<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc/m-p/3021122#M145977</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have Cisco ASA 5515-X devices with Firepower services managed by FMC 6.1.0.2 and TAC (IPS and URL) licenses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;I have few questions about it:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;-&amp;nbsp; Is it possible to allow&amp;nbsp; specific YouTube channel for a specific group of users, but block all other YouTube streaming for all other users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;-&amp;nbsp; &lt;SPAN style="color: #1f497d;"&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;/SPAN&gt;s it possible to allow specific Facebook page like "&lt;A href="https://www.facebook.com/something.hr/" target="_blank"&gt;https://www.facebook.com/something.hr/&lt;/A&gt;" for a specific group of users but block all other Facebook pages&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;If it is possible can you please explain how to set it up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:01:24 GMT</pubDate>
    <dc:creator>osman.cerkez</dc:creator>
    <dc:date>2019-03-12T09:01:24Z</dc:date>
    <item>
      <title>FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/3021122#M145977</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have Cisco ASA 5515-X devices with Firepower services managed by FMC 6.1.0.2 and TAC (IPS and URL) licenses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;I have few questions about it:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;-&amp;nbsp; Is it possible to allow&amp;nbsp; specific YouTube channel for a specific group of users, but block all other YouTube streaming for all other users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;-&amp;nbsp; &lt;SPAN style="color: #1f497d;"&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;/SPAN&gt;s it possible to allow specific Facebook page like "&lt;A href="https://www.facebook.com/something.hr/" target="_blank"&gt;https://www.facebook.com/something.hr/&lt;/A&gt;" for a specific group of users but block all other Facebook pages&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;If it is possible can you please explain how to set it up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/3021122#M145977</guid>
      <dc:creator>osman.cerkez</dc:creator>
      <dc:date>2019-03-12T09:01:24Z</dc:date>
    </item>
    <item>
      <title>Yes this is possible if your</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/3021123#M145982</link>
      <description>&lt;P&gt;Yes this is possible if your Defence center is integrated / joined with AD. &amp;nbsp;Or you will need to&amp;nbsp;install a user agent on the client that is connect to active directory.&lt;/P&gt;
&lt;P&gt;These links explain how you can create policies based on user identity. &amp;nbsp;Of course if the users have static IPs or are isolated to a spesific subnet then you could just match on the IP or subnet.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html#anc8"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html#anc8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Rules-User.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Rules-User.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2017 23:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/3021123#M145982</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-03-08T23:03:30Z</dc:date>
    </item>
    <item>
      <title>In the Firepower Management</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/3021124#M145986</link>
      <description>&lt;P&gt;In the Firepower Management Center a Realm has been configured and FMC is integrated with AD. Firepower User Agent for AD version 2.3 is installed on domain controler and operating correctly.&lt;/P&gt;
&lt;P&gt;The Identity Policy is configured for passive authentication, set to use the configured Realm and assigned in Access Control Policy and all of these setups works fine. &lt;/P&gt;
&lt;P&gt;I have configured SSL Policy with Decrypt-Resign Action for applications (Youtube and Facebook) and assigned in Access Control Policy &lt;/P&gt;
&lt;P&gt;But I still cannot to configure Access Control Policy with a rule which i can to use for &lt;SPAN&gt;the previously described&lt;/SPAN&gt; case like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;Allow specific YouTube channel like &lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/channel/UCZ2awNGeUbU5xN1hX-PCYpQ"&gt;https://www.youtube.com/channel/UCZ2awNGeUbU5xN1hX-PCYpQ&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;for specific group of users or for all users, but block all other YouTube streaming for all other users&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Allow specific Facebook page, but block all other Facebook pages for all users or group of AD users&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;In the rule of Access Controll Policy which I use for Application control, under Applications filters I Added Youtube and Facebook , and under URLs filters added specific url which I would like to allow but it does not work and next rule with block and reset action for Youtube and Facebook Aplications, block this traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 11:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/3021124#M145986</guid>
      <dc:creator>osman.cerkez</dc:creator>
      <dc:date>2017-03-09T11:00:48Z</dc:date>
    </item>
    <item>
      <title>I believe you are configuring</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/3021125#M145990</link>
      <description>&lt;P&gt;I believe you are configuring the rule incorrectly. &amp;nbsp;do not add Application filters just the URL filter that you would like to permit. &amp;nbsp;Then test.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 17:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/3021125#M145990</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-03-09T17:16:04Z</dc:date>
    </item>
  </channel>
</rss>

