07-06-2021 10:59 AM
Hi
In ASA we can add a Global ACL which is applied to all interfaces is there a way to do this for FTD using FMC please.??
Thanks
07-06-2021 11:02 AM
In the Access Control Policy (ACP), just create a rule and do not define a security zone (which references the interfaces). That way the rule will apply to any interface, the source/destination networks will control the traffic.
07-06-2021 11:08 AM
Hi Rob
So are you meaning a rule in the mandatory section ??
Thanks
07-06-2021 11:11 AM
Hi@benolyndav No, it doesn't necessarily matter.
07-06-2021 11:32 AM
Hi Rob
Not sure I understand we have 7 sub-interfaces so where would I apply an acl to cover all of these interfaces ??
Thanks
07-06-2021 11:38 AM
Hi @benolyndav
When you create an ACP rule you can define source/destination networks and source/destination zones. The interfaces are usually assigned to a zone. What I was suggested was, you could not define the zones, which would mean "any" zone would be permitted. Therefore you control the traffic in that ACP rule by defining the source networks, which could be any of your sub-interface networks.
07-06-2021 01:19 PM
Hi Rob
That dosent work
so I just picked a interface and created the ACP rule and didnt define zones but used a subnet from another interface and its allowed to the destination I was trying to block,? any suggestions
Result:
input-interface: INSIDE_FRH
input-status: up
input-line-status: up
output-interface: INTERNET
output-status: up
output-line-status: up
Action: allow
07-06-2021 01:23 PM
The rule order is obviously important, if you've a rule above the block rule you create that permits traffic then it would be allowed.
Can you provide the full output of packet-tracer? And a screenshot of the ACP rule?
07-06-2021 01:28 PM
Hi Rob
Ill get that info to you and appreciated as always, I have a funny feeling about some of these url objects I'm sure they are allowing anything, have you seen anything like this.??
Thanks
07-06-2021 01:43 PM
I wasn't expacting for you to be using URL objects, best I see the screenshot of the rules.
It could be you've another rule that permits http/https that is permits the traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide