Cisco Secure Endpoint with DFC enabled can block malicious outbound connections by correlating device network flows and enforcing blocks directly on the endpoints, even if those endpoints are on a separate network from the Cisco Firepower Threat Defense (FTD) device. Modifying the access control policy on Cisco FMC (Firepower Management Center) or adding IP addresses to FMC policies would not block connections from hosts on a separate network that the FMC/FTD does not directly control. Enabling DFC in Secure Endpoint allows the endpoint agent to block connections to malicious IPs or domains based on threat intelligence and policy, which is effective for hosts outside the FTD's network scope. https://docs.amp.cisco.com/en/SecureEndpoint/Secure%20Endpoint%20User%20Guide.pdf (page 73)