cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1583
Views
5
Helpful
2
Replies

Geo Lookup Not Evaluating with Trace

joelbland
Level 1
Level 1

Hello,

 

I'm attempting to validate an incoming content filter using the Trace function before committing the changes to the ESA, however, it appears that it doesn't actually evaluate the country code from the IP address given. However, if I commit the change and review the mail_logs, the ESA matches on the country code.

Example filter:

2018-04-19_9-38-16.png

Trace Information:

IP Address = 178.250.144.155

Senderbase indicates this IP is located in the Netherlands.

(https://talosintelligence.com/reputation_center/lookup?search=178.250.144.155)

 

However, the Trace results do not reflect that:

trace01.png

 

trace02.png

 

While the mail_logs do correctly reflect this, only when the content filter has been committed:

Info: MID123456 Custom Log Entry: Detect-NL-LogEntry detected connection from the Netherlands on IP 178.250.144.155

Should the ESA evaluate the country code in the Trace function?

 

Thanks!

 

 

1 Accepted Solution

Accepted Solutions

Mathew Huynh
Cisco Employee
Cisco Employee
Hello Joelbland,

I don't believe the trace tool currently includes geo-location lookup.
An Enhancement request may be required to be filed for the functionality to be considered.

Regards,
Matthew

View solution in original post

2 Replies 2

Mathew Huynh
Cisco Employee
Cisco Employee
Hello Joelbland,

I don't believe the trace tool currently includes geo-location lookup.
An Enhancement request may be required to be filed for the functionality to be considered.

Regards,
Matthew

Thanks, Mathew. I'll submit a feature request to TAC.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: