<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD user and url rules not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-user-and-url-rules-not-working/m-p/3728455#M985593</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a strange issue with a FTD running latest 6.2.3 code. When using rules that requires inspection like user or url rules, the FTD will match on those rules even if it shouldn't be a match. For example I am using an Identify policy and create rules based on users and groups from Active Directory. If I create a rule that only should match on users in group A, it will match on all users no matter which group they belong to. In fact that rule will match even if the user doesn't belong to a user group at all. Same with url rules. It will match on any url rules no matter which categories I choose.&amp;nbsp; Anyone have a clue on why this happen and how I can troubleshoot those inspection rules? Is it possible to see hitcounts from snort rules?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:22:40 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2020-02-21T16:22:40Z</dc:date>
    <item>
      <title>FTD user and url rules not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-user-and-url-rules-not-working/m-p/3728455#M985593</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a strange issue with a FTD running latest 6.2.3 code. When using rules that requires inspection like user or url rules, the FTD will match on those rules even if it shouldn't be a match. For example I am using an Identify policy and create rules based on users and groups from Active Directory. If I create a rule that only should match on users in group A, it will match on all users no matter which group they belong to. In fact that rule will match even if the user doesn't belong to a user group at all. Same with url rules. It will match on any url rules no matter which categories I choose.&amp;nbsp; Anyone have a clue on why this happen and how I can troubleshoot those inspection rules? Is it possible to see hitcounts from snort rules?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-user-and-url-rules-not-working/m-p/3728455#M985593</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-02-21T16:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD user and url rules not working</title>
      <link>https://community.cisco.com/t5/network-security/ftd-user-and-url-rules-not-working/m-p/3729674#M985594</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do you know that a specific rule is being hit for users not called in that rule config? Do you see events with the source ip/username being seen for a specific group in the 'table view of connection events'.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you show a snippet of the rule you are talking about. Ideally, if there is no match, the default rule is hit, maybe thats where the traffic is going.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 09:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-user-and-url-rules-not-working/m-p/3729674#M985594</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-10-22T09:28:59Z</dc:date>
    </item>
  </channel>
</rss>

