<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm kinda curious about this in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630256#M45073</link>
    <description>&lt;P&gt;I'm kinda curious about this too as I see some events with 'Malware Cloud Lookup' and 'Cloud Lookup Timeout'&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2015 14:02:55 GMT</pubDate>
    <dc:creator>dney</dc:creator>
    <dc:date>2015-06-10T14:02:55Z</dc:date>
    <item>
      <title>Sourcefire - Malware cloud lookup fails with 'cloud lookup timeout'</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630255#M45070</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am performing malware clould lookup using FirePOWER on ASA. I see the file event when I transfer the file, but the FireSIGHT is unable to &amp;nbsp;submit the file SHA-256&amp;nbsp;for cloud lookup. It times out. The FireSIGHT management IP is able to access the Internet.&lt;/P&gt;&lt;P&gt;Does the malware cloud lookup need some subscription for it to work? I am running this in a lab setup with malware license.&lt;/P&gt;&lt;P&gt;What could be the reasons for this lookup failure. Due to this, the file disposition is 'unavailable'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another related question. If my file policy action is to BlockMalware, and if the file disposition comes as unknown or unavailable, will the file be transferred or blocked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any help.&lt;/P&gt;&lt;P&gt;regds,&lt;/P&gt;&lt;P&gt;Mohan Muthu&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630255#M45070</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2019-03-10T13:20:07Z</dc:date>
    </item>
    <item>
      <title>I'm kinda curious about this</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630256#M45073</link>
      <description>&lt;P&gt;I'm kinda curious about this too as I see some events with 'Malware Cloud Lookup' and 'Cloud Lookup Timeout'&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 14:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630256#M45073</guid>
      <dc:creator>dney</dc:creator>
      <dc:date>2015-06-10T14:02:55Z</dc:date>
    </item>
    <item>
      <title>Mohan,Do you have you File</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630257#M45074</link>
      <description>&lt;P&gt;Mohan,&lt;/P&gt;&lt;P&gt;Do you have you File policy configured for "Malware Cloud Lookup" or for "Dynamic Analysis?" &amp;nbsp;Or are you simply selecting a file and submitting it for analysis manually? &amp;nbsp;This would help in troubleshooting your issue. &amp;nbsp;Also, can you perform updates from the FireSight Management center? &amp;nbsp;Just curious if this gets out to the Internet. &amp;nbsp;The only subscription you need for Cloud lookups is a Protect and Control license, AMP and FireSight License.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2015 01:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630257#M45074</guid>
      <dc:creator>steveahughes</dc:creator>
      <dc:date>2015-07-22T01:58:15Z</dc:date>
    </item>
    <item>
      <title>I opened a TAC case on this.</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630258#M45078</link>
      <description>&lt;P&gt;I was having this issue on an ASA5506 that wasn't using Firesight Management.&lt;/P&gt;
&lt;P&gt;I opened a TAC case on this.&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt; Please have&lt;SPAN style="color: #000000;"&gt; a look at Bug -&amp;nbsp;&lt;FONT color="#000274" face="Calibri,sans-serif"&gt;CSCze95695&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif;"&gt;&lt;FONT color="#000274" face="Calibri,sans-serif"&gt;TAC provided the following workaround.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="color: #000000; font-family: arial, helvetica, sans-serif;"&gt;&lt;FONT color="#000274" face="Calibri,sans-serif"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;&lt;SPAN style="color: #000000;"&gt;Please note that this only affects Kenton boxes&lt;/SPAN&gt; which are managed on-box. Workaround is to run the following command.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;$ touch /etc/sf/network_malware_use_legacy.enable &amp;amp;&amp;amp; pmtool restartbyid SFDataCorrelator&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;This work around will use port 32137 rather than 443 for malware cloud lookups.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;If you would like to reverse it in the future, Please run this command.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;$ rm /etc/sf/network_malware_use_legacy.enable &amp;amp;&amp;amp; pmtool restartbyid SFDataCorrelator&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 20:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-malware-cloud-lookup-fails-with-cloud-lookup-timeout/m-p/2630258#M45078</guid>
      <dc:creator>jonwoloshyn</dc:creator>
      <dc:date>2015-10-29T20:28:08Z</dc:date>
    </item>
  </channel>
</rss>

