<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC Threat Intelligence in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672967#M1092823</link>
    <description>&lt;P&gt;I've created a .txt file and added IPs prefix list into the file. I've tried to block IPs in the file via TID by uploading the file as a flat file. But I have still had same problems. Also I've tried to block the file by adding it into the Network Lists and Feeds and block that file's prefix by adding it into Security Intelligence in the Access control policy but I have the same problems that not all IPs in the same subnet is block.&lt;BR /&gt;For example, according to the attached file, I've blocked 162.142.125/24 by adding it into the txt file. some of the IPs in the same range are blocking but some of them are not.&lt;/P&gt;&lt;P&gt;According to cisco's "Inspection procedure," it should be blocked before being matched by IPS policies.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Aug 2022 12:12:51 GMT</pubDate>
    <dc:creator>Meisam Azizzadeh</dc:creator>
    <dc:date>2022-08-21T12:12:51Z</dc:date>
    <item>
      <title>FMC Threat Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672948#M1092819</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have several problems with Cisco Threat Intelligence. I want to block for example several ASN. I found their IP prefixes but sometimes Threat Intelligence doesn't block all IP prefixes in this IP scope so I manually blocked them. Is there any limitation for Threat Intelligence? How can I block these IPs prefix? what is the best practice?&lt;BR /&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 09:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672948#M1092819</guid>
      <dc:creator>Meisam Azizzadeh</dc:creator>
      <dc:date>2022-08-21T09:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Threat Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672953#M1092820</link>
      <description>&lt;LI-CODE lang="markup"&gt;I have several problems with Cisco Threat Intelligence&lt;/LI-CODE&gt;
&lt;P&gt;If so many problems in production environment, suggest to contact partner and validate what you doing correct, we do understand some bugs on cisco product.&lt;/P&gt;
&lt;P&gt;To get the best out of the product get the right resource to reply and the best way.&lt;/P&gt;
&lt;P&gt;you need to provide environmental information what is version of code running, what FTD you have, how is your FMC setup done.&lt;/P&gt;
&lt;P&gt;provide some use cases how you deployed and what logs you see or observed.&lt;/P&gt;
&lt;P&gt;check CTI deployment guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 09:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672953#M1092820</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-21T09:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Threat Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672964#M1092822</link>
      <description>&lt;P&gt;Are you asking about Threat Intelligence (Threat Intelligence Director feature) or Security Intelligence?&lt;/P&gt;
&lt;P&gt;From your question I would think it is actually the latter. How did you add the desired prefixes to be blocked?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 11:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672964#M1092822</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-08-21T11:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Threat Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672967#M1092823</link>
      <description>&lt;P&gt;I've created a .txt file and added IPs prefix list into the file. I've tried to block IPs in the file via TID by uploading the file as a flat file. But I have still had same problems. Also I've tried to block the file by adding it into the Network Lists and Feeds and block that file's prefix by adding it into Security Intelligence in the Access control policy but I have the same problems that not all IPs in the same subnet is block.&lt;BR /&gt;For example, according to the attached file, I've blocked 162.142.125/24 by adding it into the txt file. some of the IPs in the same range are blocking but some of them are not.&lt;/P&gt;&lt;P&gt;According to cisco's "Inspection procedure," it should be blocked before being matched by IPS policies.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 12:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4672967#M1092823</guid>
      <dc:creator>Meisam Azizzadeh</dc:creator>
      <dc:date>2022-08-21T12:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Threat Intelligence</title>
      <link>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4673194#M1092835</link>
      <description>&lt;P&gt;One thing to consider - If there are any existing connection or flows to/from the addresses of interest those will persist until you clear connections.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 08:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-threat-intelligence/m-p/4673194#M1092835</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-08-22T08:07:44Z</dc:date>
    </item>
  </channel>
</rss>

