<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I just tested in lab and it in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039092#M135868</link>
    <description>&lt;P&gt;I just tested in lab and it worked as expected. I created a list(created a notepad with cisco.com as URL) under SI. Then called that URL under blacklist under ACP SI option.&lt;/P&gt;
&lt;P&gt;cisco.com was allowed earlier and as soon as I used SI blacklist option for the list created earlier, it got blocked. And I also see under 'Security Intelligence Events'.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That means that SI should be preferred when it comes to blacklist. Ofcourse for whitelist URL, it will make it go through other ACP rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you need any of the screenshots from my lab.&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-AJ&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2017 15:44:57 GMT</pubDate>
    <dc:creator>Ajay Saini</dc:creator>
    <dc:date>2017-05-05T15:44:57Z</dc:date>
    <item>
      <title>Security Intelligence URL Blacklist</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039089#M135855</link>
      <description>&lt;P&gt;I created a static list for URL blacklist and applied to my ACP. I was under assumption that the security Intelligence settings override any rules defined within the ACP. &amp;nbsp; Just to see what traffic was getting through to my Allow_All rule with IPS defined I superceded it with a Block ALL rule which catched the URL that I specified to be blocked within the Security intelligence section. Very frustrating to say the least. What should be taking place here???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039089#M135855</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2019-03-12T09:19:16Z</dc:date>
    </item>
    <item>
      <title>You are right, SI blocklist</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039090#M135859</link>
      <description>&lt;P&gt;You are right, SI blocklist should take preference. If there is a URL in blacklist, it should not fall back to the other policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Security_Intelligence_Blacklisting.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Did you make sure that all the policies were deployed before generating the result. Also, please check if the SI blacklist was added in the same ACP rule. Because rules are matched in top-down order, if the top rule matches IPS policy and a below rule has SI blacklist option added, the top rule would be preferred.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/firepower-module-user-guide/asa-firepower-module-user-guide-v541/AC-Getting-Started.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-AJ&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 18:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039090#M135859</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-05-04T18:58:07Z</dc:date>
    </item>
    <item>
      <title>I believe Security</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039091#M135865</link>
      <description>&lt;P&gt;I believe Security Intelligence customization only applies to sites and addresses that are included in the SI feed from Cisco Talos.&lt;/P&gt;
&lt;P&gt;If you want to blacklist a general URL, you should do it in an ACP rule under the URL tab and not under SI.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 05:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039091#M135865</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-05T05:06:08Z</dc:date>
    </item>
    <item>
      <title>I just tested in lab and it</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039092#M135868</link>
      <description>&lt;P&gt;I just tested in lab and it worked as expected. I created a list(created a notepad with cisco.com as URL) under SI. Then called that URL under blacklist under ACP SI option.&lt;/P&gt;
&lt;P&gt;cisco.com was allowed earlier and as soon as I used SI blacklist option for the list created earlier, it got blocked. And I also see under 'Security Intelligence Events'.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That means that SI should be preferred when it comes to blacklist. Ofcourse for whitelist URL, it will make it go through other ACP rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you need any of the screenshots from my lab.&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-AJ&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 15:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039092#M135868</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-05-05T15:44:57Z</dc:date>
    </item>
    <item>
      <title>Thanks Ajay.</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039093#M135872</link>
      <description>&lt;P&gt;Thanks Ajay.&lt;/P&gt;
&lt;P&gt;I thought I had seen something contrary to that at a customer (with whitelist instead) but I didn't capture the data to prove it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 16:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-url-blacklist/m-p/3039093#M135872</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-05T16:44:49Z</dc:date>
    </item>
  </channel>
</rss>

