01-31-2017 12:51 PM - edited 03-12-2019 01:51 AM
Is there a way to see what country the firepower system thinks an IP is from?
I get that I can create a rule and test whether the packet is allowed or denied - but I'd like more feedback from firepower regarding what country it believes the IP is from.
Thanks!
02-19-2017 11:12 PM
Unfortunately there is not at the moment. In Firepower 6.2 we are able to lookup the URL category, but I have not seen anything about geolocation lookups yet. I hope for being able to do this in the future. :)
02-20-2017 02:09 AM
Realy?
It may be, that I misundestand the question... but, for example, in Analysis -> Contex Explorer I can see Geolocation information for connections. The same for Analysis -> Connection Events. Please, see the attaches.
Also, we need to update periodically geolocation base on FMC in System -> Updates -> Geolocation Updates.
02-20-2017 02:14 AM
I might have misunderstood the question as well.
What I mean is that it is not possible to test the geolocation before actually creating a rule to either allow or block.
But it is definitely possible to see the history of connection events, and where the geolocation resolved it to be.
02-20-2017 02:39 AM
Got it, thanks for update. You meant somethink like Bulk URL lookup feature, but for geolocation.
02-20-2017 02:41 AM
That was my thought. But now I am not certain that I understand the question from the thread starter.
02-22-2017 08:03 AM
Yes. The idea is to evaluate IPs prior to rule creation and without logged traffic.
Mostly this is to evaluate IP blocks which have been assigned to the customer prior to implementing, especially where existing geographic based rules already exist.
02-23-2017 08:50 AM
Cisco added this feature in FMC 6.1:
Analysis > Lookup > Geolocation
You can enter up to 250 IP addresses and get back the Country, Country Code and Continent.
02-23-2017 08:54 AM
Oh my. You are right.
Why did I not see that!
http://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/using_lookups.html#id_15479
02-23-2017 09:37 AM
I had forgotten it too Dennis.
Earlier I was re-reading a presentation (BRKSEC-2050 from Cisco Live US 2016), saw the feature mentioned and was reminded of this thread.
02-20-2017 10:56 AM
Please see this post
https://supportforums.cisco.com/discussion/12716991/can-i-do-geo-ip-filtering-my-asa-5520
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide