<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: updating IPS rules and applying them on fmc risks in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177964#M1075420</link>
    <description>&lt;P&gt;I agree with Mohammed here.&lt;/P&gt;
&lt;P&gt;1. Disable inline drop&lt;/P&gt;
&lt;P&gt;2. Run the generate recommended rules&lt;/P&gt;
&lt;P&gt;3. Monitor for a few days to identify if there are any false positives&lt;/P&gt;
&lt;P&gt;4. Activate inline drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the rules are updated, I would suggest setting a scheduled task that updates the IPS rules on a regular basis.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Nov 2020 12:24:36 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-11-03T12:24:36Z</dc:date>
    <item>
      <title>updating IPS rules and applying them on fmc risks</title>
      <link>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177839#M1075413</link>
      <description>&lt;P&gt;i have a fmc with 2 years old ips rules , is there a risk if&amp;nbsp; update the ips rules and applied them to a production environment?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 09:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177839#M1075413</guid>
      <dc:creator>baselzind</dc:creator>
      <dc:date>2020-11-03T09:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: updating IPS rules and applying them on fmc risks</title>
      <link>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177948#M1075417</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Try to update IPS rules then run recommendation task. Once recommendation&lt;BR /&gt;is completed, try to apply the IPS rules. This is safer approach.&lt;BR /&gt;&lt;BR /&gt;After couple of days of monitoring, you can tweak rules as needed.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 03 Nov 2020 12:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177948#M1075417</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-03T12:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: updating IPS rules and applying them on fmc risks</title>
      <link>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177964#M1075420</link>
      <description>&lt;P&gt;I agree with Mohammed here.&lt;/P&gt;
&lt;P&gt;1. Disable inline drop&lt;/P&gt;
&lt;P&gt;2. Run the generate recommended rules&lt;/P&gt;
&lt;P&gt;3. Monitor for a few days to identify if there are any false positives&lt;/P&gt;
&lt;P&gt;4. Activate inline drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the rules are updated, I would suggest setting a scheduled task that updates the IPS rules on a regular basis.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 12:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/updating-ips-rules-and-applying-them-on-fmc-risks/m-p/4177964#M1075420</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-03T12:24:36Z</dc:date>
    </item>
  </channel>
</rss>

