<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Event Showing &amp;quot;would have dropped&amp;quot; as inline result in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/ips-event-showing-quot-would-have-dropped-quot-as-inline-result/m-p/4541674#M6642</link>
    <description>&lt;P&gt;When you select “No” to drop when inline the results regardless of the settings enabled for the rule is NOT to drop the traffic - hence the message would have dropped. This effectively turns the policy into an IDS based policy. If the intention is to drop traffic you need to select “yes” to drop when inline - this effectively turns the policy into an IPS based policy.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 29 Jan 2022 01:50:29 GMT</pubDate>
    <dc:creator>Jason Maynard</dc:creator>
    <dc:date>2022-01-29T01:50:29Z</dc:date>
    <item>
      <title>IPS Event Showing "would have dropped" as inline result</title>
      <link>https://community.cisco.com/t5/endpoint-security/ips-event-showing-quot-would-have-dropped-quot-as-inline-result/m-p/4539587#M6640</link>
      <description>&lt;P&gt;I observed whenever “Inline Result” generated “would have dropped” action , traffic processed by the IPS Policy ( INTPOL-01v1 from the Image ) which is called at Advanced Section of Actual Policy ( &lt;STRONG&gt;Perim-01&lt;/STRONG&gt;&amp;nbsp;1st Image ).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though&amp;nbsp; “Drop when inline” action is “No” for this IPS Policy ( &lt;A href="https://adc-j13-fmc1/DetectionPolicy/ids.cgi" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;INTPOL-01v1&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;) that means even though individual signature action is “Drop and Generate Events” it will not DROP Traffic. ?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;However at each rule,&amp;nbsp; IPS Policy&amp;nbsp;&lt;STRONG&gt;Perim-01&lt;/STRONG&gt; is called and its “Drop when InLine” Action is YES and specific signature is “Drop and Generate Events” so ultimately when IPS Policy at each Rule is Processed this same traffic is Blocked&amp;nbsp; ? for the Log/traffic which showed "would have dropped" .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/142289iECB86BE5F60D4CC8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image1.jpg" alt="Image1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/142290i8D2978269C8308B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image2.jpg" alt="Image2.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 18:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ips-event-showing-quot-would-have-dropped-quot-as-inline-result/m-p/4539587#M6640</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2022-01-26T18:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Event Showing "would have dropped" as inline result</title>
      <link>https://community.cisco.com/t5/endpoint-security/ips-event-showing-quot-would-have-dropped-quot-as-inline-result/m-p/4541674#M6642</link>
      <description>&lt;P&gt;When you select “No” to drop when inline the results regardless of the settings enabled for the rule is NOT to drop the traffic - hence the message would have dropped. This effectively turns the policy into an IDS based policy. If the intention is to drop traffic you need to select “yes” to drop when inline - this effectively turns the policy into an IPS based policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 01:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ips-event-showing-quot-would-have-dropped-quot-as-inline-result/m-p/4541674#M6642</guid>
      <dc:creator>Jason Maynard</dc:creator>
      <dc:date>2022-01-29T01:50:29Z</dc:date>
    </item>
  </channel>
</rss>

