<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bug with Analyzer in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/bug-with-analyzer/m-p/5242735#M1118535</link>
    <description>&lt;P&gt;From what I can see in your screenshots it appears the shadowing rule is actually the #1 Allow-Standard-Outbound. Since it has "any" in the destination networks, Rule #2 and most subsequent rules will be shadowed&lt;/P&gt;
&lt;P&gt;The policy analyzer is pretty new and I have found it can give misleading or downright incorrect results.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jan 2025 14:10:52 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-01-02T14:10:52Z</dc:date>
    <item>
      <title>Bug with Analyzer</title>
      <link>https://community.cisco.com/t5/network-security/bug-with-analyzer/m-p/5242474#M1118514</link>
      <description>&lt;P&gt;So I am working on getting our firepower for our company setup. So far got things set up for the most part. Now I am just getting connectivity over site-to-site and make sure I can access servers and services throughout. I was adding rules for our XDR and MDR to make sure they dont get blocked and also the streaming service we use to access the desktops. However when I was adding more rules the analyzer keeps saying that all my rules under are "Shadowing". Saying that none of the rules are going to be hit because the proceeding rule matches. However I doubt see how this is true.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule its matching on is the Geo-Block rule. We as a company have no reason to access or use anything outside North America. So I have it hard blocking any geo locations seen below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2025-01-01 094257.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236843iC1BF4AFBF80DBBD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-01-01 094257.png" alt="Screenshot 2025-01-01 094257.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the Geo-Block-All every country is selected but USA and Canada.&lt;/P&gt;&lt;P&gt;The analyzer says this otherwise says that it matches the preceding rule. But what I notice in the defenseorchestrator it shows any for the destination network? So I dont know if this is the bug or I am doing something wrong?&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2025-01-01 094446.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236844iE1AAC8EA73793C04/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-01-01 094446.png" alt="Screenshot 2025-01-01 094446.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jan 2025 14:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bug-with-analyzer/m-p/5242474#M1118514</guid>
      <dc:creator>rtarson98</dc:creator>
      <dc:date>2025-01-01T14:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Bug with Analyzer</title>
      <link>https://community.cisco.com/t5/network-security/bug-with-analyzer/m-p/5242735#M1118535</link>
      <description>&lt;P&gt;From what I can see in your screenshots it appears the shadowing rule is actually the #1 Allow-Standard-Outbound. Since it has "any" in the destination networks, Rule #2 and most subsequent rules will be shadowed&lt;/P&gt;
&lt;P&gt;The policy analyzer is pretty new and I have found it can give misleading or downright incorrect results.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 14:10:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bug-with-analyzer/m-p/5242735#M1118535</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-02T14:10:52Z</dc:date>
    </item>
  </channel>
</rss>

