cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
958
Views
0
Helpful
2
Replies

FTD Application block

gaboughanem
Level 1
Level 1

Hello,

 

I have a FTD version 6.2.3.13 and an ACP containing 1000's of rules and hundred of zones.

I want to block an application such as facebook for the entire environment.

 

If I create a rule at the top of the ACP policy and set the zone and network as "any" with application "facebook " and action as "block". This would cause all the other 1000s rule below that rule to be useless, where ALL the traffic other than facebook will be matching this rule and this traffic would be allowed.

 

The question is how to block application X globally (for any network src and dst) in an ACP with causing the above behavior?

 

Regards,

George

2 Replies 2

gaboughanem
Level 1
Level 1

Correction:

The question is how to block application X globally (for any network src and dst) in an ACP ""without"" causing the above behavior?

If the application is not equal to "facebook", then the new top rule will not match and the subsequent rules will be evaluated.

Review Cisco Networking for a $25 gift card