<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD blocking connection to OpenDNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4923246#M1104237</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am running FTD2120 pair in HA, software code 7.0.4 with VDB build 371. I noticed that there is increased counters for Malware blocks against Security Intelligence coming from our user base. We have deployed Cisco Umbrella in our environment which has been implemented for past 3 months.&lt;/P&gt;&lt;P&gt;FTD reports that following IP address is blocked&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;146.112.56.158&lt;/STRONG&gt;, reason &lt;STRONG&gt;IP Block&lt;/STRONG&gt;, Security Intelligence Category: &lt;STRONG&gt;Malware&lt;/STRONG&gt;. At the same time there are loads of connection to the same IP address which goes through no issues, this same IP Block is seen across&amp;nbsp;other IP addresses which belong to OpenDNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions as to what is happening here and means to resolve it? I could use Prefilter Rule, but this should not be happening in first place.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2023 07:07:25 GMT</pubDate>
    <dc:creator>AigarsK</dc:creator>
    <dc:date>2023-09-14T07:07:25Z</dc:date>
    <item>
      <title>FTD blocking connection to OpenDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4923246#M1104237</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am running FTD2120 pair in HA, software code 7.0.4 with VDB build 371. I noticed that there is increased counters for Malware blocks against Security Intelligence coming from our user base. We have deployed Cisco Umbrella in our environment which has been implemented for past 3 months.&lt;/P&gt;&lt;P&gt;FTD reports that following IP address is blocked&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;146.112.56.158&lt;/STRONG&gt;, reason &lt;STRONG&gt;IP Block&lt;/STRONG&gt;, Security Intelligence Category: &lt;STRONG&gt;Malware&lt;/STRONG&gt;. At the same time there are loads of connection to the same IP address which goes through no issues, this same IP Block is seen across&amp;nbsp;other IP addresses which belong to OpenDNS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions as to what is happening here and means to resolve it? I could use Prefilter Rule, but this should not be happening in first place.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 07:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4923246#M1104237</guid>
      <dc:creator>AigarsK</dc:creator>
      <dc:date>2023-09-14T07:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD blocking connection to OpenDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4924082#M1104271</link>
      <description>&lt;P&gt;AigarsK,&lt;/P&gt;&lt;P&gt;I see the same behavior on our network running two 9300s in an HA pair.&amp;nbsp; What I believe is happening is the original IP is being passed to OpenDNS and if the site is blocked, the packet coming back has the OpenDNS IP address attached rather than the original IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we could definitely solve this by running a packet capture to a known blocked site and see if the header is appended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Donnie&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 11:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4924082#M1104271</guid>
      <dc:creator>dwillia5@highpoint.edu</dc:creator>
      <dc:date>2023-09-15T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: FTD blocking connection to OpenDNS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4924164#M1104274</link>
      <description>&lt;P&gt;Hi Donnie,&lt;BR /&gt;I think you are right, I just managed to locate IP Block which included the URL, it was also blocked on Umbrella for the same user and source IP.&lt;BR /&gt;Would still like to find out how to prevent these double detections/blocks from appearing in FTD as they serve no value to report on.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 14:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-blocking-connection-to-opendns/m-p/4924164#M1104274</guid>
      <dc:creator>AigarsK</dc:creator>
      <dc:date>2023-09-15T14:43:27Z</dc:date>
    </item>
  </channel>
</rss>

