<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intrusion Rules in Cisco FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649415#M1091803</link>
    <description>&lt;P&gt;If i do not select "Drop when Inline" will the IPS function as an IDS only regardless of rule actions ?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 09:49:34 GMT</pubDate>
    <dc:creator>NeWGuy1109</dc:creator>
    <dc:date>2022-07-13T09:49:34Z</dc:date>
    <item>
      <title>Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624279#M1090610</link>
      <description>&lt;P&gt;I have configured around 300 rules in FMC.. a recent requirement is to apply an IPS Policy to all the rules..is there a way an Intrusion Policy can be applied all at once to an entire ACL ? its really inconvenient to edit 300 rules and apply an IPS Policy there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if i am not using inline mode does Intrusion Policy will act as an IDS only ? it wont drop any traffic ? in custom intrusion policy "drop when inline mode" is specific for inline modes only ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 19:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624279#M1090610</guid>
      <dc:creator>NeWGuy1109</dc:creator>
      <dc:date>2022-06-03T19:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624433#M1090616</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You can do this through FMC APIs. But from GUI that is not possible. You&lt;BR /&gt;can write your own API loop script to edit the setting.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sat, 04 Jun 2022 02:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624433#M1090616</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-04T02:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624532#M1090619</link>
      <description>&lt;P&gt;Thanks...any link i can refer for such scripts?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2022 09:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624532#M1090619</guid>
      <dc:creator>NeWGuy1109</dc:creator>
      <dc:date>2022-06-04T09:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624639#M1090620</link>
      <description>Here you go&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-security/python-scripts-to-create-and-delete-hosts-on-firepower-manager/td-p/4100224" target="_blank"&gt;https://community.cisco.com/t5/network-security/python-scripts-to-create-and-delete-hosts-on-firepower-manager/td-p/4100224&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-security/my-python-script-to-query-fmc-api-for-list-of-sensor-names-and/td-p/3737313" target="_blank"&gt;https://community.cisco.com/t5/network-security/my-python-script-to-query-fmc-api-for-list-of-sensor-names-and/td-p/3737313&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sat, 04 Jun 2022 10:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4624639#M1090620</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-04T10:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649415#M1091803</link>
      <description>&lt;P&gt;If i do not select "Drop when Inline" will the IPS function as an IDS only regardless of rule actions ?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 09:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649415#M1091803</guid>
      <dc:creator>NeWGuy1109</dc:creator>
      <dc:date>2022-07-13T09:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649580#M1091815</link>
      <description>&lt;P&gt;Just select all the rules in the ACP at once (select first one, hold down shift key and then select last one) and right click to edit. You may need to change your display rules per page (bottom right) so that you can see and select all of them at once.&lt;/P&gt;
&lt;P&gt;Common tasks (such as IPS policy) will be selectable to change them.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC - edit multiple rules" style="width: 755px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/156792i797235634DFB5053/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC - edit multiple rules.png" alt="FMC - edit multiple rules" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;FMC - edit multiple rules&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 14:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649580#M1091815</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-07-13T14:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649616#M1091816</link>
      <description>&lt;P&gt;Incredible !!!&amp;nbsp; that was very helpful Marvin.&lt;/P&gt;&lt;P&gt;One more thing if you can please help out with.. if in IPS policy i have unchecked "Drop when Inline" will my policy act as an IDS ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 15:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649616#M1091816</guid>
      <dc:creator>NeWGuy1109</dc:creator>
      <dc:date>2022-07-13T15:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Intrusion Rules in Cisco FMC</title>
      <link>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649625#M1091817</link>
      <description>&lt;P&gt;Deselecting "Drop when Inline" will indeed make the sensor function like what is sometimes referred to as an Intrusion Detection System (IDS) vs. an Intrusion Prevention System (IPS). I seldom see that used in practice though as it removes most of the utility of actually preventing intrusions.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 15:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intrusion-rules-in-cisco-fmc/m-p/4649625#M1091817</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-07-13T15:48:14Z</dc:date>
    </item>
  </channel>
</rss>

