<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connections to web sites using typekit timing out behind FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4680537#M1093136</link>
    <description>&lt;P&gt;Hi Maury,&lt;/P&gt;&lt;P&gt;Just ran into something similar, and what I found was that my 2120 was associating the URL &lt;A href="https://p.typekit.net" target="_blank"&gt;https://p.typekit.net&lt;/A&gt; with a web application called Burnbook (an anonymous messaging app) which Cisco classifies as a Very High Risk application and was blocking it per a rule to block Very High Risk applications. I discovered this by viewing Connection Events filtered for my workstation IP while trying to load the website in question. I tried whitelisting the typekit URL with no effect. However whitelisting this Burnbook app did the trick. Not sure how/why Adobe's hosted web font service got linked with this Burnbook app by Cisco in their VDB.&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;BR /&gt;John&lt;/P&gt;</description>
    <pubDate>Fri, 02 Sep 2022 18:58:35 GMT</pubDate>
    <dc:creator>jmatysek</dc:creator>
    <dc:date>2022-09-02T18:58:35Z</dc:date>
    <item>
      <title>Connections to web sites using typekit timing out behind FTD</title>
      <link>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4640343#M1091397</link>
      <description>&lt;P&gt;We noticed a strange phenomenon with at least two sites, both of which are using Adobe fonts (typenet.net), when accessed from behind our ASA with FTD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the developer tools console in chrome, I can see that while the page is loading, the browser sits and eventually times out waiting for a response while trying to load a font from p.typekit.net, and we see this from both Windows and Mac clients on our internal network.&amp;nbsp; &amp;nbsp;The actual requested URL in one case is:&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://p.typekit.net/p.css?s=1&amp;amp;k=oci4iyo&amp;amp;ht=tk&amp;amp;f=15779.15782&amp;amp;a=86990265&amp;amp;app=typekit&amp;amp;e=css" target="_blank"&gt;https://p.typekit.net/p.css?s=1&amp;amp;k=oci4iyo&amp;amp;ht=tk&amp;amp;f=15779.15782&amp;amp;a=86990265&amp;amp;app=typekit&amp;amp;e=css&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When analyzing the connection event logs in FMC, I am not seeing any relevant connections from the clients getting blocked, when loading these sites.&amp;nbsp; &amp;nbsp;Outside of our network, the issue does not come up.&amp;nbsp; &amp;nbsp;The client's we're seeing this from have access to http and https in our ACLs and aren't going through a proxy.&amp;nbsp; &amp;nbsp; Has anyone else run up against this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Versions:&lt;/P&gt;&lt;P&gt;FTD 6.7.0.3&lt;/P&gt;&lt;P&gt;Snort 2.9.17 (Build 3014)&lt;BR /&gt;Rule Update 2022-06-16-001&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 15:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4640343#M1091397</guid>
      <dc:creator>MauryJ</dc:creator>
      <dc:date>2022-06-28T15:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to web sites using typekit timing out behind FTD</title>
      <link>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4640584#M1091403</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Just to ensure that you have logging setup correctly, configure a&lt;BR /&gt;rule which matches specific client source IP at the top and enable logging&lt;BR /&gt;on it. Then look for connection events to see if there are matches.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Jun 2022 01:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4640584#M1091403</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-29T01:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to web sites using typekit timing out behind FTD</title>
      <link>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4680537#M1093136</link>
      <description>&lt;P&gt;Hi Maury,&lt;/P&gt;&lt;P&gt;Just ran into something similar, and what I found was that my 2120 was associating the URL &lt;A href="https://p.typekit.net" target="_blank"&gt;https://p.typekit.net&lt;/A&gt; with a web application called Burnbook (an anonymous messaging app) which Cisco classifies as a Very High Risk application and was blocking it per a rule to block Very High Risk applications. I discovered this by viewing Connection Events filtered for my workstation IP while trying to load the website in question. I tried whitelisting the typekit URL with no effect. However whitelisting this Burnbook app did the trick. Not sure how/why Adobe's hosted web font service got linked with this Burnbook app by Cisco in their VDB.&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;BR /&gt;John&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 18:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4680537#M1093136</guid>
      <dc:creator>jmatysek</dc:creator>
      <dc:date>2022-09-02T18:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Connections to web sites using typekit timing out behind FTD</title>
      <link>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4735855#M1095792</link>
      <description>&lt;P&gt;I have the same experience. Web pages were taking 30+ Seconds to load. Using Dev Tools in the browser confirmed a use.typekit.net file was failing to load. But only behind our FTD's/FMC not on personal / offsite machines.&lt;/P&gt;&lt;P&gt;Looked at the logs, scanned the url/file with Talos, all came back fine. FMC Events shows BurnBook application as well.&lt;BR /&gt;&lt;BR /&gt;I guess i'm going to whitelist BurnBook. Bummer. Is there a method to notify Talos of this mis-assignment?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 18:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-to-web-sites-using-typekit-timing-out-behind-ftd/m-p/4735855#M1095792</guid>
      <dc:creator>nick_t</dc:creator>
      <dc:date>2022-12-09T18:08:16Z</dc:date>
    </item>
  </channel>
</rss>

