<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136226#M1113802</link>
    <description>&lt;P&gt;Use control plane ACL and permit public IP allow to access via anyconnect and deny all other it better that deny all these prefix and allow few&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2024 08:38:03 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-06-26T08:38:03Z</dc:date>
    <item>
      <title>FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136208#M1113799</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We're using ASA and have some object-groups that contain hundreds to thousands of IP ranges, for example AS networks, for example public IP ranges of cloud providers, customers or networks where bots are originating attacking our AnyConnect VPN peers. For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;object-group network VPN_Blacklist
 network-object 91.108.241.0 255.255.255.0
 network-object 62.122.184.0 255.255.255.0
 network-object 94.156.8.0 255.255.255.0
 network-object 94.156.64.0 255.255.248.0
 network-object 152.89.198.0 255.255.255.0
 network-object 194.26.135.0 255.255.255.0
 network-object 185.216.70.0 255.255.255.0
 network-object 81.181.254.0 255.255.255.0
 network-object 216.151.183.0 255.255.255.0
 network-object 216.131.116.0 255.255.254.0
 network-object 216.131.80.0 255.255.254.0
 network-object 216.151.180.0 255.255.255.0
 network-object 216.131.112.0 255.255.255.0
 network-object 216.131.78.0 255.255.254.0
 ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently playing around with an FMC/FTD 7.2 test setup to check if FTD is a reasonable successor of our ASA firewalls. I noticed that on FTD object-groups just containing networks is no longer possible. For each network an object must be created and then the object can be added to an object-group. Even with importing objects via CSV it is still an overkill to do that for every IP range that is used only once in an object-group.&lt;/P&gt;&lt;P&gt;Is there a better method than tis? How could one handle such a requirement in FTD, for example allow only outbound Teams Traffic to Microsoft Cloud or block traffic from bad sites to AnyConnect VPN peer? Do you generally only use FTD in transparent mode in front of ASA or replace ASA on internet edge?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bernd&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 08:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136208#M1113799</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2024-06-26T08:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136218#M1113801</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/138411"&gt;@Network Diver&lt;/a&gt; &lt;/P&gt;
&lt;P&gt;In regard to blocking AnyConnect connections, on the FTD/ASA you can only (currently) block traffic to the FTA/ASA itself using a control-plane ACL using network objects. You cannot use Geolocation objects, if you want that funtionality you'd have to place an FTD in front of the RAVPN headend device.&lt;/P&gt;
&lt;P&gt;Have you seen these Cisco guides to harden RAVPN:-&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-client/221880-implement-hardening-measures-for-secure.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-client/221880-implement-hardening-measures-for-secure.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For outbound access, in the Access Control rules to cloud destinations (Teams, Outlook etc) you could use applications rather than network objects.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 08:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136218#M1113801</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-06-26T08:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136226#M1113802</link>
      <description>&lt;P&gt;Use control plane ACL and permit public IP allow to access via anyconnect and deny all other it better that deny all these prefix and allow few&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 08:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136226#M1113802</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-26T08:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136287#M1113805</link>
      <description>&lt;P&gt;About AnyConnect: As we have "Work from Anywhere" and since Covid mostly work remotely, the number of good networks is currently larger than the ones where botnets originate. These usually come from hosting datacenters with infected servers or from Russia. Chances that our employees spend their holidays in a datacenter in a foreign country are way smaller than they spend it in a hotel. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have to look at Application rules.&lt;/P&gt;&lt;P&gt;The knowledge/learning gap between ASA and FTD is as big as from ASA to any other firewall vendor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 11:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136287#M1113805</guid>
      <dc:creator>Network Diver</dc:creator>
      <dc:date>2024-06-26T11:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTD/FMC 7.2.x: How to do Object-groups with a lot of IP ranges?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136293#M1113806</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;the cisco publish doc about this issue this year&amp;nbsp;&lt;BR /&gt;take look&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 11:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-fmc-7-2-x-how-to-do-object-groups-with-a-lot-of-ip-ranges/m-p/5136293#M1113806</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-26T11:08:41Z</dc:date>
    </item>
  </channel>
</rss>

