<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking TikTok app on Firepower 2140 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165143#M1115300</link>
    <description>&lt;P&gt;I think you need ssl decrypt'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FTD can not detect app-id until it decrypt ssl session and see inside packet.&lt;/P&gt;
&lt;P&gt;You need to check if traffic is http or https&lt;/P&gt;
&lt;P&gt;Sorry you need license I think to run this feature&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 16:35:57 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-08-23T16:35:57Z</dc:date>
    <item>
      <title>Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165012#M1115291</link>
      <description>&lt;P&gt;The 2140s are managed by FMC.&lt;/P&gt;&lt;P&gt;In my ACPs, I have a policy for blocking. In this policy, the main components it is blocking are URLs. We have all the default groups that should be blocked. And we also have a custom list of URLs that we block to. This list is made in Objects&amp;gt; security intelligence&amp;gt; URL lists and feeds.&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/admkjnI" target="_blank" rel="noopener"&gt;https://imgur.com/a/admkjnI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The list is just a .txt file that is a master list of 1500+ URLs that we block and I just upload it into FMC. One of the urls on the list is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.tiktok.com/" target="_blank" rel="noopener"&gt;www.tiktok.com&lt;/A&gt;, and it works great at blocking access to tiktok from a web browser.&lt;/P&gt;&lt;P&gt;The issue is that the tiktok app is still accessible. Weather it be a windows app or a ios/android phone app, you can still access it that way.&lt;/P&gt;&lt;P&gt;You can see in the screenshot of the access control policy that I did add tiktok and tiktok music app to the block list. That did not block the tiktok app though. I then went into objects&amp;gt;application filters and created a custom filter. I named it Tiktok and in there, also added tiktok and tiktok music app. I then applied that filter to the ACP. Still no luck. Tiktok is still accessible on phones and windows apps.&lt;/P&gt;&lt;P&gt;So I started to watch the logs as I was accessing tiktok from my phone to see what is coming up. I can see the tiktok web application being used, and noticed that everytime it is accessed, it is a different url everytime....&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/FHswKip" target="_blank" rel="noopener"&gt;https://imgur.com/a/FHswKip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So my question is, what is the right way to make sure the tiktok app is blocked from our network? Am I doing the app blocking correctly? Is there some type of wildcard url filter I need to put in to block all the random tiktok urls coming up from the app being used? As I said, i am blocking "&lt;A href="http://www.tiktok.com/" target="_blank" rel="noopener"&gt;www.tiktok.com&lt;/A&gt;" from web browsers via url filtering, but just cant figure out how to block the actual app.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 12:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165012#M1115291</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T12:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165027#M1115292</link>
      <description>&lt;P&gt;Make separate ACP entries for URLs and Apps. Otherwise the rule logic looks to logically combine (Boolean AND) the separate parameters.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:10:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165027#M1115292</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-08-23T13:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165085#M1115293</link>
      <description>&lt;P&gt;Try making an ACP rule and only include the TikTok app and the source subnets you want to block for.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 15:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165085#M1115293</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-08-23T15:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165090#M1115294</link>
      <description>&lt;P&gt;Have you tried a rule where you block the detected application? You could try inserting that about the rule that blocks the URL list.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 15:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165090#M1115294</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-08-23T15:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165107#M1115295</link>
      <description>&lt;P&gt;So I tried that and still no luck. I have attached pictures so you can see the rule I made, its placement, and the logs I am seeing from the iphone I am testing with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is also a link that might make it easier to look at the 3 pictures....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/mkIsJLJ" target="_blank" rel="noopener"&gt;https://imgur.com/a/mkIsJLJ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 15:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165107#M1115295</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T15:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165108#M1115296</link>
      <description>&lt;P&gt;So I tried that and still no luck. I have attached pictures so you can see the rule I made, its placement, and the logs I am seeing from the iphone I am testing with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is also a link that might make it easier to look at the 3 pictures....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/mkIsJLJ" target="_blank" rel="noopener"&gt;https://imgur.com/a/mkIsJLJ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 15:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165108#M1115296</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T15:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165109#M1115297</link>
      <description>&lt;P&gt;So I tried that and still no luck. I have attached pictures so you can see the rule I made, its placement, and the logs I am seeing from the iphone I am testing with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is also a link that might make it easier to look at the 3 pictures..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://imgur.com/a/mkIsJLJ" target="_blank" rel="noopener"&gt;https://imgur.com/a/mkIsJLJ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 15:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165109#M1115297</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T15:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165143#M1115300</link>
      <description>&lt;P&gt;I think you need ssl decrypt'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FTD can not detect app-id until it decrypt ssl session and see inside packet.&lt;/P&gt;
&lt;P&gt;You need to check if traffic is http or https&lt;/P&gt;
&lt;P&gt;Sorry you need license I think to run this feature&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165143#M1115300</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-23T16:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165156#M1115303</link>
      <description>&lt;P&gt;So how can it block &lt;A href="https://www.tiktok.com" target="_blank"&gt;https://www.tiktok.com&lt;/A&gt;&amp;nbsp;if it too is using https?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165156#M1115303</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T16:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165158#M1115304</link>
      <description>&lt;P&gt;Ssl policy you need&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165158#M1115304</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-23T16:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165159#M1115305</link>
      <description>&lt;P&gt;hmm ok. I might need to open a tac case&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165159#M1115305</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T16:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165162#M1115306</link>
      <description>&lt;P&gt;Sure Open TAC abd check them opinion&lt;/P&gt;
&lt;P&gt;aap detect is happened before and after ssl decrypt' so this my view to issue&lt;/P&gt;
&lt;P&gt;Goodluck and update us about solution&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165162#M1115306</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-23T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165164#M1115307</link>
      <description>&lt;P&gt;Yeah not saying I dont trust your opinion, but creating an SSL decryption policy is above my level. Going to open a TAC case to assist with that. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165164#M1115307</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T17:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165167#M1115308</link>
      <description>&lt;P&gt;Friend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are so welcome anytime&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165167#M1115308</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-23T17:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165214#M1115311</link>
      <description>&lt;P&gt;I found the Cisco Secure Firepower documentation on setting up decryption to be lacking. If you are in an Active Directory environment, this video may be useful.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=tAIdcZ3EBiw" target="_blank"&gt;https://www.youtube.com/watch?v=tAIdcZ3EBiw&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Once you have the Sub-CA enabled and are able to decrypt traffic, this doc proved quite useful for me in crafting the decryption policy.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3063.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 18:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165214#M1115311</guid>
      <dc:creator>davparker</dc:creator>
      <dc:date>2024-08-23T18:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TikTok app on Firepower 2140</title>
      <link>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165217#M1115312</link>
      <description>&lt;P&gt;Seems like this is going to get more complicated than what I thought&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 18:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-tiktok-app-on-firepower-2140/m-p/5165217#M1115312</guid>
      <dc:creator>net_ad</dc:creator>
      <dc:date>2024-08-23T18:26:34Z</dc:date>
    </item>
  </channel>
</rss>

