cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
571
Views
0
Helpful
3
Replies

Cisco FTD Block Encrypted Archive failed

adnanbiek1
Level 1
Level 1

Hi everyone.

I have problem with cisco FTD when i want to block encrypted or password archive files like RAR or ZIP.

I have configured FTD to block encrypted archive in AMP(File) Policy and attached to ACP but not working. all encrypted archives will pass through firewall. blocking file format in working. for example, when I block RAR file, it will be blocked but for encrypted not working.

thank so much for any advice or help through solving my problem.

3 Replies 3

marce1000
VIP
VIP

 

 -  Make sure that you have enabled the "Inspect Archive Files" option in the Advanced tab of the AMP(File) Policy. This option must be enabled in order for the firewall to inspect encrypted archives.

Make sure that you have selected the "Block encrypted and uninspectable archive files" option in the Advanced tab of the AMP(File) Policy. This option will cause the firewall to block all encrypted archives, even if they cannot be fully inspected.

Make sure that the AMP(File) Policy is attached to the appropriate Access Control Policy (ACP). The ACP must be applied to the traffic that is carrying the encrypted archives.

Make sure that the firewall has the necessary licenses for malware protection. Malware protection is required to block encrypted archives.

If you have checked all of these things and you are still having problems blocking encrypted archives, you can contact Cisco support for further assistance.

Here are some additional things to keep in mind when blocking encrypted archives on Cisco FTD:

Encrypted archives can be large, so it may take some time for the firewall to inspect them.

The firewall may not be able to fully inspect all encrypted archives. In these cases, the firewall will block the archive even if it does not contain malware.

You can use the "Store Files" option in the AMP(File) Policy to store encrypted archives on the firewall for further analysis. This can be helpful if you need to investigate a suspicious archive.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '