cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
900
Views
2
Helpful
1
Replies

Blocking High Risk Applications in FMC

dcanady55
Level 3
Level 3

Hello,

FMC and FTD version 7.3.

In looking at my dashboards recently, I noticed some traffic designated as very high risk. I created an application block for this traffic, which is high on my ACP. The traffic is not being blocked, and looking at the connection events of one flow, it's hitting a rule way down in my ACP. The application itself was already in Cisco's risky application filter, so I'm not sure why it's not hitting my earlier rule. Any suggestions on how to fix that?

Thanks

1 Reply 1

dcanady55
Level 3
Level 3

I ended up creating a new rule and putting this at the top of the ACP which now is blocking the traffic.