- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-14-2023 12:07 AM
Hi All,
I am running FTD2120 pair in HA, software code 7.0.4 with VDB build 371. I noticed that there is increased counters for Malware blocks against Security Intelligence coming from our user base. We have deployed Cisco Umbrella in our environment which has been implemented for past 3 months.
FTD reports that following IP address is blocked 146.112.56.158, reason IP Block, Security Intelligence Category: Malware. At the same time there are loads of connection to the same IP address which goes through no issues, this same IP Block is seen across other IP addresses which belong to OpenDNS.
Any suggestions as to what is happening here and means to resolve it? I could use Prefilter Rule, but this should not be happening in first place.
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-15-2023 04:54 AM
AigarsK,
I see the same behavior on our network running two 9300s in an HA pair. What I believe is happening is the original IP is being passed to OpenDNS and if the site is blocked, the packet coming back has the OpenDNS IP address attached rather than the original IP.
I think we could definitely solve this by running a packet capture to a known blocked site and see if the header is appended.
Donnie
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-15-2023 04:54 AM
AigarsK,
I see the same behavior on our network running two 9300s in an HA pair. What I believe is happening is the original IP is being passed to OpenDNS and if the site is blocked, the packet coming back has the OpenDNS IP address attached rather than the original IP.
I think we could definitely solve this by running a packet capture to a known blocked site and see if the header is appended.
Donnie
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-15-2023 07:43 AM
Hi Donnie,
I think you are right, I just managed to locate IP Block which included the URL, it was also blocked on Umbrella for the same user and source IP.
Would still like to find out how to prevent these double detections/blocks from appearing in FTD as they serve no value to report on.
