<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC 6.2 Portscan alerting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3358223#M926266</link>
    <description>&lt;P&gt;You should be able to see it in the events before waiting for a report, if you know a portscan is taking place.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Mar 2018 19:07:51 GMT</pubDate>
    <dc:creator>Brett Walters</dc:creator>
    <dc:date>2018-03-30T19:07:51Z</dc:date>
    <item>
      <title>FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3301026#M926245</link>
      <description>&lt;P&gt;This may be an obvious answer - as in a bad idea - but is there no way to have the FMC/FPwr sensors generate an email alert when being portscanned?&amp;nbsp; The policy is working and dropping traffic as it should, and has been - but I can't find the proper item to enable to get it to email like it does for other malware events and email attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And as a side note - shouldn't it drop traffic leaving the network like this?&amp;nbsp; It definitely drops incoming port scans, but if you port scan out, it doesn't seem to care.&amp;nbsp; Maybe a missed configuration - but if something internally decided to scan out, it would be good to block or know about it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3301026#M926245</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2020-02-21T15:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3302735#M926247</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Maybe you can create a correlation policy for that?&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/correlation_policies.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/correlation_policies.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;br, Micke</description>
      <pubDate>Wed, 27 Dec 2017 10:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3302735#M926247</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-12-27T10:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3308259#M926249</link>
      <description>&lt;P&gt;I will take a look - it just didn't make sense I can get alerts on a ton of other things, but not that.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 12:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3308259#M926249</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-01-09T12:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3327151#M926251</link>
      <description>&lt;P&gt;I am also looking for this feature.&amp;nbsp; It seems that it used to be available based on:&amp;nbsp; &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Detecting_Specific_Threats.html#ID-2236-0000021b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Detecting_Specific_Threats.html#ID-2236-0000021b&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However when I try to follow the instructions I get to Policies/Intrusion and had to create the Network Analysis Policy.&amp;nbsp; I only had the Initial inline policy listed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After creating the Network Analysis Policy I tried to continue with the instructions.&amp;nbsp; I don't see a Settings however I do see an Advanced Settings so I selected that. I do not see Portscan Detection under Specific Threat Detection. All I have is Sensitive Data Detection.&amp;nbsp; I am stuck at this point.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 23:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3327151#M926251</guid>
      <dc:creator>Steven Carnahan</dc:creator>
      <dc:date>2018-02-07T23:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3341283#M926253</link>
      <description>&lt;P&gt;I haven't forgotten this - just tied up with a huge Mobility Controller issue at the same site.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3341283#M926253</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-03-02T15:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349099#M926255</link>
      <description>&lt;P&gt;See attached.&amp;nbsp; This is when I edit my Network Analysis Policy.&amp;nbsp; Settings should be top left (you have to click on it to see the options), and Portscan Detection is down a bit.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 11:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349099#M926255</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-03-15T11:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349322#M926257</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/9020i9E1062C3067D5BDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="capture.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;capture.png&lt;/span&gt;&lt;/span&gt;I apparently have a different view.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349322#M926257</guid>
      <dc:creator>Steven Carnahan</dc:creator>
      <dc:date>2018-03-15T16:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349326#M926259</link>
      <description>&lt;P&gt;You are in the Intrusion Policy. Not the network analysis policy. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policies &amp;gt; Access Control &amp;gt; Intrusion &amp;gt; Network Analysis Policy in the top right &amp;gt;Create or Edit that policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349326#M926259</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-03-15T16:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349331#M926261</link>
      <description>&lt;P&gt;Well don't I feel foolish.&amp;nbsp; I have a Network Analysis Policy listed under the Intrusion Policy.&amp;nbsp; I suppose I should remove that one.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349331#M926261</guid>
      <dc:creator>Steven Carnahan</dc:creator>
      <dc:date>2018-03-15T16:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349332#M926263</link>
      <description>&lt;P&gt;Heh, not at all.&amp;nbsp; It's not like it is a simple or logical process flow to deploy FMC!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3349332#M926263</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-03-15T16:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3358207#M926265</link>
      <description>&lt;P&gt;Well I was able to make the proper changes with your guidance however I have not yet seen any report so not sure if it worked yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 18:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3358207#M926265</guid>
      <dc:creator>Steven Carnahan</dc:creator>
      <dc:date>2018-03-30T18:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2 Portscan alerting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3358223#M926266</link>
      <description>&lt;P&gt;You should be able to see it in the events before waiting for a report, if you know a portscan is taking place.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 19:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-portscan-alerting/m-p/3358223#M926266</guid>
      <dc:creator>Brett Walters</dc:creator>
      <dc:date>2018-03-30T19:07:51Z</dc:date>
    </item>
  </channel>
</rss>

