cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
131
Views
2
Helpful
7
Replies

Firepower file inspection/malware detection rule placement

willb1
Level 1
Level 1

I'm confused as to where to place this rule. From my understanding, there should be an allow rule with the File Policy configured to use the associated Malware & File policy. However, the rest of the configuration of that rule is set to allow any any.

There are other allow and block rules in the policy with the policy default action set to block all traffic. The last rule in the ACP is to allow all traffic outbound and inspect.

With that in mind, where should the file inspection policy be placed?

1 Accepted Solution

Accepted Solutions

ccieexpert
Level 3
Level 3

File/malware policy is applied to a regular access control rule .

The most important would be for inbound to oubound rules like users browsing to a website and downloading files etc which can be inspected for malware..

But keep in mind that 90% or above is encrypted, so unless you are doing ssl decryption, the malware inspection will not kick in..

View solution in original post

7 Replies 7

ccieexpert
Level 3
Level 3

File/malware policy is applied to a regular access control rule .

The most important would be for inbound to oubound rules like users browsing to a website and downloading files etc which can be inspected for malware..

But keep in mind that 90% or above is encrypted, so unless you are doing ssl decryption, the malware inspection will not kick in..

Gotcha. Thank you!

do you want other opinion here ?

MHM

Absolutely

Thank you, that's very helpful! I located that PDF and will review it.

you are so welcome 
MHM

Review Cisco Networking for a $25 gift card