02-24-2015 08:38 AM - edited 03-10-2019 06:20 AM
Hi,
I am performing malware clould lookup using FirePOWER on ASA. I see the file event when I transfer the file, but the FireSIGHT is unable to submit the file SHA-256 for cloud lookup. It times out. The FireSIGHT management IP is able to access the Internet.
Does the malware cloud lookup need some subscription for it to work? I am running this in a lab setup with malware license.
What could be the reasons for this lookup failure. Due to this, the file disposition is 'unavailable'
Another related question. If my file policy action is to BlockMalware, and if the file disposition comes as unknown or unavailable, will the file be transferred or blocked?
Appreciate any help.
regds,
Mohan Muthu
06-10-2015 07:02 AM
I'm kinda curious about this too as I see some events with 'Malware Cloud Lookup' and 'Cloud Lookup Timeout'
07-21-2015 06:58 PM
Mohan,
Do you have you File policy configured for "Malware Cloud Lookup" or for "Dynamic Analysis?" Or are you simply selecting a file and submitting it for analysis manually? This would help in troubleshooting your issue. Also, can you perform updates from the FireSight Management center? Just curious if this gets out to the Internet. The only subscription you need for Cloud lookups is a Protect and Control license, AMP and FireSight License.
10-29-2015 01:28 PM
I was having this issue on an ASA5506 that wasn't using Firesight Management.
I opened a TAC case on this. Please have a look at Bug - CSCze95695
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide