<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue about Custom IPS Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010198#M925629</link>
    <description>&lt;P&gt;When i learning Firepower Intrusion Policy, i create a IPS Rule like the picture, i want to block traffic from test-pc to http server when the uri contain "configure" keyword, but it not work properly. i didn't see the intrusion events.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:01:09 GMT</pubDate>
    <dc:creator>yangui319</dc:creator>
    <dc:date>2020-02-21T14:01:09Z</dc:date>
    <item>
      <title>Issue about Custom IPS Rules</title>
      <link>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010198#M925629</link>
      <description>&lt;P&gt;When i learning Firepower Intrusion Policy, i create a IPS Rule like the picture, i want to block traffic from test-pc to http server when the uri contain "configure" keyword, but it not work properly. i didn't see the intrusion events.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010198#M925629</guid>
      <dc:creator>yangui319</dc:creator>
      <dc:date>2020-02-21T14:01:09Z</dc:date>
    </item>
    <item>
      <title>Add metadata with service</title>
      <link>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010199#M925630</link>
      <description>&lt;P&gt;Add metadata with service http. See whether it fires now.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When you test, add logging to the ACP rule and provide with the connection event screenshot (from the table view of events, multiple screenshots to cover all the fields) associated with the test you're performing.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 19:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010199#M925630</guid>
      <dc:creator>Claudiu Cismaru</dc:creator>
      <dc:date>2017-02-16T19:50:49Z</dc:date>
    </item>
    <item>
      <title>I configure two intrusion</title>
      <link>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010200#M925631</link>
      <description>&lt;P&gt;I configure two intrusion rule:intrusion rule "http certsrv" and intrusion rule "http configure". Like the picture, but when i test it, the "http certsrv" is work properly, but the "http configure" didn't. use windows server 2008 as web server for test about "http certsrv", use Cisco IOS as web server for test "http configure".&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 01:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010200#M925631</guid>
      <dc:creator>yangui319</dc:creator>
      <dc:date>2017-02-17T01:29:46Z</dc:date>
    </item>
    <item>
      <title>I couldn't reproduce your</title>
      <link>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010201#M925632</link>
      <description>&lt;P&gt;I couldn't reproduce your issue. For me it fires. Are you sure you deployed the ACP after making changes?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you provide the full connection event entry screenshot?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2017 09:01:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-about-custom-ips-rules/m-p/3010201#M925632</guid>
      <dc:creator>Claudiu Cismaru</dc:creator>
      <dc:date>2017-02-17T09:01:36Z</dc:date>
    </item>
  </channel>
</rss>

