<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Robert, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876689#M1030212</link>
    <description>&lt;P&gt;Hi Robert,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For blocking bittorrent, you can create an access control rule with bittorrent as an application selected and set the action to block.&lt;/P&gt;
&lt;P&gt;Make sure if you are using the latest VDB (vulnearbility database on your firepower)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For getting alerts on intrusions and malware , you can refer to the below document :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you are managing via ASDM, you can use syslog an snmp same as above.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate and mark helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jul 2016 05:07:27 GMT</pubDate>
    <dc:creator>ankojha</dc:creator>
    <dc:date>2016-07-04T05:07:27Z</dc:date>
    <item>
      <title>Firepower configuration for maximum throughput</title>
      <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876688#M1030210</link>
      <description>&lt;P&gt;We are a small ISP with about 600 customers. &amp;nbsp;Our aggregate&amp;nbsp;through our&amp;nbsp;ASA 5515x hits about 320 mbps.&lt;/P&gt;
&lt;P&gt;A speedtest shows that it can do about 860 mbps up/down without FirePower. &amp;nbsp;With a typical Firepower inline configuration, we get about 220 mbps.&lt;/P&gt;
&lt;P&gt;Purchasing a 5555-x is currently over our budget. &amp;nbsp;We are licensed for two ASAs, so the option exists to put a second one on the network or load balance. (which I've heard does not consume a license)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another option is to just block BitTorrent, otherwise be notified of malware &amp;amp; intrusion attempts?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can anyone suggest a way to configure this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Robert&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 01:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876688#M1030210</guid>
      <dc:creator>Robert Zeff</dc:creator>
      <dc:date>2019-03-26T01:16:30Z</dc:date>
    </item>
    <item>
      <title>Hi Robert,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876689#M1030212</link>
      <description>&lt;P&gt;Hi Robert,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For blocking bittorrent, you can create an access control rule with bittorrent as an application selected and set the action to block.&lt;/P&gt;
&lt;P&gt;Make sure if you are using the latest VDB (vulnearbility database on your firepower)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For getting alerts on intrusions and malware , you can refer to the below document :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you are managing via ASDM, you can use syslog an snmp same as above.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate and mark helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 05:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876689#M1030212</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-04T05:07:27Z</dc:date>
    </item>
    <item>
      <title>We are managing with FMC</title>
      <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876690#M1030213</link>
      <description>&lt;P&gt;We are managing with FMC running under VMWare. &amp;nbsp;I'd rather see the alerts on FMC.&lt;/P&gt;
&lt;P&gt;I do have this configuration, with my File policy looking like:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://git.nikola.com/software/filepolicy.png" alt="File Policy" width="930" height="478" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I select Malware cloud lookup under "action", it just looks up? &amp;nbsp;Otherwise I'd select "block malware"?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems that no matter how minimal the configuration is, I cannot get over 280 mbps, and while doing a speedtest with one client, a ping test of about 2ms goes to 150-330&amp;nbsp;ms with a lot of jitter.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 19:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876690#M1030213</guid>
      <dc:creator>Robert Zeff</dc:creator>
      <dc:date>2016-07-04T19:06:21Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876691#M1030214</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;If you enable malware cloudlookup it will query cloud for the file disposition to check if the file is clean or threat etc..Block malware means it will completely block the files marked as malware.&lt;/P&gt;
&lt;P&gt;For the verification of throughputs you can open a TAC request just to confirm that your deploymebt is proper.&lt;/P&gt;
&lt;P&gt;Rate if posts helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 05:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876691#M1030214</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-05T05:33:22Z</dc:date>
    </item>
    <item>
      <title>Keep in mind that Malware</title>
      <link>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876692#M1030215</link>
      <description>&lt;P&gt;Keep in mind that Malware/file analysis will create more overhead on those ASAs, adding latency in your network. &amp;nbsp;Tune it well. &amp;nbsp; this is in addition on other features you add like URI filtering, Network Discovery policies, and Signatures with HIgh or very High overhead.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just me 2 pennies&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 19:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-configuration-for-maximum-throughput/m-p/2876692#M1030215</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2016-07-15T19:44:33Z</dc:date>
    </item>
  </channel>
</rss>

