Introduction
This document describes the outbound internet connections by firepower devices in order to meet network security requirements.
Firepower Connections to Internet Servers
Firepower devices require outbound connections to Internet Servers for network security requirements.
Either the FMC, firepower or FTD devices make both on demand and scheduled outbound connections to Internet Servers for network security services that are active on the device. These services are enabled by the appropriate licenses for advanced features like malware protection, URL filtering etc.
Note: For more information on licensing and usage, refer to the appropriate configuration guides relevant to your product and version.
Here are the Internet Server websites:
- cloud-sa.amp.sourcefire.com
- Advanced Malware Protection (AMP) cloud base intelligence (only reached with Malware Lic.)
- cloud-sa-589592150.us-east-1.elb.amazonaws.com.
- AMP cloud base intelligence (only reached with Malware Lic.)
- database.brightcloud.com
- Cloud based URL classification and reputation service (only reached if URL Filtering feature is enabled)
- service.brightcloud.com
- Cloud based URL classification and reputation service (only reached if URL Filtering feature is enabled)
- amp.updates.vrt.sourcefire.com
- intelligence.sourcefire.com
- Cisco Talos (only reached if using the Security Intelligence feature)
- panacea.threatgrid.com
- Threatgrid service for malware
- blogs.cisco.com/talos or cloud.google.com
- Threat intelligence for Cisco Products – Contacts google cloud. (it is active by Default)
- tools.cisco.com
- updates.vrt.sourcefire.com
For firepower with AMP enabled, refer to this doc link for the external servers:
https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html