<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gotcha - agree w/ you there.  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728160#M1026181</link>
    <description>&lt;P&gt;Gotcha - agree w/ you there.&amp;nbsp; What's confusing me, with that graphic in particular, is where they have the Intrusion Policy on rule 4 as "(optional)" and I'm assuming they are using the same Intrusion Policy as the default action.&lt;/P&gt;&lt;P&gt;Thanks for the thoughts!&lt;/P&gt;</description>
    <pubDate>Mon, 21 Sep 2015 14:16:23 GMT</pubDate>
    <dc:creator>mekozloski</dc:creator>
    <dc:date>2015-09-21T14:16:23Z</dc:date>
    <item>
      <title>Default Action vs. Inspection Rule?</title>
      <link>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728158#M1026179</link>
      <description>&lt;P&gt;I've seen mixed configurations where someone will explicitly create an inspection rule using an intrusion policy and then other cases where someone has created an inspection rule only for files (no intrusion policy) but then configures the intrusion policy as the default action.&amp;nbsp; Which method is correct?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728158#M1026179</guid>
      <dc:creator>mekozloski</dc:creator>
      <dc:date>2019-03-12T12:46:03Z</dc:date>
    </item>
    <item>
      <title>For me the default action is</title>
      <link>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728159#M1026180</link>
      <description>&lt;P&gt;For me the default action is only used as a fail safe.&amp;nbsp; It reminds me of an implicit deny in an access list.&lt;/P&gt;&lt;P&gt;The last rule in my Access Control Policy is a 'Default Inspection and File' rule configured to allow traffic. Both the Intrusion Policy and File Policy would be included in this rule.&lt;/P&gt;&lt;P&gt;Its also important to include the Inspection Policy and File Policy to any rules with the allow action. Matching traffic will not be scanned by the IPS Policy unless it is applied at the given rule. An example would be a&amp;nbsp; bypass rule for specific users that may be allowed to use applications in a global application block rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel like with the example given in the Cisco documentation, this would be the correct way to configure the access policy with an Intrusion and File Policy.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="http://www.cisco.com/c/dam/en/us/td/i/300001-400000/370001-380000/373001-374000/373466.tif/_jcr_content/renditions/373466.jpg" style="margin-bottom:20px" /&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/AC-Intrusion-Malware-Detection.html&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 21:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728159#M1026180</guid>
      <dc:creator>Justin Walker</dc:creator>
      <dc:date>2015-09-18T21:35:27Z</dc:date>
    </item>
    <item>
      <title>Gotcha - agree w/ you there. </title>
      <link>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728160#M1026181</link>
      <description>&lt;P&gt;Gotcha - agree w/ you there.&amp;nbsp; What's confusing me, with that graphic in particular, is where they have the Intrusion Policy on rule 4 as "(optional)" and I'm assuming they are using the same Intrusion Policy as the default action.&lt;/P&gt;&lt;P&gt;Thanks for the thoughts!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 14:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-vs-inspection-rule/m-p/2728160#M1026181</guid>
      <dc:creator>mekozloski</dc:creator>
      <dc:date>2015-09-21T14:16:23Z</dc:date>
    </item>
  </channel>
</rss>

