<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco FTD Evaluation Mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358247#M1123952</link>
    <description>&lt;P data-start="3458" data-end="3469"&gt;Hello Team,&lt;/P&gt;
&lt;P data-start="3471" data-end="3637"&gt;I am testing a Cisco Firepower 1010 physical appliance running FTD 7.2.5 in standalone mode. The device is currently in Evaluation mode (no licenses applied).&lt;/P&gt;
&lt;P data-start="3639" data-end="3657"&gt;Observed behavior:&lt;/P&gt;
&lt;UL data-start="3658" data-end="3945"&gt;
&lt;LI data-start="3658" data-end="3713"&gt;
&lt;P data-start="3660" data-end="3713"&gt;Internet traffic works when allowed in Access Control.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Internet traffic doesnt work when blocked below allowed rules in Access Control.&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Malware test URLs (EICAR) are not blocked&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Threat / malware sites are allowed&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;All URLs appear as &lt;STRONG data-start="3820" data-end="3837"&gt;Uncategorized&lt;/STRONG&gt; in event logs&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;“Malware &amp;amp; File” policy option is not visible in GUI&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;URL category-based rules never match&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="3947" data-end="3963"&gt;I have verified:&lt;/P&gt;
&lt;UL data-start="3964" data-end="4094"&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;Access Control policies are applied correctly&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;DNS and HTTP/HTTPS are allowed when configured under ports however doesnt work when allowed under Applications.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;&lt;SPAN&gt;Logging is enabled&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4066" data-end="4094"&gt;
&lt;P data-start="4068" data-end="4094"&gt;SSL decryption is disabled&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="4096" data-end="4109"&gt;My questions:&lt;/P&gt;
&lt;OL data-start="4110" data-end="4424"&gt;
&lt;LI data-start="4110" data-end="4203"&gt;
&lt;P data-start="4113" data-end="4203"&gt;Are Malware, URL Filtering, and IPS enforcement disabled by design in Evaluation mode?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4204" data-end="4345"&gt;
&lt;P data-start="4207" data-end="4267"&gt;Is a valid Malware / URL / Threat license mandatory for:&lt;/P&gt;
&lt;UL data-start="4271" data-end="4345"&gt;
&lt;LI data-start="4271" data-end="4289"&gt;
&lt;P data-start="4273" data-end="4289"&gt;Malware blocking&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4293" data-end="4313"&gt;
&lt;P data-start="4295" data-end="4313"&gt;URL categorization&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4317" data-end="4345"&gt;
&lt;P data-start="4319" data-end="4345"&gt;Talos reputation verdicts?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="4346" data-end="4424"&gt;
&lt;P data-start="4349" data-end="4424"&gt;Is it expected that all URLs show as Uncategorized without URL license?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="4426" data-end="4545"&gt;Please confirm if this behavior is expected and license-dependent, or if there is any limitation specific to FTD 7.2.5.&lt;/P&gt;
&lt;P data-start="4547" data-end="4557"&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2025 11:41:40 GMT</pubDate>
    <dc:creator>bhavin-vadodaria</dc:creator>
    <dc:date>2025-12-30T11:41:40Z</dc:date>
    <item>
      <title>Cisco FTD Evaluation Mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358247#M1123952</link>
      <description>&lt;P data-start="3458" data-end="3469"&gt;Hello Team,&lt;/P&gt;
&lt;P data-start="3471" data-end="3637"&gt;I am testing a Cisco Firepower 1010 physical appliance running FTD 7.2.5 in standalone mode. The device is currently in Evaluation mode (no licenses applied).&lt;/P&gt;
&lt;P data-start="3639" data-end="3657"&gt;Observed behavior:&lt;/P&gt;
&lt;UL data-start="3658" data-end="3945"&gt;
&lt;LI data-start="3658" data-end="3713"&gt;
&lt;P data-start="3660" data-end="3713"&gt;Internet traffic works when allowed in Access Control.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Internet traffic doesnt work when blocked below allowed rules in Access Control.&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Malware test URLs (EICAR) are not blocked&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;Threat / malware sites are allowed&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;All URLs appear as &lt;STRONG data-start="3820" data-end="3837"&gt;Uncategorized&lt;/STRONG&gt; in event logs&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;“Malware &amp;amp; File” policy option is not visible in GUI&lt;/LI&gt;
&lt;LI data-start="3658" data-end="3713"&gt;URL category-based rules never match&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="3947" data-end="3963"&gt;I have verified:&lt;/P&gt;
&lt;UL data-start="3964" data-end="4094"&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;Access Control policies are applied correctly&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;DNS and HTTP/HTTPS are allowed when configured under ports however doesnt work when allowed under Applications.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3964" data-end="4011"&gt;
&lt;P data-start="3966" data-end="4011"&gt;&lt;SPAN&gt;Logging is enabled&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4066" data-end="4094"&gt;
&lt;P data-start="4068" data-end="4094"&gt;SSL decryption is disabled&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="4096" data-end="4109"&gt;My questions:&lt;/P&gt;
&lt;OL data-start="4110" data-end="4424"&gt;
&lt;LI data-start="4110" data-end="4203"&gt;
&lt;P data-start="4113" data-end="4203"&gt;Are Malware, URL Filtering, and IPS enforcement disabled by design in Evaluation mode?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4204" data-end="4345"&gt;
&lt;P data-start="4207" data-end="4267"&gt;Is a valid Malware / URL / Threat license mandatory for:&lt;/P&gt;
&lt;UL data-start="4271" data-end="4345"&gt;
&lt;LI data-start="4271" data-end="4289"&gt;
&lt;P data-start="4273" data-end="4289"&gt;Malware blocking&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4293" data-end="4313"&gt;
&lt;P data-start="4295" data-end="4313"&gt;URL categorization&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="4317" data-end="4345"&gt;
&lt;P data-start="4319" data-end="4345"&gt;Talos reputation verdicts?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="4346" data-end="4424"&gt;
&lt;P data-start="4349" data-end="4424"&gt;Is it expected that all URLs show as Uncategorized without URL license?&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-start="4426" data-end="4545"&gt;Please confirm if this behavior is expected and license-dependent, or if there is any limitation specific to FTD 7.2.5.&lt;/P&gt;
&lt;P data-start="4547" data-end="4557"&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 11:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358247#M1123952</guid>
      <dc:creator>bhavin-vadodaria</dc:creator>
      <dc:date>2025-12-30T11:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Evaluation Mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358252#M1123953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; It needs to work, however you need to first perform content updates, for URL and Malware. Also, from device configuration, ensure all licenses are checked.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 12:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358252#M1123953</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2025-12-30T12:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD Evaluation Mode</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358546#M1123979</link>
      <description>&lt;P&gt;Thank you for an update. Yes, but before performing content updates or anything make sure NTP is in sync to get all the updates.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jan 2026 10:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-evaluation-mode/m-p/5358546#M1123979</guid>
      <dc:creator>bhavin-vadodaria</dc:creator>
      <dc:date>2026-01-01T10:53:17Z</dc:date>
    </item>
  </channel>
</rss>

