<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc/m-p/5278976#M1120495</link>
    <description>&lt;P&gt;I don't know any "IDF" term in relation to FMC. &lt;/P&gt;
&lt;P&gt;In telecommunications, IDF is usually used to mean "Intermediate Distribution Frame" - a term used in building cabling.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 13:31:30 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-04-07T13:31:30Z</dc:date>
    <item>
      <title>FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/5278972#M1120494</link>
      <description>&lt;P&gt;I need a solution to suppress the IDF alert in FMC.&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 13:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/5278972#M1120494</guid>
      <dc:creator>anuoluwapo-bankole</dc:creator>
      <dc:date>2025-04-07T13:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/5278976#M1120495</link>
      <description>&lt;P&gt;I don't know any "IDF" term in relation to FMC. &lt;/P&gt;
&lt;P&gt;In telecommunications, IDF is usually used to mean "Intermediate Distribution Frame" - a term used in building cabling.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 13:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/5278976#M1120495</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-04-07T13:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/5278977#M1120496</link>
      <description>&lt;P&gt;&lt;A target="_blank" rel="noopener"&gt;@Marvin Rhoads&lt;/A&gt;, I am so sorry.&amp;nbsp;I meant IDS Alert&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 13:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/5278977#M1120496</guid>
      <dc:creator>anuoluwapo-bankole</dc:creator>
      <dc:date>2025-04-07T13:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/5279036#M1120502</link>
      <description>&lt;P&gt;OK, for IDS then, see below.&lt;/P&gt;
&lt;P&gt;In general, you should carefully consider why you want to suppress a rule and only proceed if you have a thorough understanding of the implications.&lt;/P&gt;
&lt;P&gt;Methods to Suppress IPS Rules:&lt;/P&gt;
&lt;P&gt;1. Adjust Rule State in Intrusion Policy:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Navigate to the Intrusion Policy in the FMC. Locate the specific IPS rule you want to suppress. &lt;BR /&gt;Change the rule state to "Disabled" to stop processing the rule or "Generate Events" to only log events without blocking traffic. &lt;BR /&gt;Alternatively, you can set the rule to "Drop and Generate Events" to both drop the traffic and generate an event.&lt;/P&gt;
&lt;P&gt;2. Create an Access Control Rule to Bypass Inspection:&lt;/P&gt;
&lt;P&gt;Create a new access control rule that matches the traffic you want to bypass IPS inspection for.&lt;/P&gt;
&lt;P&gt;Ensure the new rule is placed above the rule with the IPS policy configured. &lt;BR /&gt;Set the action of the new rule to "Trust" or "Allow" to bypass inspection.&lt;/P&gt;
&lt;P&gt;3. Create a New IPS Policy with Disabled Rules:&lt;/P&gt;
&lt;P&gt;Create a new IPS policy with the specific rules disabled for the traffic you want to exempt.&lt;/P&gt;
&lt;P&gt;4. Create a new access control rule that references the new IPS policy.&lt;/P&gt;
&lt;P&gt;Set the action of the new access control rule to "Allow".&lt;/P&gt;
&lt;P&gt;Suppression and Thresholding:&lt;/P&gt;
&lt;P&gt;You can configure suppression and thresholding for specific IPS rules to control the number of events generated.&lt;/P&gt;
&lt;P&gt;This can help prevent the Firepower device from being overloaded with events during high-volume attacks. &lt;BR /&gt;You can configure suppression based on source or destination IP addresses or networks. &lt;BR /&gt;Thresholding allows you to define a limit on the number of events generated within a specific time interval.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 16:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/5279036#M1120502</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-04-07T16:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: FMC</title>
      <link>https://community.cisco.com/t5/network-security/fmc/m-p/5279845#M1120554</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;Thank you so much.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 16:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc/m-p/5279845#M1120554</guid>
      <dc:creator>anuoluwapo-bankole</dc:creator>
      <dc:date>2025-04-09T16:53:25Z</dc:date>
    </item>
  </channel>
</rss>

