<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello experts, need some knowledge on firepower applicance deployment modes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155411#M1074097</link>
    <description>&lt;P&gt;We don't want to send all our traffic to IPS hence I was looking for options where I can deploy the same device as IPS for some critical data and IDS for other traffic. Some of my friends say firepower can send tcp resets even when its configured as IDS, is that achievable? My understanding was IDS can not take any action since its passively listening to traffic spanned to it. Can someone shed some light on this to me if there is a way to do this ?&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 16:53:52 GMT</pubDate>
    <dc:creator>skc455</dc:creator>
    <dc:date>2020-09-22T16:53:52Z</dc:date>
    <item>
      <title>Hello experts, need some knowledge on firepower applicance deployment modes</title>
      <link>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155411#M1074097</link>
      <description>&lt;P&gt;We don't want to send all our traffic to IPS hence I was looking for options where I can deploy the same device as IPS for some critical data and IDS for other traffic. Some of my friends say firepower can send tcp resets even when its configured as IDS, is that achievable? My understanding was IDS can not take any action since its passively listening to traffic spanned to it. Can someone shed some light on this to me if there is a way to do this ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 16:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155411#M1074097</guid>
      <dc:creator>skc455</dc:creator>
      <dc:date>2020-09-22T16:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Hello experts, need some knowledge on firepower applicance deployment modes</title>
      <link>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155424#M1074100</link>
      <description>&lt;P&gt;IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.&lt;/P&gt;
&lt;P&gt;Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155424#M1074100</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-09-22T17:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hello experts, need some knowledge on firepower applicance deployment modes</title>
      <link>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155455#M1074102</link>
      <description>&lt;P&gt;Thank you for confirming Marvin&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 18:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hello-experts-need-some-knowledge-on-firepower-applicance/m-p/4155455#M1074102</guid>
      <dc:creator>skc455</dc:creator>
      <dc:date>2020-09-22T18:36:14Z</dc:date>
    </item>
  </channel>
</rss>

