cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
573
Views
0
Helpful
1
Replies

Question: On FMC Access Control Rule - Is Source and Destination Networks an OR Operator?

Lucas Phelps
Level 5
Level 5

I've created a Geolocation list of countries I want to block.   Do I put it in my Access Control list as the destination network, source network, or both?

 

If I put the geo list in both, does the FMC interpret it as an AND operator?  Meaning the traffic has to be sourced from and destined to the bad countries?   Or is it one or the other?

 

Thank you!

1 Reply 1

mikael.lahtela
Level 4
Level 4
Hi,

The AP rule is "and" rule, so if everything matches in the rule it will use that rule.
If I understand your question correctly if you have blacklist source geo and blacklist destination geo the traffic will block between blacklisted countries, but not if one of them are "white".

br, Micke
Review Cisco Networking products for a $25 gift card