<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Analysis Policies in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334586#M925997</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;I have kept network analysis policies in a passive mode ( default mode) but the access control policies has default action of IPS that means if the traffic doesn't match it will pass by the IPS,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;have not enabled a network analysis policies&amp;nbsp;that means a firepower is not configured properly or I can keep passive &lt;FONT color="#ff0000"&gt;Network analysis policy&lt;/FONT&gt; and Inline &lt;FONT color="#ff0000"&gt;IPS&lt;/FONT&gt; that makes more sense&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;I shld keep both inline.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:22:59 GMT</pubDate>
    <dc:creator>adamgibs7</dc:creator>
    <dc:date>2020-02-21T15:22:59Z</dc:date>
    <item>
      <title>Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334586#M925997</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;I have kept network analysis policies in a passive mode ( default mode) but the access control policies has default action of IPS that means if the traffic doesn't match it will pass by the IPS,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;have not enabled a network analysis policies&amp;nbsp;that means a firepower is not configured properly or I can keep passive &lt;FONT color="#ff0000"&gt;Network analysis policy&lt;/FONT&gt; and Inline &lt;FONT color="#ff0000"&gt;IPS&lt;/FONT&gt; that makes more sense&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;I shld keep both inline.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334586#M925997</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334611#M925998</link>
      <description>&lt;P&gt;How is the sensor deployed? What is the policy map settings if its ASA+FP?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 21:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334611#M925998</guid>
      <dc:creator>babiojd01</dc:creator>
      <dc:date>2018-02-20T21:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334759#M925999</link>
      <description>&lt;P&gt;A network analysis policy governs how traffic is decoded and preprocessed so that it can be further evaluated, especially for anomalous traffic that might signal an intrusion attempt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you put NAP policy in passive, means traffic won't be dropped by any of the pre-processors if it matches with those GIDs. (&lt;SPAN&gt;preprocessors&amp;nbsp;won't affect the traffic).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We should keep both in Inline mode.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dv&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 03:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334759#M925999</guid>
      <dc:creator>Dinesh Verma</dc:creator>
      <dc:date>2018-02-21T03:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334893#M926000</link>
      <description>&lt;P&gt;If I am keeping only one &amp;nbsp;inline will it be a high security risk ??&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 08:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3334893#M926000</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-02-21T08:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3335392#M926001</link>
      <description>&lt;P&gt;anybody can justify the below, if I keep only one in inline does it will be&amp;nbsp;considered as a high security risk.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 19:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3335392#M926001</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-02-21T19:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Network Analysis Policies</title>
      <link>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3335450#M926002</link>
      <description>Hello Team,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The network analysis as stated, is where the Snort preprocessors reside. They are mainly used to normalize the traffic. If its inline and there is some anomalous traffic, it can be dropped here.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We cannot state if this would be a security vulnerability for you since we do not know your network.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I can do tell that most customer have it Inline/ dropping with the Balanced Security and Connectivity policy as the default.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[cid:image002.png@01D3AB2D.C8339CA0]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thus normally, a default/basic environment,  I recommend the Inline Mode for the Network Analysis Policy and the Intrusion Prevention Policy. With Balanced Security and Connectivity as the Base Policy.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If the policy is passive, you will just need to ensure to review your logs more often and take action on any IPS events.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 21 Feb 2018 21:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-analysis-policies/m-p/3335450#M926002</guid>
      <dc:creator>argrullo</dc:creator>
      <dc:date>2018-02-21T21:06:02Z</dc:date>
    </item>
  </channel>
</rss>

