<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FDM GUI Block Rule Shows Permit IP Any Any in CLI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210563#M1116703</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1219980"&gt;@TerenceLockette&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="toc-hId-61800764"&gt;Rules with Snort Features Are Deployed As Permit Any Any&lt;/H2&gt;
&lt;P&gt;When you create a rule with features that are run by Snort side, like &lt;STRONG&gt;Geolocation&lt;/STRONG&gt;, URL (Universal Resource Locator) filter, Application detection, etc, &lt;STRONG&gt;they are deployed on Lina side as a permit any any rule.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/218196-understand-how-lina-rules-configured-wit.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/218196-understand-how-lina-rules-configured-wit.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 16:28:05 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-10-17T16:28:05Z</dc:date>
    <item>
      <title>FDM GUI Block Rule Shows Permit IP Any Any in CLI</title>
      <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210527#M1116701</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am extremely irritated and frustrated with FDM and have no idea why anyone would want to manage the FTDs locally (I do know why but that's beyond the point). I am in the process of going through ACL rules in order to migrate away from the FDM FTDs to FTDs that are managed by FMC just like the rest of our NGFWs in our environment. As I am going through the ruleset, I noticed that 99% of the rules have a zero hit count which doesn't make sense to me. I also checked the secondary firewall in the HA pair in case some of those hit counts are there due to any failover scenarios and it's much the same. Upon further inspection, I noticed a GeoBlock rule in the CLI that is listed as a 'permit ip any any' listed right above the remaining rules that have zero hit counts. However, when I review the GeoBlock rule in the GUI, it shows the action as block and has a list of geographic regions we configured to be blocked. Perhaps I'm missing something but I don't have any other 'permit ip any any' rules explicitly defined on this firewall and what's even more confusing is why is this rule listed as a 'permit ip any any' rule? It makes all remaining rules obsolete and provides a false log of whether those rules are actually needed for my migration and puts me in the predicament of having to add rules that may not be needed any longer. Has anyone else seen this or have an answer as to why this is?&lt;/P&gt;&lt;P&gt;I'm attaching screen shots for your review and can clearly see, in the CLI output below, that the rule remark and actual rule share the same rule-id and the GUI image contains the same name as the rule in the CLI output. This makes absolutely no sense to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TerenceLockette_0-1729180988620.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231561iA2D24EF91892EE59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TerenceLockette_0-1729180988620.png" alt="TerenceLockette_0-1729180988620.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TerenceLockette_1-1729181017105.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231562i2491A231DFDEBE0D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TerenceLockette_1-1729181017105.png" alt="TerenceLockette_1-1729181017105.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210527#M1116701</guid>
      <dc:creator>TerenceLockette</dc:creator>
      <dc:date>2024-10-17T16:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: FDM GUI Block Rule Shows Permit IP Any Any in CLI</title>
      <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210557#M1116702</link>
      <description>&lt;LI-CODE lang="markup"&gt;It makes all remaining rules obsolete and provides a false log of whether those rules are actually needed for my migration and puts me in the predicament of having to add rules that may not be needed any longer&lt;/LI-CODE&gt;
&lt;P&gt;as per the information, Looks for me someone did misconfiguraiton.&lt;/P&gt;
&lt;P&gt;you only showing part of the configuration so i can not fully confident to comment on that.&lt;/P&gt;
&lt;P&gt;Order of ACP Top to down&lt;/P&gt;
&lt;P&gt;we list all allowed on the Top end with deny any any to block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210557#M1116702</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-10-17T16:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: FDM GUI Block Rule Shows Permit IP Any Any in CLI</title>
      <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210563#M1116703</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1219980"&gt;@TerenceLockette&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="toc-hId-61800764"&gt;Rules with Snort Features Are Deployed As Permit Any Any&lt;/H2&gt;
&lt;P&gt;When you create a rule with features that are run by Snort side, like &lt;STRONG&gt;Geolocation&lt;/STRONG&gt;, URL (Universal Resource Locator) filter, Application detection, etc, &lt;STRONG&gt;they are deployed on Lina side as a permit any any rule.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/218196-understand-how-lina-rules-configured-wit.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/218196-understand-how-lina-rules-configured-wit.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210563#M1116703</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-17T16:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: FDM GUI Block Rule Shows Permit IP Any Any in CLI</title>
      <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210577#M1116705</link>
      <description>&lt;P&gt;Here is the rule order from rule 1 to the GeoBlock rule. No misconfiguration based on what's shown here. Any rules that may be any any specifies a source and destination zone. The CLI output doesn't even list source/dest zone which makes sense because the config from the GUI doesn't specify a zone:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TerenceLockette_0-1729183110292.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231575i58B921DEF34A61BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TerenceLockette_0-1729183110292.png" alt="TerenceLockette_0-1729183110292.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210577#M1116705</guid>
      <dc:creator>TerenceLockette</dc:creator>
      <dc:date>2024-10-17T16:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: FDM GUI Block Rule Shows Permit IP Any Any in CLI</title>
      <link>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210584#M1116706</link>
      <description>&lt;P&gt;So based on the URL referenced above, the appliance is indeed blocking this traffic so all other rules below with a zero hit count are not being matched against that 'permit ip any any' and are legit zero hit as the firewall has not matched any traffic against it; regardless of the GeoBlock 'permit ip any any'. Is this correct?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fdm-gui-block-rule-shows-permit-ip-any-any-in-cli/m-p/5210584#M1116706</guid>
      <dc:creator>TerenceLockette</dc:creator>
      <dc:date>2024-10-17T16:46:27Z</dc:date>
    </item>
  </channel>
</rss>

