날짜: 08-07-2024 02:58 PM
Hello.
I have a ASA 5525-X with Firepower.
I want to block all traffic into Web Server without some country, but I don't work properly.
My firewall is separated into ASA and Firepower(I'm manage it in FMC).
It is my rule ↓
===============================================================
1. ASA Rule
Any -> Web Server ALLOW
2. Firepower Rule(FMC)
South Korea, Japan -> Web Server ALLOW
Any -> Web Server BLOCK
==============================================================
But Web Server engineer told me that Web Server had a lot of connection log from other countries(US, Italy, Brazil....)
When I tested my rule, I can't open web page in my browser, but Web Server had a connection log(My PC ip / GET / HTTP 1.1 404... something like that)
Therefore, I think firepower blocks web browser connection well, but it can't block tcp handshake and HTTP signal properly.
And I found that firewall pass a tcp handshake and http signal packets in firewall packet capture.
I have to block traffic from hunreds coutries, so I can't make a block rule manually.
I tried to change action to 'block with reset', It didn't work.
Can you give me some advice?
해결되었습니다! 솔루션으로 이동.
날짜: 08-08-2024 03:55 PM
I found why I had a problem.
You can refer comment by John Telford in the link.
FirePOWER Geo Blocking이 작동하지 않음 - Cisco 커뮤니티
날짜: 08-08-2024 03:55 PM
I found why I had a problem.
You can refer comment by John Telford in the link.
FirePOWER Geo Blocking이 작동하지 않음 - Cisco 커뮤니티
새로운 아이디어를 발견하고 저장하세요. 전문가 답변, 단계별 가이드, 최근 주제 등 다양한 내용을 확인해 보세요.
처음이신가요? 아래 팁들을 확인해 보세요. 시스코 커뮤니티 사용하기 새 멤버 가이드