cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
949
Views
0
Helpful
1
Replies

Security Intelligence Feature

fatalXerror
Level 5
Level 5

Hi Guys,

I am using security intelligence in my firepower system to block and white-list URLs however, it seems to be not working it still goes to the verdict of my access control list and not the security intelligence.

Thanks.

1 Reply 1

Muhammad Awais Khan
Cisco Employee
Cisco Employee

Hi,

As per the packet flow of FTD, the blacklisted traffic in SI config will be dropped.  It seems your whitelisted URL's is going through the ACL policies which seems to be a normal behavior. 

 

The whitelisted policies only whitelists the specific URL's defines in the blacklists.

 

I am attaching a snapshot of Packet flow in FTD software code 

 

Reference: https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/security_intelligence_blacklisting.html

 

 

Review Cisco Networking for a $25 gift card