<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC/FTD Inspection before identification in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-inspection-before-identification/m-p/4525658#M1086117</link>
    <description>&lt;P&gt;Doing a bunch of testing with FMC/FTD and came across &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/advanced_access_control_settings_for_network_analysis_and_intrusion_policies.html#ID-2194-0000001f" target="_self"&gt;this article&lt;/A&gt; talking about inspection of packets that pass before traffic is identified.&amp;nbsp; I'm testing this with ftp.&amp;nbsp; My policy is very simple (picture attached).&amp;nbsp; The traffic in question will hit the FTPBLOCK rule.&amp;nbsp; I'm doing a simple FTP out to a public FTP server and in my case no matter what I do the initial connection is allowed.&amp;nbsp; I enter username and pass and only then does the firewall deny the traffic.&amp;nbsp; All I see in the log is the deny yet a packet capture and the output on the screen certainly shows this being allowed for that period of time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article states that adding the inspection Intrusion policy is how this is handled.&amp;nbsp; I've tested with both Balanced Security and Connectivity and Security over connectivity adding it to the policy and the rule it would otherwise hit (Internet) as you can't add this to a block rule.&amp;nbsp; I've tested with block, block with reset, etc.&amp;nbsp; Currently the only way I've been able to make sure that initial traffic doesn't go out is to add a pre-filter rule to block it OR to disable the monitor rules I have at the top.&amp;nbsp; &amp;nbsp;In my case my block rule isn't even using application detection as I'm simply blocking tcp 20/21 all together.&amp;nbsp; I then found &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/access_control_rules.html#ID-2190-0000023b" target="_self"&gt;this article&lt;/A&gt; that talks about monitor rules stating they would allow early packets if they contain layer 7 conditions.&amp;nbsp; However, it goes on to say you can specify an intrusion policy and links to the other article.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal here is to make sure this traffic doesn't make it out at all from the get go.&amp;nbsp; Just curious if anyone has any info on what I would need to do here to make that happen while still being able to keep the monitor rules in place?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-02_08-33-09.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/140416i1C88E4B24E7CB07D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-01-02_08-33-09.jpg" alt="2022-01-02_08-33-09.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jan 2022 14:57:44 GMT</pubDate>
    <dc:creator>stamperbrian</dc:creator>
    <dc:date>2022-01-02T14:57:44Z</dc:date>
    <item>
      <title>FMC/FTD Inspection before identification</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-inspection-before-identification/m-p/4525658#M1086117</link>
      <description>&lt;P&gt;Doing a bunch of testing with FMC/FTD and came across &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/advanced_access_control_settings_for_network_analysis_and_intrusion_policies.html#ID-2194-0000001f" target="_self"&gt;this article&lt;/A&gt; talking about inspection of packets that pass before traffic is identified.&amp;nbsp; I'm testing this with ftp.&amp;nbsp; My policy is very simple (picture attached).&amp;nbsp; The traffic in question will hit the FTPBLOCK rule.&amp;nbsp; I'm doing a simple FTP out to a public FTP server and in my case no matter what I do the initial connection is allowed.&amp;nbsp; I enter username and pass and only then does the firewall deny the traffic.&amp;nbsp; All I see in the log is the deny yet a packet capture and the output on the screen certainly shows this being allowed for that period of time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article states that adding the inspection Intrusion policy is how this is handled.&amp;nbsp; I've tested with both Balanced Security and Connectivity and Security over connectivity adding it to the policy and the rule it would otherwise hit (Internet) as you can't add this to a block rule.&amp;nbsp; I've tested with block, block with reset, etc.&amp;nbsp; Currently the only way I've been able to make sure that initial traffic doesn't go out is to add a pre-filter rule to block it OR to disable the monitor rules I have at the top.&amp;nbsp; &amp;nbsp;In my case my block rule isn't even using application detection as I'm simply blocking tcp 20/21 all together.&amp;nbsp; I then found &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/access_control_rules.html#ID-2190-0000023b" target="_self"&gt;this article&lt;/A&gt; that talks about monitor rules stating they would allow early packets if they contain layer 7 conditions.&amp;nbsp; However, it goes on to say you can specify an intrusion policy and links to the other article.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goal here is to make sure this traffic doesn't make it out at all from the get go.&amp;nbsp; Just curious if anyone has any info on what I would need to do here to make that happen while still being able to keep the monitor rules in place?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-02_08-33-09.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/140416i1C88E4B24E7CB07D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-01-02_08-33-09.jpg" alt="2022-01-02_08-33-09.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jan 2022 14:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-inspection-before-identification/m-p/4525658#M1086117</guid>
      <dc:creator>stamperbrian</dc:creator>
      <dc:date>2022-01-02T14:57:44Z</dc:date>
    </item>
  </channel>
</rss>

