04-28-2023 09:05 AM
We are experiencing some odd issues with our geolocation feature in FMC/FTD environment. We have about 150 remote end users based in the US, metro Atlanta specifically, and an overwhelming majority of them have no issue connecting over our Citrix/VPN. However a handful of end users, four in this case, all in Atlanta, are being blocked. Manually applying their outside-facing ISP addresses of these four end users to the firewall rule that also included the geolocation rule corrected the issue. We're stumped as to why only these four end users are being impacted. We did note they use AT&T Uverse as their service provider, but so do many of the other end users who are not impacted by this issue. All four end user's each have the same first octet of 99.x.x.x, again, like many other unaffected end users. We're running IOS Version 7.0.4 on each of our 2110 FTD appliances as well as our FMC VM. All geolocation files are regularly updated, and we run the most recent Snort3 rules, which are configured to manually update. We just can't quite figure out why these four end users are being blocked. The only thing we can relate it to is that it began after a geolocation update was pushed in late January. The problem began immediately following that update. Has anyone else experienced this? Thanks in advance.
05-09-2023 09:02 AM
05-14-2023 11:18 PM
Hi,
i would also say that for starters a quick look at unified events will let you identify whats dropping the connection - ACL, Security intelligence, Malware/file policy etc.
If it is because of geolocation update, you can probably reach out to Cisco TAC and get it checked / fixed.
-----------------------------------------
If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.
You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.
-----------------------------------------
Regards,
Divya Jain
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide