cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1293
Views
10
Helpful
4
Replies

FMC tags valid URLs into Spam, Exploits or Malicious Sites

kish02
Level 1
Level 1

Hi,

Outbound traffic to the internet on our network are being blocked. FMC tags valid URLs into Spam or Malicious Sites or Exploits.

Im using FMC 7.0.1 (build 84) and FTD Version 7.0.1. Any idea? Thanks.

Sample logs

fmc logs.jpg

1 Accepted Solution

Accepted Solutions

Jose-Net
Level 1
Level 1

Seems a problem with Snortv3 as per bug https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa85492

Ive reverted to Snortv2 and seems to have fixed the problem.

View solution in original post

4 Replies 4

marce1000
VIP
VIP

 

 - Check the URL filtering  policies : https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/url_filtering.html

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

brewnet84
Level 1
Level 1

brewnet84_0-1663296407487.png

I am seeing the same thing running FTD 7.0.4 (build 55) and FMC of same version. I did a pending deployment and despite no changes actual deployed the categories flipped back and traffic started passing. I had been running these versions without issue for almost a week. The exact time I experienced this is 9/14 2pm - 7pm CST.

After

brewnet84_1-1663296608627.png

 

Jose-Net
Level 1
Level 1

Seems a problem with Snortv3 as per bug https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa85492

Ive reverted to Snortv2 and seems to have fixed the problem.

Hi Sir, In my situation i can revert to Snort 2 but i will also face the same problem with High Memory Utilization-Snort, that is the main reason why i upgraded to Snort 3. I have reached to TAC already and they suggested to upgrade to FMC and FTD 7.0.5. 

https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/bugs.html

Have you tried or experienced the 7.0.5? or anyone here experienced it? need some feedback on this version.

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card