<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Right after posting I came in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943736#M43530</link>
    <description>&lt;P&gt;Right after posting I came across the following URL which has proved useful.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote-SourceFire-00.html&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have a reasonably accurate time of when traffic seems to have stopped flowing. Would anyone be able to guide me on which log files may prove most useful to inspect.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 15 Oct 2016 19:58:40 GMT</pubDate>
    <dc:creator>darreng</dc:creator>
    <dc:date>2016-10-15T19:58:40Z</dc:date>
    <item>
      <title>Firepower Blocking Traffic Randomly ?</title>
      <link>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943735#M43529</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am running a ASA5525X Active / Standby pair of Firewalls with FIrewpower 6.0.1.1. Recently I have experienced an issue where at random intervals the active Firewall seems to stop passing traffic. When the problem occurs we know that:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The Firewall Inside interface is accessible from a host on the inside&lt;/P&gt;
&lt;P&gt;I can VPN into the outside interface (and strangely authenticate to my AD Server on the inside)&lt;/P&gt;
&lt;P&gt;I cannot ping any hosts on the inside via my VPN connection even though the VPN has authenticated&lt;/P&gt;
&lt;P&gt;If I fail over the Firewall to the secondary it begins to work once again e.g. pings etc are fine&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Minutes ago the issue re-occurred and failing back from the Secondary (Active) to the Primary (Backup) once again resolved the issue. We believe that have ruled out the internal network via various tests / log checks etc. We haven't ruled out that the IPS.&lt;/P&gt;
&lt;P&gt;My plan was to disable the IPS when the error next occurred to prove or disprove my theory. Unfortunately another Engineer beat me to it and failed over the Firewalls before I could check so I'm again scratching my head as to how to prove it is / isn't Firepower related. My question is simple:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1) Has anyone experienced this on Firewpower&lt;/P&gt;
&lt;P&gt;2) I understand I can send the logs off the Sourcefire IPS to a SFTP server for inspection. Are there any other useful troubleshooting tips / links anyone has to allow me to investigate this from the Sourcefire CLI&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm currently going through the Sourcefire Management Console session events to try to determine the series of events but I'm working on the fact logging on the Firewpower module will offer me more detail.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943735#M43529</guid>
      <dc:creator>darreng</dc:creator>
      <dc:date>2019-03-10T13:41:50Z</dc:date>
    </item>
    <item>
      <title>Right after posting I came</title>
      <link>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943736#M43530</link>
      <description>&lt;P&gt;Right after posting I came across the following URL which has proved useful.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/sourcefire-defense-center/117663-technote-SourceFire-00.html&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have a reasonably accurate time of when traffic seems to have stopped flowing. Would anyone be able to guide me on which log files may prove most useful to inspect.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Oct 2016 19:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943736#M43530</guid>
      <dc:creator>darreng</dc:creator>
      <dc:date>2016-10-15T19:58:40Z</dc:date>
    </item>
    <item>
      <title>Maybe you are hitting the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943737#M43531</link>
      <description>&lt;P&gt;Maybe you are hitting the following bug:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CSCup37416&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2016 06:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943737#M43531</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2016-10-16T06:48:24Z</dc:date>
    </item>
    <item>
      <title>Hi Massimo,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943738#M43532</link>
      <description>&lt;P&gt;Hi Massimo,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your kind response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue isn't just related to VPN's. When the error occurs normal traffic such as outbound WWW or HTTPS cannot pass from inside to outside. I also loose email until I fail over the Firewalls and then everything appears to come back.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have a router on an inside interface that uses a DMVPN to a remote site. The GRE tunnel and EIGRP relationship break also.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Darren&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2016 07:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-blocking-traffic-randomly/m-p/2943738#M43532</guid>
      <dc:creator>darreng</dc:creator>
      <dc:date>2016-10-16T07:16:23Z</dc:date>
    </item>
  </channel>
</rss>

