06-08-2015 06:10 AM - edited 03-10-2019 06:23 AM
Cheers
06-10-2015 08:56 AM
The botnet license is made redundant when you have a licensed FirePOWER module and apply an access policy blocking Botnet CnC connections etc.
The only reason I've seen customers use both is to satisfy an auditor who's interested in checking the box that says "is botnet filter installed" and won't listen to the explanation that the FirePOWER module accomplishes this function more thoroughly.
06-11-2015 02:40 AM
Hi Marvin
I was hoping that you would reply as you seem to be the main man when it comes to firepower.
My customer will do a little cart wheel as they can knock the botnet off next years budget for the 5525X's we have to upgrade.
Thankyou!
03-18-2016 10:06 AM
On the same note, is it possible to have a trial of the botnet license while in the process to purchase the license ?
03-18-2016 11:25 AM
With Firepower, I see how 'known malware/botnet' sites can be blocked via URL filtering, as destination addresses.
But how about the case when one is trying to block known malware/botnet sites, as source addresses? I do not see where this can be configured within Firepower.
However, I believe that the botnet license does offer this functionality. Is my understanding correct?
Thank you.
03-18-2016 07:30 PM
You're correct that the URL Filtering policy is used for connections initiated from the inside.
However if you include the Botnet connections in your Access Policy it should address the concern. While in the Intrusion Policy Screen, select Rules in the left pane. When you select rule, you will see numerous categories. Select Rules in the left pane. When you select rule, you will see numerous categories and rules. On the Rules page, type malware into the filter and hit return. The specific rules for Malware should appear. Select the checkbox next to GID to select all malware rules.
Select the Rule State drop-down and choose Drop and Generate events.
You're correct that the URL Filtering policy is used for connections initiated from the inside.
03-18-2016 08:55 PM
So you are saying to address blocking bad IPs as source address is accomplished w/ an intrusion policy? I thought the old botnet license functioned differently? Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide