<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about Security Intelligence in firepower. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403113#M1080788</link>
    <description>&lt;P&gt;DNS based Security Intelligence blocks attempts to resolve black listed names in DNS requests.&lt;BR /&gt;Does it also block DNS responses containing referalls to black listed names?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I try to resolve A (which is a white name).&lt;BR /&gt;The response does not contain an answer for A but rather&lt;BR /&gt;a referral to nameserver B (which is black listed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would the response be blocked by DNS based Security Intelligence?&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 14:12:46 GMT</pubDate>
    <dc:creator>FredrikW73</dc:creator>
    <dc:date>2021-05-14T14:12:46Z</dc:date>
    <item>
      <title>Question about Security Intelligence in firepower.</title>
      <link>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403113#M1080788</link>
      <description>&lt;P&gt;DNS based Security Intelligence blocks attempts to resolve black listed names in DNS requests.&lt;BR /&gt;Does it also block DNS responses containing referalls to black listed names?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I try to resolve A (which is a white name).&lt;BR /&gt;The response does not contain an answer for A but rather&lt;BR /&gt;a referral to nameserver B (which is black listed).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would the response be blocked by DNS based Security Intelligence?&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 14:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403113#M1080788</guid>
      <dc:creator>FredrikW73</dc:creator>
      <dc:date>2021-05-14T14:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Security Intelligence in firepower.</title>
      <link>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403260#M1080802</link>
      <description>&lt;P&gt;If I understand the scenario correctly, wouldn't the client then need to resolve the referral as well? Or if it was just to an IP address perhaps the IP address would be picked up in the SI address blacklist.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 18:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403260#M1080802</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-14T18:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Security Intelligence in firepower.</title>
      <link>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403983#M1080826</link>
      <description>&lt;P&gt;The scenario is this, the client looks up a white name via a resolver.&lt;/P&gt;&lt;P&gt;The resolver get a referral back, without any IP-adresses, but containing a name of a black listed name server.&lt;/P&gt;&lt;P&gt;Will the referral be blocked so that the resolver never gets to know black listed name?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that if the resolver gets the referall then it will perform a look up for the black listed name and that would be blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thing is, our internal DNS act as a resolver for our clients. We see that our internal DNS makes lookups for black listed names,&lt;/P&gt;&lt;P&gt;but no client have tried to lookup the names. My theory is that referrals trigger these lookups from the internal DNS.&lt;/P&gt;&lt;P&gt;That would not work though if referrals for black listen names where blocked by security intelligence.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 11:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-security-intelligence-in-firepower/m-p/4403983#M1080826</guid>
      <dc:creator>FredrikW73</dc:creator>
      <dc:date>2021-05-17T11:24:50Z</dc:date>
    </item>
  </channel>
</rss>

