<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to verify enabled snort rules in FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518918#M1085809</link>
    <description>&lt;P&gt;Thanks, it looks like even the "&lt;SPAN&gt;Connectivity Over Security" base policy have all the log4j signatures enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/Chess&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 19:43:43 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2021-12-14T19:43:43Z</dc:date>
    <item>
      <title>How to verify enabled snort rules in FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518910#M1085807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an IPS policy based on Balanced Security and Connectivity and according to that policy 473 rules are set to generate events and 8657 rules are set to drop and generate events. I have downloaded the latest ruleset and want to verify that all signatures related to the log4j&amp;nbsp;vulnerability are enabled and set to drop and generate events. However if I select "View rules" from the Balanced Security and Connectivity policy layer, it will display 46237 rules, which I assume is every available snort signatures. So my question is how I can see only the 8657 signature that I'm currently using? I am assuming all log4j signatures are enabled in the Balanced Security and Connectivity policy, but I just want to make sure this is the case.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/Chess&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518910#M1085807</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2021-12-14T19:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to verify enabled snort rules in FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518913#M1085808</link>
      <description>&lt;P&gt;You should be able to search for the snort rule ID associated with this and see what the action is set to which might well be “set to drop”. But you would need to confirm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.snort.org/advisories/talos-rules-2021-12-10" target="_blank"&gt;https://www.snort.org/advisories/talos-rules-2021-12-10&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518913#M1085808</guid>
      <dc:creator>shahzad_ahmed</dc:creator>
      <dc:date>2021-12-14T19:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to verify enabled snort rules in FTD</title>
      <link>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518918#M1085809</link>
      <description>&lt;P&gt;Thanks, it looks like even the "&lt;SPAN&gt;Connectivity Over Security" base policy have all the log4j signatures enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/Chess&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-verify-enabled-snort-rules-in-ftd/m-p/4518918#M1085809</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2021-12-14T19:43:43Z</dc:date>
    </item>
  </channel>
</rss>

