<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Proxy exceptions on FMC Version 6.0 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459518#M1083318</link>
    <description>&lt;P&gt;I am using version on 6.0 on a physical 1600 FMC, we have configured a proxy in order to download updates from FMC and things like this. In house we also have the Smart Software Manager Satellite for licenses.&lt;/P&gt;&lt;P&gt;From FMC we are able to download updates but we can't reach the Satellite from the FMC after pasting the token generated from Satellite, my worry is that exceptions have to be configured on FMC but it has no options for that, looks like a limitation.&lt;/P&gt;&lt;P&gt;Does anyone know if exceptions can be configured, if they are needed at all, or any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Davide&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 15:23:13 GMT</pubDate>
    <dc:creator>DavideRanalli97851</dc:creator>
    <dc:date>2021-09-03T15:23:13Z</dc:date>
    <item>
      <title>Proxy exceptions on FMC Version 6.0</title>
      <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459518#M1083318</link>
      <description>&lt;P&gt;I am using version on 6.0 on a physical 1600 FMC, we have configured a proxy in order to download updates from FMC and things like this. In house we also have the Smart Software Manager Satellite for licenses.&lt;/P&gt;&lt;P&gt;From FMC we are able to download updates but we can't reach the Satellite from the FMC after pasting the token generated from Satellite, my worry is that exceptions have to be configured on FMC but it has no options for that, looks like a limitation.&lt;/P&gt;&lt;P&gt;Does anyone know if exceptions can be configured, if they are needed at all, or any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Davide&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 15:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459518#M1083318</guid>
      <dc:creator>DavideRanalli97851</dc:creator>
      <dc:date>2021-09-03T15:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy exceptions on FMC Version 6.0</title>
      <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459781#M1083328</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1173409"&gt;@DavideRanalli97851&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unfortunatelly, there is no possibility to configure exceptions list, while using proxy on Firepower. There is an enhancement request filed as &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva74145/?rfs=iqvred" target="_self"&gt;CSCva74145&lt;/A&gt;, which is still open.&lt;/P&gt;&lt;P&gt;What stops you of permitting Satelite communication over proxy? If you are using TLS, just create TLS decryption exception (otherwise you would need to think of a way FMC trusts your TLS-decryption certificate). You could also try communicating over plain HTTP.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 05:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459781#M1083328</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-04T05:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy exceptions on FMC Version 6.0</title>
      <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459796#M1083331</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;No, you can't configure proxy exceptions on FMC. These have to be&lt;BR /&gt;configured on proxy to bypass FMC traffic when going to SSM.&lt;BR /&gt;&lt;BR /&gt;Also, try to move from 6.0. It's very outdated.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sat, 04 Sep 2021 07:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459796#M1083331</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-09-04T07:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy exceptions on FMC Version 6.0</title>
      <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459844#M1083334</link>
      <description>&lt;P&gt;Hi Milos,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the ideas, i tried configuring a "Do not decrypt" policy clicking on SSL tab under the Access Control tab, but still not able to reach the Satellite, why would a&amp;nbsp;&lt;SPAN&gt;TLS decryption exception policy need to be configured?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Satellite and FMC both refer to the same pki we have in house.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Davide&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 12:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459844#M1083334</guid>
      <dc:creator>DavideRanalli97851</dc:creator>
      <dc:date>2021-09-04T12:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy exceptions on FMC Version 6.0</title>
      <link>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459909#M1083341</link>
      <description>&lt;P&gt;No, not on FMC/FTD. What I meant, you should configure proxy on FMC (like you need to), but then configure exception on proxy - when traffic is coming from FMC, bypass it from TLS decryption on proxy and/or permit it towards Satelite (and Internet, in order to download updates).&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 20:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-exceptions-on-fmc-version-6-0/m-p/4459909#M1083341</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-04T20:05:03Z</dc:date>
    </item>
  </channel>
</rss>

