cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1982
Views
5
Helpful
2
Replies

Firepower Module 6.4 - If I block traffic sourced by geolocation will it block returning traffic requested from inside the network?

N3t-Guy
Level 1
Level 1

Hello, I am wanting to set an access rule in my default policy that blocks traffic from certain geolocations. If I block traffic sourced by these geolocations to "any" will it drop web traffic initiated by my internal users? I know that returning traffic that is initiated from inside the network will normally be allowed but how will Firepower handle web traffic from my users destined to websites in these countries? Thank-you!

1 Accepted Solution

Accepted Solutions

HQuest
Level 1
Level 1

A L3 access control is applied on the initial SYN packet of a brand new session; your return traffic is a SYN+ACK packet on an existing session, so no, the return traffic won't be dropped. For you to block, you need to place a restriction using these geolocations as "destination", which will match a SYN packet of a brand new session from your internal users.

View solution in original post

2 Replies 2

HQuest
Level 1
Level 1

A L3 access control is applied on the initial SYN packet of a brand new session; your return traffic is a SYN+ACK packet on an existing session, so no, the return traffic won't be dropped. For you to block, you need to place a restriction using these geolocations as "destination", which will match a SYN packet of a brand new session from your internal users.

Thank you. For now just want to block inbound but will eventually block outbound to prevent C2 to these locations so it sounds like just from source will work for now!

Review Cisco Networking for a $25 gift card