cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
773
Views
1
Helpful
5
Replies

Check if an IP address would be blocked in FMC

ryders1
Beginner
Beginner

Does anyone know if it would be possible to enter an IP somewhere in FMC and see how it would react to it? I am wondering if it is possible to simulate a user accessing an IP address or address range. I have been given a list of IPs from a vendor that we are supposed to whitelist. However, if we already allow access I don't want to make an access policy rule to allow them. Specifically I would like to enter an address like 8.8.8.8 and see if firepower would block or allow that address and then see why it was blocked or not.

4 Accepted Solutions

Accepted Solutions

@ryders1 you can run packet-tracer to simulate the traffic flow to the destination, this will tell you if it is allowed or blocked.

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212474-working-with-firepower-threat-defense-f.html

 

View solution in original post