv</dc:creator>
      <dc:date>2021-04-03T09:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318181#M1079856</link>
      <description>&lt;P&gt;Well geolocation and originator country didn't get populated because the traffic came from your inside network RFC 1918 address (192.168.0.0/16).&lt;/P&gt;
&lt;P&gt;I can only think that Firepower is caching the previous disposition despite Brightcloud having updated the cloud side database. I found a bugID that appears to describe this behavior exactly:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuw57184/?rfs=iqvred" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuw57184/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you have support, Cisco TAC can run a script to clear the cache.&lt;/P&gt;
&lt;P&gt;As a workaround you could add a higher level rule specifically allowing that URL - thus avoiding the Block rule lower down.&lt;/P&gt;
&lt;P&gt;Newer versions of FDM have a place where we can modify the cache settings:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FDM URL Filterng Preferences" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108078i4764667F938F3BC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="FDM URL Filtering Preferences.PNG" alt="FDM URL Filterng Preferences" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;FDM URL Filterng Preferences&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 14:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318181#M1079856</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-03T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318269#M1079859</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Marvin is right, you’ll need to call TAC.&lt;/P&gt;
&lt;P&gt;However, if you want to run it or take a look at it, you can go on the folder&amp;nbsp;/ftd/app_bin/root/ngfw/var/sf/bin and run the script&amp;nbsp;url_cache_tool.pl&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to make sure the folder is the right now, once logged on your FTD using SSH, you will need to go into expert mode and then go into sudo su (use your admin password to enter sudo space).&lt;/P&gt;
&lt;P&gt;Then, you can run the command:&amp;nbsp;find / -name url_cache_tool.pl&lt;/P&gt;
&lt;P&gt;The output will show you the full path. You can just run it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let us know if that works&lt;/P&gt;</description>
      <pubDate>Sun, 04 Apr 2021 02:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318269#M1079859</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2021-04-04T02:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318603#M1079865</link>
      <description>&lt;P&gt;Hi Francesco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've used the script url_cache_tool.pl but after I got some issues:&lt;/P&gt;&lt;P&gt;1. after 10 min since I run it I was unable to open any web page via Browser (while I was able to ping host name_&lt;/P&gt;&lt;P&gt;2. I did reboot of my FTD, same resoults.&lt;/P&gt;&lt;P&gt;3. I disabled my "URL filtering" rule (I change BLOCK to Trust mode) and do commit&lt;/P&gt;&lt;P&gt;this workaroud "fix" the issue temporarly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decdided to restore back my config to understand what has happened.&lt;/P&gt;&lt;P&gt;I revert back "URL filtering" to BLOCK and check settings for Uncategorized websites to:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_63.jpg" style="width: 535px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108129i9DBD97889F4631AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_63.jpg" alt="Screenshot_63.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once I did commit again most of websites where inaccesible, ie:&lt;/P&gt;&lt;P&gt;&lt;A href="https://speed.cloudflare.com/" target="_blank"&gt;https://speed.cloudflare.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_64.jpg" style="width: 848px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108130i1AD6DA45A5AA63D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_64.jpg" alt="Screenshot_64.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and from device logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_62.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108131iE29D2EF0A095FD8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_62.jpg" alt="Screenshot_62.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so its seems that I still have issues with URL filtering (Brightcloud cache).&lt;/P&gt;&lt;P&gt;Is there anything else what I can check on my device? - I can't engage TAC &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; here&lt;/P&gt;&lt;P&gt;Why its not pooling correct url category from Bright cloud service?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My intention is to block url uncategorized with reputation set to Suspicious site or High - how to achieve it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there other functions on FTD which I can use to get such url blocked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 10:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4318603#M1079865</guid>
      <dc:creator>slv_slv</dc:creator>
      <dc:date>2021-04-05T10:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4319439#M1079892</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I ask you to review my last update?&lt;/P&gt;&lt;P&gt;I stil can't use url filtering with blocking enabled for Uncategorized web-paged - why ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regrds&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 17:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4319439#M1079892</guid>
      <dc:creator>slv_slv</dc:creator>
      <dc:date>2021-04-06T17:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: FTD url blocked with notification "You are attempting to access a forbidden site."</title>
      <link>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4319469#M1079893</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've decided to create dedicated rule for Uncategorised URL's (rule number 4)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_70.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108245i76E2A4E54069190D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_70.jpg" alt="Screenshot_70.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and now in logs, traffic to &lt;A href="https://speed.cloudflare.com/&amp;nbsp;" target="_blank" rel="noopener"&gt;https://speed.cloudflare.com/&amp;nbsp;&lt;/A&gt; hit rule "IN to OUT" (rule number 6)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_69.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/108246iE6FF1478BC8E46B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_69.jpg" alt="Screenshot_69.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats good for me, but I'm still looking&amp;nbsp; for explanation why it was blocked previously.&lt;/P&gt;&lt;P&gt;Anyway, I will keep my eyes open on this problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 18:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-url-blocked-with-notification-quot-you-are-attempting-to/m-p/4319469#M1079893</guid>
      <dc:creator>slv_slv</dc:creator>
      <dc:date>2021-04-06T18:16:41Z</dc:date>
    </item>
  </channel>
</rss>

