<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSA 5.2 - Assigning Groups in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011621#M80404</link>
    <description>&lt;P&gt;When adding hosts to a group, for example, does a SQL Server get both SQL Server Group and Servers - All Types assigned or is the SQL Server Group good enough?  Also, is it best to use the default group or clone the group/s?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:02:36 GMT</pubDate>
    <dc:creator>kerraj2004</dc:creator>
    <dc:date>2019-03-10T11:02:36Z</dc:date>
    <item>
      <title>CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011621#M80404</link>
      <description>&lt;P&gt;When adding hosts to a group, for example, does a SQL Server get both SQL Server Group and Servers - All Types assigned or is the SQL Server Group good enough?  Also, is it best to use the default group or clone the group/s?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011621#M80404</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2019-03-10T11:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011622#M80405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For #1 I use both groups since they have different policies.  That way they have common Windows server and SQL specific protections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#2 depends on your preferences.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I leave them in the default groups and make changes to exception rule modules and policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Makes upgrades and patching easier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Mar 2008 17:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011622#M80405</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-03-24T17:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011623#M80407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;exactly, i'm just looking to make upgrades easy.  You will create new policies and rules under the Default Groups, correct?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Mar 2008 17:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011623#M80407</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2008-03-24T17:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011624#M80409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I create them for the default groups but put them in a separate policy.  This keeps the groups clean for upgrade simplicity (usually).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Mar 2008 18:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011624#M80409</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-03-24T18:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011625#M80410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, just so i understand what you are doing. You use the default groups and then create NEW rules  that get attached to the NEW Policy.  Once the all created the new policy gets attached to the default group, correct?  Im just trying to simplify the upgrade/hotfix process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and sorry for it being so wordy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Mar 2008 18:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011625#M80410</guid>
      <dc:creator>kerraj2004</dc:creator>
      <dc:date>2008-03-24T18:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: CSA 5.2 - Assigning Groups</title>
      <link>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011626#M80411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adam, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's pretty much how I do it.  The exceptions are when it makes more sense to exclude an application class from certain rules rather than create an exception.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way it it only has to process it once.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still have to go through the rules, modules and policies after every upgrade to make sure the exceptions still apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fortunately that happens only a couple of times a year and it's usually immediately apparent if the exceptions aren't working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Mar 2008 21:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csa-5-2-assigning-groups/m-p/1011626#M80411</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2008-03-24T21:38:32Z</dc:date>
    </item>
  </channel>
</rss>

