10-12-2020 01:52 AM
After receiving some user reports, apparently all Firepower rules are getting ignored in my ASA-5508X.
I was unable to find what is wrong.
Nothing related to Firepower was recently modified.
The SFR policy is the same and enabled. It matches all LAN segments towards any IP.
But Access Control Policy seems to be completely ignored/bypassed.
Using the packet tracer shows that any IP that suppose to be blocked in the ACP goes through without any problem.
How can I properly identify the problem ?
10-12-2020 02:19 AM
Well, packet tracer will only provide the result of the ASA verdict of the traffic and does not include what Firepower will do to the traffic. If you jump to the Firepower CLI and issue the command system support diagnostic-cli, enter the client IP and leave everything else blank, and then run a test. What rule are you hitting. If you se no traffic at all, then traffic is not being redirected to Firepower.
10-12-2020 02:25 AM
Update:
Apparently this is a problem with some objects suddenly missing from the main network objects group.
This is fixable, so it was not a serious issue.
10-12-2020 02:41 AM
Objects that suddenly go missing should not happen. If this continues, I suggest opening a TAC case as this sounds a lot like a bug.
10-12-2020 02:33 AM
I think Marius meant to say system support firewall-engine-debug command to capture the traffic subnet to the ACP. Check if snort is engine is running, if not, try to restart it with the command pmtool restartbytype snort.
10-12-2020 02:40 AM
D'OH! Correct Aref, I meant firewall-engine-debug.
10-12-2020 04:10 AM
Thanks for the feedback.
The last serious problem I encountered was licenses suddenly not correctly detected witch of course caused lack of certain licensed functionality.
I will follow closely to see if similar anomalies occur.
10-12-2020 06:35 AM - edited 10-12-2020 06:35 AM
What version of ASA/SFR are you running?
10-13-2020 03:24 AM
Cisco Adaptive Security Appliance Software Version 9.8(2)
Firepower Extensible Operating System Version 2.2(2.52)
Device Manager Version 7.13(1)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide