09-10-2023 01:48 AM
Guys Please help me ..
why showing ID numbers instead of policy name in cisco ftd firewall access policy? also this policy not get hit when access from client pc falcon.crowdstrike.com.
please check below results :
system support firewall-engine-debug
n, dst sgt: 0, dst sgt type: unknown, svc -1, payload -1, client -1, misc -1, user 9999999
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 2, 'Block_URL', app s=-1 c=-1 p=-1 m=-1
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 5, 'Blocked MOI IN to OUT', dst network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 9, 'Block-CCTV-To-Internet & KIN', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 12, id 268437637 no host
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 13, 'Servers to CrowdStrike', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 14, 'Servers to CarbonBlack', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 15, 'Servers to SecureWorks', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 16, 'Servers to Windows Update', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 17, 'Servers Without Internet', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 18, 'Block-B1-Archive-PCs-Internet', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 19, 'Block NOC PC Internet', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 20, 'Block-NEW-DMZs-Communication', SrcZone
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 no match rule order 21, 'Block 192.168.20.5 Internet', src network, GEO, FQDN
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 match rule order 22, 'New_Dmz_to _Outside_No Internet', action Block
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 Got end of flow event from hardware with flags 00006001
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 Rule Match Data: rule_id 0, rule_action 0 rev_id 0, rule_flags 0
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 Received EOF, deleting the snort session
192.168.176.11 443 -> 13.52.93.220 443 6 AS=0 ID=10 GR=1-1 Deleting Firewall session
Solved! Go to Solution.
09-12-2023 04:07 AM
09-12-2023 04:07 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide