<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower Threat Intelligence Director Elements. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-thread-intellegence-director-elements/m-p/3417892#M902113</link>
    <description>&lt;P&gt;Have you checked the following? I have done this in my lab and the managed devices (FTDv in my case) show up fine. (Note the embedded links won't work as they are taken from my FMC server's help page.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="topictitle1"&gt;Configure Policies to Support &lt;SPAN&gt;TID&lt;/SPAN&gt;&lt;/H1&gt;
&lt;DIV&gt;
&lt;DIV class="section"&gt;
&lt;DIV class="tasklabel"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="tablenoborder"&gt;&lt;A target="_blank" name="id_55372__table_mnf_3fc_t1b"&gt;&lt;/A&gt;
&lt;TABLE border="1" summary="" width="90%" frame="border" rules="all" cellspacing="0" cellpadding="3"&gt;
&lt;THEAD align="left"&gt;
&lt;TR&gt;
&lt;TH id="d2936589e20" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Smart License&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e25" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Classic License&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e30" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Supported Devices&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e35" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Supported Domains&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e40" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Access&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Global&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Admin/Threat Intelligence Director (TID) User&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;You must configure access control policies to publish &lt;SPAN&gt;TID&lt;/SPAN&gt; data from the &lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt; to your managed devices (elements). In addition, we recommend that you configure your access control policies to maximize observation and &lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt; event generation.&lt;/P&gt;
&lt;P&gt;For each managed device that you want to support &lt;SPAN&gt;TID&lt;/SPAN&gt;, perform the steps below to configure the associated access control policy.&lt;/P&gt;
&lt;P&gt;Elements that are configured to use &lt;SPAN&gt;TID&lt;/SPAN&gt; after data has been published will automatically receive all currently-published observables.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="tasklabel"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;HR noshade="noshade" /&gt;
&lt;TABLE class="stepTable" border="0" width="90%" cellspacing="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;1&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Verify that the &lt;SPAN class="uicontrol"&gt;Enable Threat Intelligence Director&lt;/SPAN&gt; check box is checked in the &lt;SPAN class="uicontrol"&gt;Advanced Settings&lt;/SPAN&gt; tab of the access control policy. This option is enabled by default. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/r_Access_Control_Policy_Advanced_Settings.html" target="_blank"&gt;Access Control Policy Advanced Settings&lt;/A&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;2&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Add rules to the access control policy if they are not already present. TID requires that the access control policy specify at least one rule. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Creating_a_Basic_Access_Control_Policy.html#ID-2176-00000240" target="_blank"&gt;Creating a Basic Access Control Policy&lt;/A&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;3&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;If you want &lt;SAMP class="codeph"&gt;SHA-256&lt;/SAMP&gt; observables to generate observations and Firepower Management Center events: &lt;/SPAN&gt;
&lt;OL type="a"&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Create a file policy containing one or more &lt;SPAN class="uicontrol"&gt;Malware Cloud Lookup&lt;/SPAN&gt; or &lt;SPAN class="uicontrol"&gt;Block Malware&lt;/SPAN&gt; file rules.&lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Configuring_an_Access_Control_Rule_to_Perform_File_Control_and_Malware_Protection.html" target="_blank"&gt;Configuring an Access Control Rule to Perform File Control and AMP&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Associate this file policy with one or more rules in the access control policy.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;4&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;If you want &lt;SAMP class="codeph"&gt;IPv4&lt;/SAMP&gt;, &lt;SAMP class="codeph"&gt;IPv6&lt;/SAMP&gt;, &lt;SAMP class="codeph"&gt;URL&lt;/SAMP&gt;, or &lt;SAMP class="codeph"&gt;Domain Name&lt;/SAMP&gt; observations to generate connection and security intelligence events, enable connection and security intelligence logging in the access control policy:&lt;/SPAN&gt;
&lt;OL type="a"&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;In access control rules where you invoked a file policy, enable &lt;SPAN class="uicontrol"&gt;Log at End of Connection&lt;/SPAN&gt; and &lt;SPAN class="uicontrol"&gt;File Events: Log Files&lt;/SPAN&gt;, if not already enabled. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Logging_Connections_with_Access_Control_Rules.html" target="_blank"&gt;Logging Connections with Access Control Rules&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Verify that default logging (&lt;SPAN class="uicontrol"&gt;DNS Policy&lt;/SPAN&gt;, &lt;SPAN class="uicontrol"&gt;Networks&lt;/SPAN&gt;, and &lt;SPAN class="uicontrol"&gt;URLs&lt;/SPAN&gt;) is enabled in your Security Intelligence settings. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Logging_Connections_with_Security_Intelligence.html" target="_blank"&gt;Logging Connections with Security Intelligence&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Deploy configuration changes; see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_deploying_configuration_changes.html#task_75E181687ECF4EFC8EB6AF4509C20C0B" target="_blank"&gt;Deploying Configuration Changes&lt;/A&gt;.&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR noshade="noshade" /&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 19 Jul 2018 03:07:44 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-07-19T03:07:44Z</dc:date>
    <item>
      <title>Firepower Thread Intellegence Director Elements.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-thread-intellegence-director-elements/m-p/3417722#M902112</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I was just looking into setting up the TID feature on Firepower management center. I have most of it configured, but my SFR modules are not showing up as "Elements" under the Intelligence tab. I have Access policies running on all of my modules, what else specifically needs to be set up to be able to tie the modules to the TID?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FMC &lt;SPAN&gt;6.2.3 (build 79)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;SFR 6.2&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-thread-intellegence-director-elements/m-p/3417722#M902112</guid>
