취소
다음에 대한 결과 표시 
다음에 대한 검색 
다음을 의미합니까? 
cancel
345
VIEWS
1
Helpful
1
답글

Firepower block rule doesn't work proprely.

GaeMi
Level 1
Level 1

Hello.

I have a ASA 5525-X with Firepower.

I want to block all traffic into Web Server without some country, but I don't work properly.

My firewall is separated into ASA and Firepower(I'm manage it in FMC).

It is my rule ↓

===============================================================

1. ASA Rule

Any -> Web Server ALLOW

 

2. Firepower Rule(FMC)

South Korea, Japan -> Web Server ALLOW

Any -> Web Server BLOCK

==============================================================

But Web Server engineer told me that Web Server had a lot of connection log from other countries(US, Italy, Brazil....)

When I tested my rule, I can't open web page in my browser, but Web Server had a connection log(My PC ip / GET / HTTP 1.1 404... something like that)

 

Therefore, I think firepower blocks web browser connection well, but it can't block tcp handshake and HTTP signal properly.

And I found that firewall pass a tcp handshake and http signal packets in firewall packet capture.

I have to block traffic from hunreds coutries, so I can't make a block rule manually.

I tried to change action to 'block with reset', It didn't work.

Can you give me some advice?

1 채택된 솔루션

채택된 솔루션

GaeMi
Level 1
Level 1

I found why I had a problem.

You can refer comment by John Telford in the link.

FirePOWER Geo Blocking이 작동하지 않음 - Cisco 커뮤니티

 

 

원본 게시물의 솔루션 보기

1 응답 1

GaeMi
Level 1
Level 1

I found why I had a problem.

You can refer comment by John Telford in the link.

FirePOWER Geo Blocking이 작동하지 않음 - Cisco 커뮤니티

 

 

빠른 링크