11-17-2020 01:17 PM
Hello, I am wanting to set an access rule in my default policy that blocks traffic from certain geolocations. If I block traffic sourced by these geolocations to "any" will it drop web traffic initiated by my internal users? I know that returning traffic that is initiated from inside the network will normally be allowed but how will Firepower handle web traffic from my users destined to websites in these countries? Thank-you!
Solved! Go to Solution.
11-17-2020 02:06 PM
A L3 access control is applied on the initial SYN packet of a brand new session; your return traffic is a SYN+ACK packet on an existing session, so no, the return traffic won't be dropped. For you to block, you need to place a restriction using these geolocations as "destination", which will match a SYN packet of a brand new session from your internal users.
11-17-2020 02:06 PM
A L3 access control is applied on the initial SYN packet of a brand new session; your return traffic is a SYN+ACK packet on an existing session, so no, the return traffic won't be dropped. For you to block, you need to place a restriction using these geolocations as "destination", which will match a SYN packet of a brand new session from your internal users.
11-17-2020 03:50 PM
Thank you. For now just want to block inbound but will eventually block outbound to prevent C2 to these locations so it sounds like just from source will work for now!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide