<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Intelligence - Block List - Bogon in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558123#M1125329</link>
    <description>&lt;P&gt;The current SI feed appears to indeed have zero bogon addresses listed. I confirmed it on two separate FMCs.&lt;/P&gt;
&lt;P&gt;You can verify the raw files under&amp;nbsp;/var/sf/iprep_download in your FMC. That folder contains files for the various IP reputation feeds from TALOS. They all are named by UUIDs but you can check the mapping to human-readable name by looking at&amp;nbsp;rep_dd.yaml. There you will see the various categories listed with their associated attributes. For example:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;  bogon:
    ID: 10
    UUID: 5f8148f1-e5e4-427a-aa3b-ee1c2745c350
    expiration: never
    long: IP Addresses that are known to not be allocated but are sending traffic
    short: Bogon Address&lt;/LI-CODE&gt;
&lt;P&gt;If we look at that file, we see just the header (with no addresses listed):&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;/var/sf/iprep_download$ cat 5f8148f1-e5e4-427a-aa3b-ee1c2745c350
#Cisco intelligence feed: Bogon
&lt;/LI-CODE&gt;
&lt;P&gt;...matching the zero address shown in the FMC GUI.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2026 17:23:37 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2026-06-11T17:23:37Z</dc:date>
    <item>
      <title>Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5557973#M1125319</link>
      <description>&lt;P&gt;Does anyone know if it's normal for the Cisco Talos Feed to have 0 objects in the BOGON list?&amp;nbsp; I found when mousing over the "Bogon" in the block list it shows 0 objects.&amp;nbsp; In FMC, this is under Access Policy &amp;gt; Security Intelligence &amp;gt; Block List.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a.png" style="width: 380px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/283180i6D9FDEE3994FFC63/image-size/large?v=v2&amp;amp;px=999" role="button" title="a.png" alt="a.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Security Intelligence feeds are downloading fine.&amp;nbsp; I do have IPS licensing.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 21:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5557973#M1125319</guid>
      <dc:creator>davidb84</dc:creator>
      <dc:date>2026-06-10T21:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5557997#M1125323</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1728161"&gt;@davidb84&lt;/a&gt;&amp;nbsp;hi, bogon is IP ranges which are not assigned to use in public ip space. not sure why talos showing 0 objects in it. but blocking this will help to avoid some attacker using illegitimate IP addresses to attack.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 03:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5557997#M1125323</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2026-06-11T03:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558068#M1125326</link>
      <description>&lt;P&gt;Would anyone have the ability to check their BOGON object and verify if it shows 0 objects as pictured above?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 12:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558068#M1125326</guid>
      <dc:creator>davidb84</dc:creator>
      <dc:date>2026-06-11T12:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558093#M1125328</link>
      <description>&lt;P&gt;My cdFMC is also reporting 0 objects&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 14:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558093#M1125328</guid>
      <dc:creator>AigarsK</dc:creator>
      <dc:date>2026-06-11T14:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558123#M1125329</link>
      <description>&lt;P&gt;The current SI feed appears to indeed have zero bogon addresses listed. I confirmed it on two separate FMCs.&lt;/P&gt;
&lt;P&gt;You can verify the raw files under&amp;nbsp;/var/sf/iprep_download in your FMC. That folder contains files for the various IP reputation feeds from TALOS. They all are named by UUIDs but you can check the mapping to human-readable name by looking at&amp;nbsp;rep_dd.yaml. There you will see the various categories listed with their associated attributes. For example:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;  bogon:
    ID: 10
    UUID: 5f8148f1-e5e4-427a-aa3b-ee1c2745c350
    expiration: never
    long: IP Addresses that are known to not be allocated but are sending traffic
    short: Bogon Address&lt;/LI-CODE&gt;
&lt;P&gt;If we look at that file, we see just the header (with no addresses listed):&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;/var/sf/iprep_download$ cat 5f8148f1-e5e4-427a-aa3b-ee1c2745c350
#Cisco intelligence feed: Bogon
&lt;/LI-CODE&gt;
&lt;P&gt;...matching the zero address shown in the FMC GUI.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 17:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558123#M1125329</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-06-11T17:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558124#M1125330</link>
      <description>&lt;P&gt;So what's the correct way to block BOGONs if this feed is empty? Manually maintain a list?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 17:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558124#M1125330</guid>
      <dc:creator>davidb84</dc:creator>
      <dc:date>2026-06-11T17:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence - Block List - Bogon</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558126#M1125331</link>
      <description>&lt;P&gt;I haven't read Cisco's rationale for having no addresses in the bogon category.&lt;/P&gt;
&lt;P&gt;Normally I would expect the upstream ISP to block bogons in their router(s) eBGP configuration and thus you would never see them at your edge firewall. I suppose if you wanted, you could use a custom IP list and use that to block them as well.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 17:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-block-list-bogon/m-p/5558126#M1125331</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-06-11T17:42:18Z</dc:date>
    </item>
  </channel>
</rss>

