<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trust host in Sourcefire IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trust-host-in-sourcefire-ips/m-p/3013096#M42806</link>
    <description>&lt;P&gt;We have deployed sourcefire 7125 with defence center 1500 recently.&lt;/P&gt;
&lt;P&gt;We get alot of alert through email about 10.1.1.10 with port 445, 10.1.1.10 is our share file server so that is normal to open that port in the server.&lt;/P&gt;
&lt;P&gt;How could we classify that 10.0.0.0/8 is allowed connect to 10.1.1.10:445 and wont get email alert any more.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:51:15 GMT</pubDate>
    <dc:creator>duyennv10</dc:creator>
    <dc:date>2019-03-10T13:51:15Z</dc:date>
    <item>
      <title>Trust host in Sourcefire IPS</title>
      <link>https://community.cisco.com/t5/network-security/trust-host-in-sourcefire-ips/m-p/3013096#M42806</link>
      <description>&lt;P&gt;We have deployed sourcefire 7125 with defence center 1500 recently.&lt;/P&gt;
&lt;P&gt;We get alot of alert through email about 10.1.1.10 with port 445, 10.1.1.10 is our share file server so that is normal to open that port in the server.&lt;/P&gt;
&lt;P&gt;How could we classify that 10.0.0.0/8 is allowed connect to 10.1.1.10:445 and wont get email alert any more.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trust-host-in-sourcefire-ips/m-p/3013096#M42806</guid>
      <dc:creator>duyennv10</dc:creator>
      <dc:date>2019-03-10T13:51:15Z</dc:date>
    </item>
    <item>
      <title>Create a new rule in your</title>
      <link>https://community.cisco.com/t5/network-security/trust-host-in-sourcefire-ips/m-p/3013097#M42808</link>
      <description>&lt;P&gt;Create a new rule in your Access Control Policy with those addresses in it and action "Trust". Make sure it is above any more general rules. Save and deploy.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2017 15:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trust-host-in-sourcefire-ips/m-p/3013097#M42808</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-03T15:49:11Z</dc:date>
    </item>
  </channel>
</rss>

