12-20-2022 05:30 AM
We have a Cisco FirePower FTD 2140. When I go to MONITOR-EVENTS, I'd like to see the "ORIGINAL CLIENT COUNTRY AND CONTINENT" within the filtered session. Presently, it is blank, as if it does not know or there is a setting missing somewhere to allow me to see that.
Does anyone have the steps or the commands/configuration to allow me to see what country originates the potential attack/connection?
Thank you!
Dave
12-20-2022 05:44 AM
It looks like you are using Firepower Device Manager. Can you verify that you have a current geolocation database installed?
12-20-2022 06:18 AM
hi Marvin,
Yes, we have the latest Geolocation database installed. Everything is fully licensed, as well.
-Dave
12-20-2022 06:44 AM
In that case, you may be hitting a bug. If you are already running 7.0.5 or 7.2.2 (e.g., the current latest versions for that platform) then I would recommend opening a TAC case.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide