<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I put my External Facing Servers in EXTERNAL_NET of a Firepower's VARIABLE SET? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-i-put-my-external-facing-servers-in-external-net-of-a/m-p/4102229#M1070983</link>
    <description>&lt;P&gt;I have a range of IP's which are assigned for Internet facing servers. I had already defined all of my HOME_NET in which I also included publicly addressable internal IPs which I would like to monitor. However I had not added these external facing network ranges to the HOME_NET. I rather thought of adding them in the EXTERNAL_NET's excluded category. This ensures that, these IP's are not part of the internal network and are also not part of the external networks either. I believe it is safe to say that anything in the excluded category of EXTERNAL_NET can be called as an unprotected network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is, did I configured it right? If there is an attack on one of the external facing server which is open on 80 and 443, for a signature such as "&lt;SPAN&gt;alert tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET $HTTP_PORTS&lt;/SPAN&gt;&lt;SPAN&gt;" I should be triggered only when the attack reaches an IP from the HOME_NET (159.x.x.x -&amp;gt; 192.168.x.x). Will this cause any conflicts? Is this even the right way of defining our external facing/internet facing networks?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jun 2020 13:13:42 GMT</pubDate>
    <dc:creator>nemanas</dc:creator>
    <dc:date>2020-06-12T13:13:42Z</dc:date>
    <item>
      <title>Can I put my External Facing Servers in EXTERNAL_NET of a Firepower's VARIABLE SET?</title>
      <link>https://community.cisco.com/t5/network-security/can-i-put-my-external-facing-servers-in-external-net-of-a/m-p/4102229#M1070983</link>
      <description>&lt;P&gt;I have a range of IP's which are assigned for Internet facing servers. I had already defined all of my HOME_NET in which I also included publicly addressable internal IPs which I would like to monitor. However I had not added these external facing network ranges to the HOME_NET. I rather thought of adding them in the EXTERNAL_NET's excluded category. This ensures that, these IP's are not part of the internal network and are also not part of the external networks either. I believe it is safe to say that anything in the excluded category of EXTERNAL_NET can be called as an unprotected network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is, did I configured it right? If there is an attack on one of the external facing server which is open on 80 and 443, for a signature such as "&lt;SPAN&gt;alert tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET $HTTP_PORTS&lt;/SPAN&gt;&lt;SPAN&gt;" I should be triggered only when the attack reaches an IP from the HOME_NET (159.x.x.x -&amp;gt; 192.168.x.x). Will this cause any conflicts? Is this even the right way of defining our external facing/internet facing networks?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 13:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-put-my-external-facing-servers-in-external-net-of-a/m-p/4102229#M1070983</guid>
      <dc:creator>nemanas</dc:creator>
      <dc:date>2020-06-12T13:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can I put my External Facing Servers in EXTERNAL_NET of a Firepower's VARIABLE SET?</title>
      <link>https://community.cisco.com/t5/network-security/can-i-put-my-external-facing-servers-in-external-net-of-a/m-p/4102257#M1070984</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like this is North-South traffic, in which case you will actually want to include your public facing servers in the HOME_NET so that the Snort signatures can detect inbound attacks against your servers. Basically, HOME_NET should contain everything you want to protect and EXTERNAL_NET should be viewed as where an attack might come from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest including all the subnets you own in HOME_NET and then setting the EXTERNAL_NET to exclude HOME_NET.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a link to a Cisco Live presentation which contains some good information on variable sets:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKSEC-2066.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKSEC-2066.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 14:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-put-my-external-facing-servers-in-external-net-of-a/m-p/4102257#M1070984</guid>
      <dc:creator>JohnLong3</dc:creator>
      <dc:date>2020-06-12T14:11:07Z</dc:date>
    </item>
  </channel>
</rss>

