02-16-2017 04:43 PM - edited 03-12-2019 06:17 AM
What is the way to block users from accessing HTTP websites that are running on tcp/443 instead of tcp/80?
Solved! Go to Solution.
02-18-2017 04:57 AM
Yes. There is an optional setting in the preprocessor to "Detect Anomalous HTTP Servers".
Details for setting it can be found here:
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/application_layer_preprocessors.html#ID-2244-0000052b
02-17-2017 07:23 PM
Your intrusion policy must be set to block. You might want to look at the Configuration guides located on Cisco's support site: http://www.cisco.com/c/en/us/support/security/defense-center/products-installation-and-configuration-guides-list.html for additional information.
Hope this helps.
02-18-2017 04:57 AM
Yes. There is an optional setting in the preprocessor to "Detect Anomalous HTTP Servers".
Details for setting it can be found here:
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/application_layer_preprocessors.html#ID-2244-0000052b
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide