<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Application block in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884833#M925441</link>
    <description>&lt;P&gt;If the application is not equal to "facebook", then the new top rule will not match and the subsequent rules will be evaluated.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 14:33:04 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-07-04T14:33:04Z</dc:date>
    <item>
      <title>FTD Application block</title>
      <link>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884792#M925439</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a FTD version 6.2.3.13 and an ACP containing 1000's of rules and hundred of zones.&lt;/P&gt;&lt;P&gt;I want to block an application such as facebook for the entire environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I create a rule at the&lt;EM&gt;&lt;STRONG&gt; &lt;U&gt;top&lt;/U&gt; &lt;/STRONG&gt;&lt;/EM&gt;of the ACP policy and set the zone and network as "any" with application "facebook " and action as "block". This would cause all the other 1000s rule below that rule to be useless, where ALL the traffic other than facebook will be matching this rule and this traffic would be allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is how to block application X globally (for any network src and dst) in an ACP with causing the above behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:16:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884792#M925439</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2020-02-21T17:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Application block</title>
      <link>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884796#M925440</link>
      <description>&lt;P&gt;Correction:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The question is how to block application X globally (for any network src and dst) in an ACP ""without"" causing the above behavior?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 13:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884796#M925440</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2019-07-04T13:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Application block</title>
      <link>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884833#M925441</link>
      <description>&lt;P&gt;If the application is not equal to "facebook", then the new top rule will not match and the subsequent rules will be evaluated.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-application-block/m-p/3884833#M925441</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-04T14:33:04Z</dc:date>
    </item>
  </channel>
</rss>

