04-12-2016 04:50 AM - edited 03-12-2019 05:58 AM
Dears
when i select users while creating a new policies I get the attached error.
i have some queries for the access control policies
Rule 1: action: block , ,zone: inside to outside,, source :any destination: any url : high risk url
Result will be block for all users for high risk url
Rule 2: action allow,, zone: inside to outside, source : any destination: any ,, user : ADMINS url : all-allow ,,, application filter: allow all
Result: will be user Admin will be allowed all url but block bittorent application
Rule 3: action allow,, zone: inside to outside, source : any destination: any ,, user : USER-ALL url : specific url category application filter: bittorrent block
Result: will be user will be restricted to specific url and bittorent will be block
Thanks
04-12-2016 06:49 PM
So do you have an identity policy?
Have you linked to your domain and are you getting user identity mapping via Sourcefire User Agent or ISE?
04-13-2016 10:08 AM
Dear Marvin,
can you help me for access policies whether my thinking are correct??? for identity policies i will come to you what is my exact query.
thanks
04-13-2016 06:05 PM
Clark,
The logic you present for your access control policy seems good.
04-16-2016 04:54 AM
Dear Marvin,
I have created a identity policy with a rule in which I have a passive authentication and a realm which I configured but still I get the same " exclamation mark on the user while creating the access policies,
For below access control policies the internet was very slow for every webpage when I disable URL filtering allowing to all the browsing was fast,
Rule 1: action: block , ,zone: inside to outside,, source :any destination: any url : high risk url
Result will be block for all users for high risk url
Thanks
04-16-2016 06:07 AM
Have you deployed the Sourcefire User Agent and is it successfully discovering user-IP mapping and is that information reflected in your "Users" tab of the FirePOWER Manager?
04-18-2016 12:14 PM
Dear Marvin,
the realm issue solved by changing the Base DN path once I changed the path the users were able to download.
But for the Access Control policies, can u give a base idea how the access control policies are build ?? I want to keep Intrusion policy as a default becz I am controlling everything from firewall ijust wanted a malware, application, url , security intelligence, file filtering to be configured.
Please correct me if I am wrong. Rule 3 will never match ,,, users will not match this rule becz this rule has to be splitted by 2 different rules application filter rule for all user and url filter separate rule for all user.
Rule 3: action allow,, zone: inside to outside, source : any destination: any ,, user : USER-ALL url : specific url category application filter: bittorrent block
Result: no match and traffic will be send to default intrusion policy rule.
Thanks
04-18-2016 12:51 PM
I din't really think of them as a whole set.
You're right - you need to order them most specific to least specific and consider that the first match will end the rule processing.
04-24-2016 09:20 PM
Dear Marvin,
I am confuse little to create access policies,below are my thought to create a policies by order ,so please correct me if i am doing wrong.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide