<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD - &amp;quot;No Rules Active&amp;quot; but active in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737848#M1095904</link>
    <description>&lt;P&gt;Thank you again for the reply. I did generate and review the report but didn't see anything out of the ordinary. All of the rules have the correct intrusion policy specified (which every allow rule at the moment.) Perhaps it notes that in the deploy window if there is a deny (with no intrusion policy, of course) or a pre-filter policy with something fast-pathed? In that case, there would be "no rules active." I guess? I really have no idea where that line on the deploy screen is coming from, to be honest.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 13:18:12 GMT</pubDate>
    <dc:creator>brettp</dc:creator>
    <dc:date>2022-12-13T13:18:12Z</dc:date>
    <item>
      <title>Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737082#M1095845</link>
      <description>&lt;P&gt;Hello, I'm still getting used to the FTD and have been for the better part of this year. Unfortunately, I have suffered so many things that TAC could not help with because they're in all probability bugs (some of which, very clearly bugs.) I already have two cases open, one of which since August, still with no solution or communication for several weeks. At this point, and I hate to be a downer, I'm sadly losing my faith in the FTD and I don't trust anything I see. I can not find the answer anywhere... Can someone clarify something? When I deploy updated IPS definitions, there are three points under "Intrusion Policy" on the preview page... It looks like this (see screenshot for an actual view from the deploy screen.)&lt;/P&gt;&lt;P&gt;Intrusion Policy&lt;/P&gt;&lt;P&gt;- Intrusion Policy: IPS-Policy-CC (Clearly, this references the policy I manually created.)&lt;BR /&gt;- Intrusion Policy: No Rules Active (What is this? We're using FTD/FMC version 7 and inspection mode is set to "prevention.")&lt;BR /&gt;- Intrusion Policy: Balanced Security and Connectivity (And clearly, this is the base policy I'm using.)&lt;/P&gt;&lt;P&gt;What is the "Intrusion Policy: No Rules Active" referencing?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any insight is appreciated! Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 13:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737082#M1095845</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2022-12-12T13:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737223#M1095846</link>
      <description>&lt;P&gt;Your original post doesn't have any screen shot attached.&lt;/P&gt;
&lt;P&gt;However, Intrusion policy can be uniquely set per rule in your access control policy (ACP). You may have some varying settings there that would cause multiple intrusion policies to be deployed. It is sometimes easiest to see the settings by exporting a report of the ACP (done from the ACP home page - see icon that looks like pages to the far right).&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 16:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737223#M1095846</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-12T16:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737241#M1095847</link>
      <description>&lt;P&gt;Marvin, thank you very much for the reply. Hmm, I attached the screenshot to the post so I am not sure what happened... I've attached it to this reply. So is that what is being referenced by the deploy window -- the various policies being modified? I only have one policy which is applied to every ACP rule with the exception of any deny rules. I just find it strange and confusing for it to say "No rules active." And I assume the 3rd listing is a default policy? Not a reference to base policy in the custom policy I created?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-12-12 at 7.46.24 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170712i7A241D4F513EC62F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2022-12-12 at 7.46.24 AM.png" alt="Screen Shot 2022-12-12 at 7.46.24 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 16:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737241#M1095847</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2022-12-12T16:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737825#M1095899</link>
      <description>&lt;P&gt;Yes, the third one is a default policy. I could see it updating that and the first one. The second one is a bit odd if it is not called out at all in your ACP. Did you check the report I suggested?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 12:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737825#M1095899</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-13T12:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737840#M1095902</link>
      <description>&lt;P&gt;Update - look in your ACP advanced settings under Network Analysis and Intrusion Policies. Most likely the default values there call out the "No Rules Active" policy as the "Intrusion Policy used before Access Control rule is determined" and the "Balanced Security and Connectivity" policy as the "Default Network Analysis Policy".&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 13:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737840#M1095902</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-13T13:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737848#M1095904</link>
      <description>&lt;P&gt;Thank you again for the reply. I did generate and review the report but didn't see anything out of the ordinary. All of the rules have the correct intrusion policy specified (which every allow rule at the moment.) Perhaps it notes that in the deploy window if there is a deny (with no intrusion policy, of course) or a pre-filter policy with something fast-pathed? In that case, there would be "no rules active." I guess? I really have no idea where that line on the deploy screen is coming from, to be honest.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 13:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737848#M1095904</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2022-12-13T13:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737871#M1095905</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290729"&gt;@brettp&lt;/a&gt; see my "Update" post. I believe that answers the question.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 13:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4737871#M1095905</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-13T13:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD - "No Rules Active" but active</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4738801#M1095948</link>
      <description>&lt;P&gt;Thank you. Yes, I see that. It's somewhat bizarre, but I guess it's normal!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 13:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-quot-no-rules-active-quot-but-active/m-p/4738801#M1095948</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2022-12-14T13:22:39Z</dc:date>
    </item>
  </channel>
</rss>

