cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1693
Views
0
Helpful
3
Replies

How to Limit FMC's access to the internet?

PacketSpartan
Level 1
Level 1

We are currently in the process of filtering and only allowing the necessary internet access for the FMC. Where would be the best place to set up this filtering? 

 

is it better to set up the filtering under the Access policy in the FMC (this allows the FMC to reach out to certain sites) or should we do it under the prefilter policy?  or would it be better to do it under ASA access policy. 

 

 

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/security__internet_access__and_communication_ports.html

CCNA R&S
1 Accepted Solution

Accepted Solutions

@PacketSpartan I personally would use the ACP rules to permit the required access, you can rely on URL filtering and applications (if required), which you cannot with the prefilter.

View solution in original post

3 Replies 3

@PacketSpartan I personally would use the ACP rules to permit the required access, you can rely on URL filtering and applications (if required), which you cannot with the prefilter.

Cheers Rob, 

 

Just had a look through Applications under the ACP, cant see anything for FMC. 

 

We'll go down the lines of ACP

CCNA R&S

@PacketSpartan I didn't mean an application for FMC itself, I meant the applications for smtp, http etc of the destination networks/URLs the FMC would need to communicate with (as per the link you provided).

Review Cisco Networking products for a $25 gift card