<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC: Does packet state impact Access Control Policy processing? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436795#M1082406</link>
    <description>&lt;P&gt;For our first rule in our Access Control Policy, we've got a geolocation block on incoming traffic from country X. There is no corresponding rule for outgoiong traffic to country X, however.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, as I understand it, anyone in country X trying to initiate a new connection to us would have the packet dropped. However, someone trying to initiate a connection&amp;nbsp;&lt;EM&gt;to&lt;/EM&gt; country X from inside our network would be allowed through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm not clear on is, in the latter case, would the response packet from country X, which would hit the firewall with state "ESTABLISHED" rather than "NEW," still get blocked by the geolocation rule?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jul 2021 16:32:08 GMT</pubDate>
    <dc:creator>00u1arh1c7Nbc5p2z5d7</dc:creator>
    <dc:date>2021-07-21T16:32:08Z</dc:date>
    <item>
      <title>FMC: Does packet state impact Access Control Policy processing?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436795#M1082406</link>
      <description>&lt;P&gt;For our first rule in our Access Control Policy, we've got a geolocation block on incoming traffic from country X. There is no corresponding rule for outgoiong traffic to country X, however.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, as I understand it, anyone in country X trying to initiate a new connection to us would have the packet dropped. However, someone trying to initiate a connection&amp;nbsp;&lt;EM&gt;to&lt;/EM&gt; country X from inside our network would be allowed through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm not clear on is, in the latter case, would the response packet from country X, which would hit the firewall with state "ESTABLISHED" rather than "NEW," still get blocked by the geolocation rule?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 16:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436795#M1082406</guid>
      <dc:creator>00u1arh1c7Nbc5p2z5d7</dc:creator>
      <dc:date>2021-07-21T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Does packet state impact Access Control Policy processing?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436806#M1082407</link>
      <description>&lt;P&gt;Since FW is statefull if the connection intiated from inside and allowed, the that should be ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if the intiation from outside should be blocked, your understanding correct ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see any issue, or is that just clarfication ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 16:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436806#M1082407</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-21T16:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Does packet state impact Access Control Policy processing?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436844#M1082409</link>
      <description>&lt;P&gt;Thanks, Balaji. I was just looking for clarification.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 17:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-does-packet-state-impact-access-control-policy-processing/m-p/4436844#M1082409</guid>
      <dc:creator>00u1arh1c7Nbc5p2z5d7</dc:creator>
      <dc:date>2021-07-21T17:54:32Z</dc:date>
    </item>
  </channel>
</rss>

