cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
354
Views
1
Helpful
3
Replies

Firepower Traffic Blocked with Default Action but same permitted other

Danny Dulin
Level 1
Level 1
We are experiencing an issue where a packet is blocked by a Default Action but previous and subsequent traffic between the same src and dst is permitted. The blocked traffic event has no Ingress or Egress interface.
 
The traffic has ACP that permits Any VLAN to ANY network on 443.
 
NOTE: There are other similar events on different ports.
3 Replies 3

Can you more elaborate 

MHM

Here's an example.

I have an ACP that permits Any -> Any Port 443.

I see connection events permitting 10.5.5.5 -> 192.168.5.155 port 443

I also see connection events blocking 10.5.5.5 -> 192.168.5.155 port 443

The blocked connection events have no ingress or egress data.

The blocked event identifies "Default Action" as the ACP rule the FW rule that decided the action.

There's no reason for the block other than the device could not find a rule to match the traffic, but the reality is there is a rule.

 

I send to you PM please check it 

MHM

Review Cisco Networking for a $25 gift card