<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Intelligence Application Bypass in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/intelligence-application-bypass/m-p/3942800#M17952</link>
    <description>&lt;P&gt;My customer is receiving alerts for the PkgCatalog.z file. The customer is telling me it is a McAfee file. I cannot create a Clean List for this file since the hash is always changing. I am attempting to use IAB so I can trust the file and eliminate the file alerts. I have configured IAB with the only two Available Application choices, McAfee and McAfee AutoUpdate. I have the flow options low so the file can trigger at least one of the option for the FMC to evaluate the file and trust the file. So far, this has not worked.&lt;/P&gt;&lt;P&gt;I would like to know if anyone has used IAB with McAfee? If I am going in the wrong direction, any suggestions would be greatly appreciated. Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2019 19:11:13 GMT</pubDate>
    <dc:creator>msanclimenti</dc:creator>
    <dc:date>2019-10-17T19:11:13Z</dc:date>
    <item>
      <title>Intelligence Application Bypass</title>
      <link>https://community.cisco.com/t5/network-security/intelligence-application-bypass/m-p/3942800#M17952</link>
      <description>&lt;P&gt;My customer is receiving alerts for the PkgCatalog.z file. The customer is telling me it is a McAfee file. I cannot create a Clean List for this file since the hash is always changing. I am attempting to use IAB so I can trust the file and eliminate the file alerts. I have configured IAB with the only two Available Application choices, McAfee and McAfee AutoUpdate. I have the flow options low so the file can trigger at least one of the option for the FMC to evaluate the file and trust the file. So far, this has not worked.&lt;/P&gt;&lt;P&gt;I would like to know if anyone has used IAB with McAfee? If I am going in the wrong direction, any suggestions would be greatly appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 19:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intelligence-application-bypass/m-p/3942800#M17952</guid>
      <dc:creator>msanclimenti</dc:creator>
      <dc:date>2019-10-17T19:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Intelligence Application Bypass</title>
      <link>https://community.cisco.com/t5/network-security/intelligence-application-bypass/m-p/3942812#M17967</link>
      <description>&lt;P&gt;IAB is not used for such scenarios, usually IAB identifies applications that you trust to traverse your network without further inspection if performance and flow thresholds are exceeded. For example, if a nightly backup significantly impacts system performance, you can configure thresholds that, if exceeded, trust traffic generated by your backup application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i recommend you to do is to trust&amp;nbsp; Mcafee as an application by using&amp;nbsp; application filter with an access policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 19:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intelligence-application-bypass/m-p/3942812#M17967</guid>
      <dc:creator>hassan.mehsen</dc:creator>
      <dc:date>2019-10-17T19:37:19Z</dc:date>
    </item>
  </channel>
</rss>

