cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3251
Views
10
Helpful
8
Replies

IP Blocking on FMC/FTD

Hello, 

 

I would like to block some public IP addresses in the FMC in a manual way. 

When I see it in the events I have the option to select to blacklist it.

When I go to that blacklist I cannot add manually. 

 

Which is the best way to block a public IP?

 

Regards,

Konstantinos

8 Replies 8

Hi @kostasthedelegate 

You could create a manual list, define the IP addresses you wish to block and reference that list in the ACP as a blacklist. You'd need to manually download the list and re-upload to modify.

 

HTH

Hello @Rob Ingram 

 

In the access policy you mean the URL tab?

Would it be better to use DNS policy?

What is the order the traffic flows in the FTD in order to cut the desired traffic as soon as possible?

 

 

No under the SI tab of the ACP, select the list and add to the blacklist. Screenshot below shows which is blocked first.

d8ee303e-a96a-4b54-9ed3-797419000323.PNG

Thank you Rob

 

I will test it!!

Hello 

 

We tested it and we get that 0 IP found

Could you point me to the syntax of the file the list should contain?

 

Regards, 

Konstantinos

The list just needs to contain the IP address(es) you wish to block.

I tried putting the IP only and it said It found 0 IPs

1.PNG

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: