FTD 6.1 Application Detector - Not detecting certain connections
Anyone run into issues with FTD, in what appears to be random cases the application detection engine doesn't classify a flow with AVC application protocol / client information?
I have seen it on SYSLOG, NTP, NetBIOS-ssn (SMB [TCP 445]), and other applications. It is not consistent, meaning NTP will be classified correctly for quite a while and then randomly a session will not be. When it is not, there is no Application protocol / client / web application listed in the log entry for that connection.
This is a major issue as I am attempting to use AVC rules, and when the application detection doesn't work correctly the traffic hits the default action policy which is set to deny / block.
TAC suggested changing all the allow rules to log at the end of the connection. They suggested that would provide more accurate logging when the initial packets of an application are not classified at that point. That didn't have a impact and I currently running with a policy that includes temporary port / services rules.
GeneralWhich Cisco Secure products include access to SecureX?What are the SecureX data retention/privacy policies?What is SSE?How can I unlink my smart account from SSE and link it to a new account?Do I have to use the same SSE region as the SecureX regio...
More people are working remotely, and this increases the risk of security breaches and the difficulty in defending remote workers where they work and securing the devices they use.
Learn about Cisco Remote Secure Worker solutions that verify workers, secu...
GeneralWhich Cisco Secure products include access to SecureX?What are the SecureX data retention/privacy policies?What is SSE?How can I unlink my smart account from SSE and link it to a new account?Do I have to use the same SSE region as the Secur...
On December 8, FireEye reported that it had been compromised in a sophisticated supply chain attack: more specifically through the SolarWinds Orion IT monitoring and management software. The attackers leveraged business software updates in order to distr...