<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you want the same policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006619#M1006316</link>
    <description>&lt;P&gt;If you want the same policy on all 10 sites I recommend that you only make one IPS policy and make the recommendations based on all your&amp;nbsp;subnets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2017 17:51:52 GMT</pubDate>
    <dc:creator>Dennis Perto</dc:creator>
    <dc:date>2017-07-12T17:51:52Z</dc:date>
    <item>
      <title>IPS Firepower recommendations</title>
      <link>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006616#M1006313</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have say 5 subnets of different traffic requirements&lt;/P&gt;
&lt;P&gt;1/ corporate users&lt;/P&gt;
&lt;P&gt;2/ payment equipment subnet&lt;/P&gt;
&lt;P&gt;3/ dmz&lt;/P&gt;
&lt;P&gt;4/ corporate wifi&lt;/P&gt;
&lt;P&gt;5/ some other requirement&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Would one get better IPS recommendations if you created 5 IPS policies and defined the scope within recommendations according to each of the 5 above? Or would the Firepower recommendations be just as accurate with one IPS policy and it trying to recommend for the entirety?&lt;/P&gt;
&lt;P&gt;Similarly if you had a Datacentre Firepower and say 10 sites with Firepower would it be best to use a different IPS policy from the sites for the datacentre, with Recommendations defined just for the Datacentre ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006616#M1006313</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2019-03-12T13:26:14Z</dc:date>
    </item>
    <item>
      <title>Firepower will generate the</title>
      <link>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006617#M1006314</link>
      <description>&lt;P&gt;Firepower will generate the recommendations based on the hosts discovered (host profiles) on all sensors.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have multiple domains (multi tenancy in v6.0+) within that FMC, each with an IPS sensor, you will se differences in the generated recommendations.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: maybe I misunderstood the question. It is ofcause possible to limit the networks to base the recommendations on, but in my opinion this barely makes sense.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will use a lot of memory on the sensor if you apply 5 different IPS policies - one for each network.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 21:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006617#M1006314</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2017-06-27T21:52:13Z</dc:date>
    </item>
    <item>
      <title>Got you.</title>
      <link>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006618#M1006315</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Got you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you had a Datacentre Firepower and say 10 sites with Firepower would it be best to use a different IPS policies for&amp;nbsp;the sites and a different policy for the datacentre, with host Recommendations defined just for the Datacentre hosts?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Or will FMC base the recommendations on all hosts seen for both datacentre and sites?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 03:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006618#M1006315</guid>
      <dc:creator>evan.chadwick1</dc:creator>
      <dc:date>2017-07-06T03:59:09Z</dc:date>
    </item>
    <item>
      <title>If you want the same policy</title>
      <link>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006619#M1006316</link>
      <description>&lt;P&gt;If you want the same policy on all 10 sites I recommend that you only make one IPS policy and make the recommendations based on all your&amp;nbsp;subnets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 17:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-firepower-recommendations/m-p/3006619#M1006316</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2017-07-12T17:51:52Z</dc:date>
    </item>
  </channel>
</rss>

