<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Geolocation Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4835215#M1100404</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;i would also say that for starters a quick look at unified events will let you identify whats dropping the connection - ACL, Security intelligence, Malware/file policy etc.&lt;BR /&gt;If it is because of geolocation update, you can probably reach out to Cisco TAC and get it checked / fixed.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493&lt;/A&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;
&lt;P&gt;Divya Jain&lt;/P&gt;</description>
    <pubDate>Mon, 15 May 2023 06:18:56 GMT</pubDate>
    <dc:creator>Divya Jain</dc:creator>
    <dc:date>2023-05-15T06:18:56Z</dc:date>
    <item>
      <title>Issues with Geolocation Rules</title>
      <link>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4824296#M1100004</link>
      <description>&lt;P&gt;We are experiencing some odd issues with our geolocation feature in FMC/FTD environment.&amp;nbsp; We have about 150 remote end users based in the US, metro Atlanta specifically, and an overwhelming majority of them have no issue connecting over our Citrix/VPN.&amp;nbsp; However a handful of end users, four in this case, all in Atlanta, are being blocked.&amp;nbsp; Manually applying their outside-facing ISP addresses of these four end users to the firewall rule that also included the geolocation rule corrected the issue.&amp;nbsp; We're stumped as to why only these four end users are being impacted.&amp;nbsp; We did note they use AT&amp;amp;T Uverse as their service provider, but so do many of the other end users who are not impacted by this issue.&amp;nbsp; All four end user's each have the same first octet of 99.x.x.x, again, like many other unaffected end users.&amp;nbsp; We're running IOS Version 7.0.4 on each of our 2110 FTD appliances as well as our FMC VM.&amp;nbsp; All geolocation files are regularly updated, and we run the most recent Snort3 rules, which are configured to manually update.&amp;nbsp; We just can't quite figure out why these four end users are being blocked.&amp;nbsp; The only thing we can relate it to is that it began after a geolocation update was pushed in late January.&amp;nbsp; The problem began immediately following that update.&amp;nbsp; Has anyone else experienced this?&amp;nbsp; Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4824296#M1100004</guid>
      <dc:creator>CJ Bird</dc:creator>
      <dc:date>2023-04-28T16:05:03Z</dc:date>
    </item>
    <item>
      <title>It seems like the issue started after a geolocation updat...</title>
      <link>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4832031#M1100287</link>
      <description>It seems like the issue started after a geolocation update, which might have caused some changes in the geolocation database leading to these four end users being incorrectly identified based on their IP addresses.&lt;BR /&gt;&lt;BR /&gt;To diagnose and troubleshoot this issue, you can follow these steps:&lt;BR /&gt;&lt;BR /&gt;1. Verify the geolocation configuration: Double-check the geolocation settings in FMC, specifically the settings related to blocking or allowing traffic based on geolocation. Make sure that the United States, and more specifically, metro Atlanta, is allowed in your geolocation policy.&lt;BR /&gt;&lt;BR /&gt;2. Check for geolocation database discrepancies: There might be a discrepancy in the geolocation database that's causing these four IP addresses to be incorrectly identified. You can use online geolocation lookup services to double-check the location of these IP addresses and compare it with what's being shown in FMC.&lt;BR /&gt;&lt;BR /&gt;3. Review logs and events: Analyze the logs and events in FMC related to these four end users being blocked. Look for any specific indicators or reasons for the block, such as a specific rule or policy being triggered.&lt;BR /&gt;&lt;BR /&gt;4. Test with different geolocation databases: If possible, try rolling back to a previous geolocation database version to see if the issue persists. If the issue is resolved, you can consider reaching out to Cisco TAC to report the problem with the latest geolocation update.&lt;BR /&gt;&lt;BR /&gt;5. Check for other possible issues: Although the issue seems to be related to geolocation, it's still worth checking other possible causes, such as incorrect IP address ranges, overlapping rules, or issues with the ISP.&lt;BR /&gt;&lt;BR /&gt;If the issue persists after trying these steps, it's recommended to open a case with Cisco TAC for further investigation and assistance. They can help you identify the root cause and provide a solution for the issue.</description>
      <pubDate>Tue, 09 May 2023 16:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4832031#M1100287</guid>
      <dc:creator>Cisco_Virtual_Engineer</dc:creator>
      <dc:date>2023-05-09T16:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Geolocation Rules</title>
      <link>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4835215#M1100404</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;i would also say that for starters a quick look at unified events will let you identify whats dropping the connection - ACL, Security intelligence, Malware/file policy etc.&lt;BR /&gt;If it is because of geolocation update, you can probably reach out to Cisco TAC and get it checked / fixed.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493&lt;/A&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;
&lt;P&gt;Divya Jain&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 06:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issues-with-geolocation-rules/m-p/4835215#M1100404</guid>
      <dc:creator>Divya Jain</dc:creator>
      <dc:date>2023-05-15T06:18:56Z</dc:date>
    </item>
  </channel>
</rss>

