02-21-2019 11:34 AM
In Firepower I have an Access policy that blocks VPN Clients. There are about 50 VPN clients that cisco has labeled. Anyway I had a user group that accesses a third-party website that uses Duo Mobility. Cisco firepower sees this a "VPN" and blocks it. Does anyone know how to fix this?
Solved! Go to Solution.
02-21-2019 02:15 PM
Unfortunately, there is no easy way to fix faulty application detection by the Firepower. I have had many instances were legitimate sites were being detected as VPN's or proxies by Firepower. So much so, that we had to remove the application category and only add individual VPN applications that did not cause a problem.
I would create a temporary allow rule for source ip addresses to bypass the VPN block rule. You can add the site URL in the allow ACL conditions. Also, look for the name of the site inside the SSL certificate that it presents, sometimes the Firepower classifies the website based on that information too.
You should open a TAC case and have them open a bug. The more the cases opened for this, the better chance that it gets resolved.
02-21-2019 02:15 PM
Unfortunately, there is no easy way to fix faulty application detection by the Firepower. I have had many instances were legitimate sites were being detected as VPN's or proxies by Firepower. So much so, that we had to remove the application category and only add individual VPN applications that did not cause a problem.
I would create a temporary allow rule for source ip addresses to bypass the VPN block rule. You can add the site URL in the allow ACL conditions. Also, look for the name of the site inside the SSL certificate that it presents, sometimes the Firepower classifies the website based on that information too.
You should open a TAC case and have them open a bug. The more the cases opened for this, the better chance that it gets resolved.
02-22-2019 03:14 AM
You can either bypass the inspection per Source IP or add whitelist the known ("offending" for Cisco) URLs
02-25-2019 06:08 AM
Rahul thank you for your help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide