cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
696
Views
5
Helpful
1
Replies

Firepower Devices and DNS

Hello, 

 

I would like to ask if the FTD needs to access the internet DNS. 

I have high availability FTD 2110 managed by FMC and I see in the events that there are several queries to DNS that are blocked. 

DNS isn't managed by FMC? Do the FTDs have any reason to access DNS?

 

Thanks and regards, 

Konstantinos

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

FTD devices may be doing some lookups with cloud-based services like AMP for file policies. That would require DNS.

This and a few other uses are noted here:

https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/security_internet_access_and_communication_ports.html

Review Cisco Networking for a $25 gift card