<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When you say that the rule is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migrating-to-ips-mode/m-p/3016021#M42880</link>
    <description>&lt;P&gt;When you say that the rule is making the result "would have been dropped" is that an access control rule, or the actual IDS/IPS policy making that verdict?&lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 08:15:46 GMT</pubDate>
    <dc:creator>Dennis Perto</dc:creator>
    <dc:date>2017-05-24T08:15:46Z</dc:date>
    <item>
      <title>Migrating to IPS mode</title>
      <link>https://community.cisco.com/t5/network-security/migrating-to-ips-mode/m-p/3016020#M42878</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We are currently running our 8250's in an IDS mode and we are changing to an IPS mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have lots of rules which are now resulting in a "would be block", that is going to change to a Block result. To ease the migration I'm looking for ways of slowly moving to Block results.&lt;/P&gt;
&lt;P&gt;I'm thinking of dividing the 'would be block' rules into groups and changing the the result of those groups initial to monitor and group after group changing the results back to block.&lt;/P&gt;
&lt;P&gt;Is this a sane idea and if so what is a decent way of dividing the rules into groups?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Henk Fictorie&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:50:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-to-ips-mode/m-p/3016020#M42878</guid>
      <dc:creator>Henk Fictorie - Ulrich</dc:creator>
      <dc:date>2019-03-10T13:50:30Z</dc:date>
    </item>
    <item>
      <title>When you say that the rule is</title>
      <link>https://community.cisco.com/t5/network-security/migrating-to-ips-mode/m-p/3016021#M42880</link>
      <description>&lt;P&gt;When you say that the rule is making the result "would have been dropped" is that an access control rule, or the actual IDS/IPS policy making that verdict?&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 08:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-to-ips-mode/m-p/3016021#M42880</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2017-05-24T08:15:46Z</dc:date>
    </item>
  </channel>
</rss>

