<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower IPS inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691030#M1093526</link>
    <description>&lt;P&gt;I generally apply an IPS policy on all "allow" rules. If there is a Malware license available, create and apply a File policy to all allow rules for clear text protocols (since we cannot inspect the contents of encrypted traffic unless there is an (uncommon) SSL policy as well).&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2022 03:34:10 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2022-09-21T03:34:10Z</dc:date>
    <item>
      <title>Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4690898#M1093516</link>
      <description>&lt;P&gt;Is IPS a "Set it and forget it"&amp;nbsp; type deal?&amp;nbsp; Say I have 50 rules in my ACP and select balanced &amp;amp; security for every rule and on top of select a file &amp;amp; malware policy would this not kill the performance? What do you guys typically do to manage this? I have at bottom of my ACP allow http https so that my url block categories above are not able to be bypassed. Would I just set inspection for File and IPS on my allow http https rule and just forget about it and let it do its thing??? What rules would one typically enable inspection and file and malware policies for??? So confusing every step of the way here&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 18:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4690898#M1093516</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2022-09-20T18:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691030#M1093526</link>
      <description>&lt;P&gt;I generally apply an IPS policy on all "allow" rules. If there is a Malware license available, create and apply a File policy to all allow rules for clear text protocols (since we cannot inspect the contents of encrypted traffic unless there is an (uncommon) SSL policy as well).&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 03:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691030#M1093526</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-09-21T03:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691358#M1093546</link>
      <description>&lt;P&gt;Do you do anything specific as far as your IPS setup and maintaining or do you normally just set your allows to IPS balanced and security defaults and just forget about it?&amp;nbsp; There seems to be a bunch of things one can do but looking at the thousands of snort rules I wouldn't know where to start to adjust to make more efficient. It seems like setting IPS inspection on multiple rules would kill the performance. Thanks Marvin&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 13:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691358#M1093546</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2022-09-21T13:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691742#M1093557</link>
      <description>&lt;P&gt;I try to use a copy based on "Balanced Security and Connectivity" with an overlay of Firepower Recommendations updated monthly. That will tweak the default rules based on host characteristics observed in your environment. It should not affect performance appreciably since that is what the box is designed to do.&lt;/P&gt;
&lt;P&gt;The only times I have manually tweaked individual rules is when the customer had some specific SCADA protocols that they wanted to make sure were covered for their deployment.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 04:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4691742#M1093557</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-09-22T04:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692044#M1093572</link>
      <description>&lt;P&gt;Marvin one last question is do you set IPS inspection for your allows from inside zone initiator to outside zone or do you only do for outside initiator to inside or both traffic flow types?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 10:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692044#M1093572</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2022-09-22T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692087#M1093576</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/262657"&gt;@keithcclark71&lt;/a&gt;also ensure your logging is enabled on each rule so you can later troubleshoot events. For allow rules I do "log at end of connection" and for block rules "log at beginning of the connection." In our annual audits we always find a dozen or so rules where our engineers forgot to enable logging. Having a solid rule where you know all of your settings are correct, and then right-clicking and copying and pasting that rule to create your future rules is a good practice so you don't forget to turn on IPS, logging, etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692087#M1093576</guid>
      <dc:creator>Alan Inman</dc:creator>
      <dc:date>2022-09-22T12:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS inspection</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692735#M1093613</link>
      <description>&lt;P&gt;Great tip Alan. Do you also enable IPS inspection on all of your allow rules? Do you do them only for Outside Zone to Inside Zone Allow rules or do you do for both Inside zone to Outide &amp;amp; Outside zone to inside&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 12:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-inspection/m-p/4692735#M1093613</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2022-09-23T12:52:04Z</dc:date>
    </item>
  </channel>
</rss>

