<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACP Rules for IPS and File in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acp-rules-for-ips-and-file/m-p/3758652#M1012336</link>
    <description>&lt;P&gt;I typically include IPS inspection for anything unencrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;File inspection I only set for unencrypted applications that potentially include a file payload (such as the ones you mentioned). Also if you have a lot of east-west traffic (i.e. server to server or users to file servers) I exclude that from file inspection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(This assumes I don't have an SSL Policy that's decrypting traffic.)&lt;/P&gt;</description>
    <pubDate>Thu, 06 Dec 2018 02:00:21 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-12-06T02:00:21Z</dc:date>
    <item>
      <title>ACP Rules for IPS and File</title>
      <link>https://community.cisco.com/t5/network-security/acp-rules-for-ips-and-file/m-p/3758437#M1012335</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the general recommendation for which rules are inspected with IPS/File and which are not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently working on a deployment which has a large number of inside to outside zone rules that permit traffic such as dns, http, https, ftp, ICMP etc. All of these rules have been configured as allow with IPS and file inspection, however, I think that this is overkill and not actually needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, do I need to apply IPS and file inspection to outgoing DNS traffic? Should DNS traffic be set to trust only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For file inspection, should I only inspect applicable traffic that Firepower can inspect for Malware such as HTTP, SMTP, POP3, FTP etc? I dont see the need to inspect DNS, HTTPs traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acp-rules-for-ips-and-file/m-p/3758437#M1012335</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2019-03-12T14:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: ACP Rules for IPS and File</title>
      <link>https://community.cisco.com/t5/network-security/acp-rules-for-ips-and-file/m-p/3758652#M1012336</link>
      <description>&lt;P&gt;I typically include IPS inspection for anything unencrypted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;File inspection I only set for unencrypted applications that potentially include a file payload (such as the ones you mentioned). Also if you have a lot of east-west traffic (i.e. server to server or users to file servers) I exclude that from file inspection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(This assumes I don't have an SSL Policy that's decrypting traffic.)&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 02:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acp-rules-for-ips-and-file/m-p/3758652#M1012336</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-12-06T02:00:21Z</dc:date>
    </item>
  </channel>
</rss>

