<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tuning - Best Performance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tuning-best-performance/m-p/1564252#M66393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best practice would say that you should remove signatures which are not important - which should decrease inspection load a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you need to think of one thing before doing this:&lt;/P&gt;&lt;P&gt;Am I only interested in attacks againt my infrastructure? (Victims in my network)&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;Am I interested to check for attack related to my infrastructure? (sourse or victims in my network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apart from the obvious question - what happens if you do install HP open view - will you remember you turned off this signture? &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said, I understand you already went past the stage where you monitored your traffic in promiscous mode for several weeks and are confident what you actually have in your network - you identified signatures firing false positives and trimmed them. If so, you can also disable some default signatures not related to your infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will you see a superior gain of performance - I doubt so. But it's a good place to start.&lt;/P&gt;&lt;P&gt;Next up:&lt;/P&gt;&lt;P&gt;- changing normalizer mode&lt;/P&gt;&lt;P&gt;- disabling not needed engines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Oct 2010 08:03:09 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2010-10-01T08:03:09Z</dc:date>
    <item>
      <title>Tuning - Best Performance</title>
      <link>https://community.cisco.com/t5/network-security/tuning-best-performance/m-p/1564251#M66391</link>
      <description>&lt;P&gt;In tuning my signatures for products we do not have, such as HP Openview&lt;SPAN style="background-color: #f8fafd;"&gt;;&amp;nbsp; what is the best practice, or what offers the best performance- leaving them in the default state, or disabling them?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-best-performance/m-p/1564251#M66391</guid>
      <dc:creator>trippi</dc:creator>
      <dc:date>2019-03-10T12:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tuning - Best Performance</title>
      <link>https://community.cisco.com/t5/network-security/tuning-best-performance/m-p/1564252#M66393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best practice would say that you should remove signatures which are not important - which should decrease inspection load a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you need to think of one thing before doing this:&lt;/P&gt;&lt;P&gt;Am I only interested in attacks againt my infrastructure? (Victims in my network)&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;Am I interested to check for attack related to my infrastructure? (sourse or victims in my network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apart from the obvious question - what happens if you do install HP open view - will you remember you turned off this signture? &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said, I understand you already went past the stage where you monitored your traffic in promiscous mode for several weeks and are confident what you actually have in your network - you identified signatures firing false positives and trimmed them. If so, you can also disable some default signatures not related to your infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will you see a superior gain of performance - I doubt so. But it's a good place to start.&lt;/P&gt;&lt;P&gt;Next up:&lt;/P&gt;&lt;P&gt;- changing normalizer mode&lt;/P&gt;&lt;P&gt;- disabling not needed engines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 08:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tuning-best-performance/m-p/1564252#M66393</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-10-01T08:03:09Z</dc:date>
    </item>
  </channel>
</rss>

