<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC reporting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-reporting/m-p/3386624#M957245</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a pair of 4150 FTDs being managed by an FMC 1000. As part of our policy configuration we have a default action of deny for any traffic that does not match an allow policy. We also have logging enabled for this rule. I was looking to create a report that showed the top number of flows (source-&amp;gt;destination with associated ports) based on the amount of times the flow had hit the deny policy to allow us to quickly identify devices that are potentially misconfigured to reduce the amount of unnecessary processing the firewall has to complete. I took a look in the report templates and can't find anywhere obvious I can enable this? Is this at all possible?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:47:44 GMT</pubDate>
    <dc:creator>darren-carr</dc:creator>
    <dc:date>2020-02-21T15:47:44Z</dc:date>
    <item>
      <title>FMC reporting</title>
      <link>https://community.cisco.com/t5/network-security/fmc-reporting/m-p/3386624#M957245</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a pair of 4150 FTDs being managed by an FMC 1000. As part of our policy configuration we have a default action of deny for any traffic that does not match an allow policy. We also have logging enabled for this rule. I was looking to create a report that showed the top number of flows (source-&amp;gt;destination with associated ports) based on the amount of times the flow had hit the deny policy to allow us to quickly identify devices that are potentially misconfigured to reduce the amount of unnecessary processing the firewall has to complete. I took a look in the report templates and can't find anywhere obvious I can enable this? Is this at all possible?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-reporting/m-p/3386624#M957245</guid>
      <dc:creator>darren-carr</dc:creator>
      <dc:date>2020-02-21T15:47:44Z</dc:date>
    </item>
  </channel>
</rss>