      <dc:creator>nkingsbury</dc:creator>
      <dc:date>2020-02-21T16:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower Threat Intelligence Director Elements.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-thread-intellegence-director-elements/m-p/3417892#M902113</link>
      <description>&lt;P&gt;Have you checked the following? I have done this in my lab and the managed devices (FTDv in my case) show up fine. (Note the embedded links won't work as they are taken from my FMC server's help page.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="topictitle1"&gt;Configure Policies to Support &lt;SPAN&gt;TID&lt;/SPAN&gt;&lt;/H1&gt;
&lt;DIV&gt;
&lt;DIV class="section"&gt;
&lt;DIV class="tasklabel"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="tablenoborder"&gt;&lt;A target="_blank" name="id_55372__table_mnf_3fc_t1b"&gt;&lt;/A&gt;
&lt;TABLE border="1" summary="" width="90%" frame="border" rules="all" cellspacing="0" cellpadding="3"&gt;
&lt;THEAD align="left"&gt;
&lt;TR&gt;
&lt;TH id="d2936589e20" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Smart License&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e25" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Classic License&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e30" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Supported Devices&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e35" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Supported Domains&lt;/P&gt;
&lt;/TH&gt;
&lt;TH id="d2936589e40" class="cellrowborder" valign="top" width="NaN%"&gt;
&lt;P&gt;Access&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Global&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="NaN%" valign="top" class="cellrowborder"&gt;
&lt;P&gt;Admin/Threat Intelligence Director (TID) User&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;You must configure access control policies to publish &lt;SPAN&gt;TID&lt;/SPAN&gt; data from the &lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt; to your managed devices (elements). In addition, we recommend that you configure your access control policies to maximize observation and &lt;SPAN&gt;Firepower Management Center&lt;/SPAN&gt; event generation.&lt;/P&gt;
&lt;P&gt;For each managed device that you want to support &lt;SPAN&gt;TID&lt;/SPAN&gt;, perform the steps below to configure the associated access control policy.&lt;/P&gt;
&lt;P&gt;Elements that are configured to use &lt;SPAN&gt;TID&lt;/SPAN&gt; after data has been published will automatically receive all currently-published observables.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="tasklabel"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;HR noshade="noshade" /&gt;
&lt;TABLE class="stepTable" border="0" width="90%" cellspacing="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;1&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Verify that the &lt;SPAN class="uicontrol"&gt;Enable Threat Intelligence Director&lt;/SPAN&gt; check box is checked in the &lt;SPAN class="uicontrol"&gt;Advanced Settings&lt;/SPAN&gt; tab of the access control policy. This option is enabled by default. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/r_Access_Control_Policy_Advanced_Settings.html" target="_blank"&gt;Access Control Policy Advanced Settings&lt;/A&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;2&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Add rules to the access control policy if they are not already present. TID requires that the access control policy specify at least one rule. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Creating_a_Basic_Access_Control_Policy.html#ID-2176-00000240" target="_blank"&gt;Creating a Basic Access Control Policy&lt;/A&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;3&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;If you want &lt;SAMP class="codeph"&gt;SHA-256&lt;/SAMP&gt; observables to generate observations and Firepower Management Center events: &lt;/SPAN&gt;
&lt;OL type="a"&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Create a file policy containing one or more &lt;SPAN class="uicontrol"&gt;Malware Cloud Lookup&lt;/SPAN&gt; or &lt;SPAN class="uicontrol"&gt;Block Malware&lt;/SPAN&gt; file rules.&lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Configuring_an_Access_Control_Rule_to_Perform_File_Control_and_Malware_Protection.html" target="_blank"&gt;Configuring an Access Control Rule to Perform File Control and AMP&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Associate this file policy with one or more rules in the access control policy.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;4&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;If you want &lt;SAMP class="codeph"&gt;IPv4&lt;/SAMP&gt;, &lt;SAMP class="codeph"&gt;IPv6&lt;/SAMP&gt;, &lt;SAMP class="codeph"&gt;URL&lt;/SAMP&gt;, or &lt;SAMP class="codeph"&gt;Domain Name&lt;/SAMP&gt; observations to generate connection and security intelligence events, enable connection and security intelligence logging in the access control policy:&lt;/SPAN&gt;
&lt;OL type="a"&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;In access control rules where you invoked a file policy, enable &lt;SPAN class="uicontrol"&gt;Log at End of Connection&lt;/SPAN&gt; and &lt;SPAN class="uicontrol"&gt;File Events: Log Files&lt;/SPAN&gt;, if not already enabled. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Logging_Connections_with_Access_Control_Rules.html" target="_blank"&gt;Logging Connections with Access Control Rules&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="substepexpand"&gt;&lt;SPAN&gt;Verify that default logging (&lt;SPAN class="uicontrol"&gt;DNS Policy&lt;/SPAN&gt;, &lt;SPAN class="uicontrol"&gt;Networks&lt;/SPAN&gt;, and &lt;SPAN class="uicontrol"&gt;URLs&lt;/SPAN&gt;) is enabled in your Security Intelligence settings. &lt;/SPAN&gt;
&lt;P&gt;For more information, see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_Logging_Connections_with_Security_Intelligence.html" target="_blank"&gt;Logging Connections with Security Intelligence&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD align="left" valign="top" class="td_faq"&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/TD&gt;
&lt;TD valign="top" class="td_faq"&gt;&lt;SPAN&gt;Deploy configuration changes; see &lt;A href="https://fmc.ccielab.mrneteng.com/help_files/t_deploying_configuration_changes.html#task_75E181687ECF4EFC8EB6AF4509C20C0B" target="_blank"&gt;Deploying Configuration Changes&lt;/A&gt;.&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;HR noshade="noshade" /&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 19 Jul 2018 03:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-thread-intellegence-director-elements/m-p/3417892#M902113</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-07-19T03:07:44Z</dc:date>
    </item>
  </channel>
</rss>

