12-30-2025 03:41 AM
Hello Team,
I am testing a Cisco Firepower 1010 physical appliance running FTD 7.2.5 in standalone mode. The device is currently in Evaluation mode (no licenses applied).
Observed behavior:
Internet traffic works when allowed in Access Control.
I have verified:
Access Control policies are applied correctly
DNS and HTTP/HTTPS are allowed when configured under ports however doesnt work when allowed under Applications.
Logging is enabled
SSL decryption is disabled
My questions:
Are Malware, URL Filtering, and IPS enforcement disabled by design in Evaluation mode?
Is a valid Malware / URL / Threat license mandatory for:
Malware blocking
URL categorization
Talos reputation verdicts?
Is it expected that all URLs show as Uncategorized without URL license?
Please confirm if this behavior is expected and license-dependent, or if there is any limitation specific to FTD 7.2.5.
Thank you.
Solved! Go to Solution.
01-01-2026 02:53 AM
Thank you for an update. Yes, but before performing content updates or anything make sure NTP is in sync to get all the updates.
12-30-2025 04:22 AM
Hi,
It needs to work, however you need to first perform content updates, for URL and Malware. Also, from device configuration, ensure all licenses are checked.
Thanks,
Cristian.
01-01-2026 02:53 AM
Thank you for an update. Yes, but before performing content updates or anything make sure NTP is in sync to get all the updates.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide