<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default Action Block - Log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306589#M1121671</link>
    <description>&lt;P&gt;Good to know that there is no log for Default Action (block), thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jul 2025 15:59:46 GMT</pubDate>
    <dc:creator>Otvforte</dc:creator>
    <dc:date>2025-07-07T15:59:46Z</dc:date>
    <item>
      <title>Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306521#M1121661</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;I'm start learning FTD (FP1010) and trying to figure out why I can't see external blocked SYN packets on FDM web interface (Events Tab). They are visible only on syslog messages, like this example:&amp;nbsp;07-07-2025 10:29:14 Local4.Error 192.168.0.1 Jul 07 2025 13:29:14: %FTD-3-710003: TCP access denied by ACL from x.x.x.x/41322 to outside:y.y.y.y/22&lt;/P&gt;&lt;P&gt;Also, if its due to the different engines (LINA and Snort), what kind of messages are supposed to show onFTD web interface ? Only those related with Next Gen components ?&lt;/P&gt;&lt;P&gt;The Default Action on Policies are configured to Block and Log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_0-1751895849037.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/247805i97F8660E8684099E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_0-1751895849037.png" alt="Otvforte_0-1751895849037.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306521#M1121661</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-07T13:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306528#M1121663</link>
      <description>&lt;P&gt;Can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 14:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306528#M1121663</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-07T14:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306558#M1121666</link>
      <description>&lt;P&gt;Sure sir. I know the firewall is blocking WAN to LAN connections by default (Default Action on Policies is set to Block). I'm able to see these blocked connections on syslog messages (remote server or even with CLI 'show logging') but the same blocked connections do not show on FDM - Monitoring / Events logs. Why blocks on Defaul Action do not show on the events when using at the FDM ? On the other hand, for rules that I create manually (like block a ping for example), I can see the block information on the FDM Monitoring / Events option and on syslog as well.&lt;/P&gt;&lt;P&gt;Maybe this is the expected behavior, I'm just trying to understand.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306558#M1121666</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-07T15:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306566#M1121667</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (268).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/247807iCCC4359583E66EB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (268).png" alt="Screenshot (268).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;in the left down corner there is default action and it Block&amp;nbsp;&lt;BR /&gt;and by defualt there is no log&amp;nbsp;&lt;BR /&gt;you can click in icon to enable log for this action&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306566#M1121667</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-07T15:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306589#M1121671</link>
      <description>&lt;P&gt;Good to know that there is no log for Default Action (block), thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306589#M1121671</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-07T15:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Block - Log</title>
      <link>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306590#M1121672</link>
      <description>&lt;P&gt;You are so welcome&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 16:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-block-log/m-p/5306590#M1121672</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-07T16:03:48Z</dc:date>
    </item>
  </channel>
</rss>

