<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP SSL decryption in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3885712#M30322</link>
    <description>&lt;P&gt;Hmm SSL decryption definitely takes place prior to File analysis in the order of operations.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share a screenshot of your relevant ACP rule and associated file and SSL policies?&lt;/P&gt;
&lt;P&gt;I wonder if you are hitting a bug. What Firepower version are you running by the way?&lt;/P&gt;
&lt;P&gt;You may want to open a TAC case on this as it seems you have the right elements in place to make it work.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jul 2019 03:40:21 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-07-07T03:40:21Z</dc:date>
    <item>
      <title>AMP SSL decryption</title>
      <link>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3884483#M30267</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have AMP for network on Firepower 2130, have configured file policy etc and have been using this site to test&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.eicar.org/?page_id=3950" target="_blank"&gt;https://www.eicar.org/?page_id=3950&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Http request are blocked by AMP, however https are not, we then configured ssl decryption, import certificate etc however it still doesnt work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or guide would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 05:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3884483#M30267</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2019-07-04T05:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: AMP SSL decryption</title>
      <link>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3884836#M30287</link>
      <description>&lt;P&gt;Have you confirmed your SSL decryption policy is working for the target page?&lt;/P&gt;
&lt;P&gt;That said, decrypting SSL/TLS en masse to protect against malware is generally a dead end exercise. It's much more effective to protect on the endpoints using something like Cisco AMP for Endpoints.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3884836#M30287</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-04T14:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: AMP SSL decryption</title>
      <link>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3885056#M30306</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, decryption works, i do get the page loaded with the certificate ,when i do http download it block the files, however for https it doesnt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We already got AMP for network, so i guess we have to make it work and maybe later migrate to Endpoint ones.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 04:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3885056#M30306</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2019-07-05T04:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: AMP SSL decryption</title>
      <link>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3885712#M30322</link>
      <description>&lt;P&gt;Hmm SSL decryption definitely takes place prior to File analysis in the order of operations.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you share a screenshot of your relevant ACP rule and associated file and SSL policies?&lt;/P&gt;
&lt;P&gt;I wonder if you are hitting a bug. What Firepower version are you running by the way?&lt;/P&gt;
&lt;P&gt;You may want to open a TAC case on this as it seems you have the right elements in place to make it work.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2019 03:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/amp-ssl-decryption/m-p/3885712#M30322</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-07T03:40:21Z</dc:date>
    </item>
  </channel>
</rss>

