<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower file inspection/malware detection rule placement in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151030#M1114616</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (154).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224425iA364FAE54FFB7048/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (154).png" alt="Screenshot (154).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 12:13:29 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-07-25T12:13:29Z</dc:date>
    <item>
      <title>Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150218#M1114595</link>
      <description>&lt;P&gt;I'm confused as to where to place this rule. From my understanding, there should be an allow rule with the File Policy configured to use the associated Malware &amp;amp; File policy. However, the rest of the configuration of that rule is set to allow any any.&lt;/P&gt;&lt;P&gt;There are other allow and block rules in the policy with the policy default action set to block all traffic. The last rule in the ACP is to allow all traffic outbound and inspect.&lt;/P&gt;&lt;P&gt;With that in mind, where should the file inspection policy be placed?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 19:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150218#M1114595</guid>
      <dc:creator>willb1</dc:creator>
      <dc:date>2024-07-24T19:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150230#M1114597</link>
      <description>&lt;P&gt;File/malware policy is applied to a regular access control rule .&lt;/P&gt;
&lt;P&gt;The most important would be for inbound to oubound rules like users browsing to a website and downloading files etc which can be inspected for malware..&lt;/P&gt;
&lt;P&gt;But keep in mind that 90% or above is encrypted, so unless you are doing ssl decryption, the malware inspection will not kick in..&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 20:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150230#M1114597</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-24T20:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150235#M1114598</link>
      <description>&lt;P&gt;Gotcha. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 20:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5150235#M1114598</guid>
      <dc:creator>willb1</dc:creator>
      <dc:date>2024-07-24T20:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151005#M1114614</link>
      <description>&lt;P&gt;do you want other opinion here ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 11:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151005#M1114614</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-25T11:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151006#M1114615</link>
      <description>&lt;P&gt;Absolutely&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 11:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151006#M1114615</guid>
      <dc:creator>willb1</dc:creator>
      <dc:date>2024-07-25T11:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151030#M1114616</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (154).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224425iA364FAE54FFB7048/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (154).png" alt="Screenshot (154).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151030#M1114616</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-25T12:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151040#M1114617</link>
      <description>&lt;P&gt;Thank you, that's very helpful! I located that PDF and will review it.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151040#M1114617</guid>
      <dc:creator>willb1</dc:creator>
      <dc:date>2024-07-25T12:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower file inspection/malware detection rule placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151049#M1114618</link>
      <description>&lt;P&gt;you are so welcome&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-file-inspection-malware-detection-rule-placement/m-p/5151049#M1114618</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-25T12:23:30Z</dc:date>
    </item>
  </channel>
</rss>

