02-03-2016 03:57 AM - edited 02-21-2020 05:43 AM
Hardware- Cisco ASA5510-
Version - 9.0
Solved! Go to Solution.
02-03-2016 07:31 AM
No.
This sort of functionality is offered in the newer models (ASA 5500-X series) when you add the FirePOWER service modules with their associated license(s).
They can download and auto update a Geolocation database which you can use in your access policy.
02-03-2016 07:31 AM
No.
This sort of functionality is offered in the newer models (ASA 5500-X series) when you add the FirePOWER service modules with their associated license(s).
They can download and auto update a Geolocation database which you can use in your access policy.
02-04-2016 02:36 AM
Hi Marvin,
Thanks!!,
So do i need to purchase license as well along with firewall ?
02-04-2016 06:42 AM
I believe if all you want to do is create a policy to allow or block certain countries, you can use the free Control license.
However, if you're going to the effort to configure and use the FirePOWER module NGIPS, it makes sense to buy at least the IPS license.
Available licenses are IPS (Protect), URL Filtering and Malware (Advanced Malware Protection or AMP).
02-05-2016 07:34 AM
Hi Marvin,
Thanks for your response.
Regards,
Nilesh
02-05-2016 07:36 AM
You're welcome.
Please mark your question as answered if it has been.
10-02-2017 07:58 AM
Is it possible to use firepower module to block , say China using geo location but allow certain IPs from that country.
08-24-2018 08:59 AM
Have you got any response for this?
10-05-2022 08:23 AM
I dont think this ever worked
10-05-2022 08:38 AM
You can insert rule(s) with PERMIT action above the rule for geoblocking the entire country. The first match (for action other than monitor) from the top down stops the processing of the rest of rules in the access control policy.
10-24-2022 01:59 AM
Hi
Is there a way to restrict AnyConnect users from certain countries? I have ASA's on Firepower 1140's.
Regards, Justin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide