Guest

Preview Tool

Cisco Bug: CSCvs30892 - Firepower2K FDM AMP rule not take effect

Last Modified

May 13, 2020

Products (35)

  • Cisco Firepower Management Center
  • Cisco Firepower Management Center 2500
  • Cisco FirePOWER Appliance 8260
  • Cisco Firepower Management Center 4600
  • Cisco FirePOWER Appliance 7050
  • Cisco FirePOWER Appliance 8120
  • Cisco FirePOWER Appliance 8360
  • Cisco FirePOWER Appliance 8140
  • Cisco FirePOWER Appliance 8350
  • Cisco FirePOWER Appliance 8130
View all products in Bug Search Tool Login Required

Known Affected Releases

2.9.14.0

Description (partial)

Symptom:
1/ Firepower 2k running FTD 6.4, managed by FDM, config AMP rule:  block office document and PDF upload, block malware others.
2/ when transfer Virus files using FTP traffic for testing AMP function. found Firewall generated events log for block Malware files, on the firewall engine debug, confirm the result was disposition Malware and action Block Malware.
3/ but in fact, the files transfer were successful,firewall capture shows that ftp data is forwarded by firewall. firewall does not have Block Malware files.

Conditions:
1/ FTD was managed locally, found this issue. test on the FMC, the malware files was blocked normally.
2/ the test version was 6.4.0.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.