<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD 1010 - Traffic No Action Policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236601#M1118206</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've configured a Cisco FTD 1010 and I'm having a weird behavior happening. I've configured all the policies from inside to outside and the default action is to block.&lt;/P&gt;&lt;P&gt;I've configured several policies and I can see them being allowed and matching correctly, but then I saw this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Othacon_0-1734098826882.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235907i44D73CFE6D5898C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Othacon_0-1734098826882.png" alt="Othacon_0-1734098826882.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The default action of the firewall is to block. Why is the firewall not matching any traffic and putting the traffic in No Action??&lt;/P&gt;&lt;P&gt;Please anyone can help?&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2024 14:14:01 GMT</pubDate>
    <dc:creator>Othacon</dc:creator>
    <dc:date>2024-12-13T14:14:01Z</dc:date>
    <item>
      <title>FTD 1010 - Traffic No Action Policy</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236601#M1118206</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've configured a Cisco FTD 1010 and I'm having a weird behavior happening. I've configured all the policies from inside to outside and the default action is to block.&lt;/P&gt;&lt;P&gt;I've configured several policies and I can see them being allowed and matching correctly, but then I saw this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Othacon_0-1734098826882.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235907i44D73CFE6D5898C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Othacon_0-1734098826882.png" alt="Othacon_0-1734098826882.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The default action of the firewall is to block. Why is the firewall not matching any traffic and putting the traffic in No Action??&lt;/P&gt;&lt;P&gt;Please anyone can help?&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 14:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236601#M1118206</guid>
      <dc:creator>Othacon</dc:creator>
      <dc:date>2024-12-13T14:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 - Traffic No Action Policy</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236602#M1118207</link>
      <description>&lt;P&gt;can I see show access-list of FTD&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 14:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236602#M1118207</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-13T14:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 - Traffic No Action Policy</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236607#M1118208</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately I really can't put the entire rule list, but I can put the last ones, please see below:&lt;/P&gt;&lt;P&gt;access-list NGFW_ONBOX_ACL line 34 remark rule-id 268435458: ACCESS POLICY: NGFW_Access_Policy&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 35 remark rule-id 268435458: L5 RULE: Blocked Traffic&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 36 advanced deny object-group |acSvcg-268435458 ifc inside any ifc outside any rule-id 268435458 event-log both (hitcnt=483795) (Last Hit=14:19:25 UTC Dec 13 2024) 0x7aae9053&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 36 advanced deny ip ifc inside any ifc outside any rule-id 268435458 event-log both (hitcnt=483795) (Last Hit=14:19:25 UTC Dec 13 2024) 0xe41ebd9d&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 37 remark rule-id 1: ACCESS POLICY: NGFW_Access_Policy&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 38 remark rule-id 1: L5 RULE: DefaultActionRule&lt;BR /&gt;access-list NGFW_ONBOX_ACL line 39 advanced deny ip any any rule-id 1 event-log both (hitcnt=278693635) (Last Hit=14:19:26 UTC Dec 13 2024) 0x84953cae&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the rules are configured I would expect for them to match their respective policies, but from the image, the FTD is not matching some traffic with anything and it's putting it as No Action, and i really can't understand why. I even double on the deny action to no avail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 14:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236607#M1118208</guid>
      <dc:creator>Othacon</dc:creator>
      <dc:date>2024-12-13T14:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 - Traffic No Action Policy</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236609#M1118210</link>
      <description>&lt;P&gt;I will send you some hints about FTD ACL&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 14:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236609#M1118210</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-13T14:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1010 - Traffic No Action Policy</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236987#M1118224</link>
      <description>&lt;P&gt;This can happen when an access control rule has not finished evaluating a connection and at that point the connection just breaks our stops outside the firewall. At that point the rule was still pending and it logged the latest state it was evaluating at the time. If that’s what it is it’s possible you have an Application rule that requires more packets to be fully evaluated.&amp;nbsp;&lt;BR /&gt;Future versions will include this state as a new state as part of the Reason field to avoid confusion.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2024 19:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1010-traffic-no-action-policy/m-p/5236987#M1118224</guid>
      <dc:creator>ckleopa</dc:creator>
      <dc:date>2024-12-14T19:27:54Z</dc:date>
    </item>
  </channel>
</rss>

