cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4286
Views
0
Helpful
3
Replies

Firepower Intrusion detection: How to disable/whitelist rule for spesific hosts?

cisco
Level 1
Level 1

Hi,

I have implemented Firepower Intrusion detection on my ASA 5525-X, and how a question: One of the rules blocks traffic between 2 hosts, but I do not want this traffic to be blocked between these hosts. I want the rule to be active, but how can I prevent the rule to block traffic between these 2 hosts, while blocking traffic for other hosts that are hit by the rule?

Br,

Thor-Egil

1 Accepted Solution

Accepted Solutions

Boris Uskov
Level 4
Level 4

Hello, this can be achived by implementing Access control rule for those two hosts. Let's assume, you need to disable IPS Policy for traffic between 192.168.1.5 and 172.16.1.5. Inseret the new access rule above the rule with IPS policy configured. Choose the "trust" action for new rule. See the attach.

Alternatively, if you don't want to disable IPS between two hosts completely, you can create a new IPS policy with the signature which blocks traffic between two hosts currently setted to disabled state. After that create the new access rule as in the first example but with action "Allow", and implement a new IPS policy with disabled signature.

View solution in original post

3 Replies 3

Boris Uskov
Level 4
Level 4

Hello, this can be achived by implementing Access control rule for those two hosts. Let's assume, you need to disable IPS Policy for traffic between 192.168.1.5 and 172.16.1.5. Inseret the new access rule above the rule with IPS policy configured. Choose the "trust" action for new rule. See the attach.

Alternatively, if you don't want to disable IPS between two hosts completely, you can create a new IPS policy with the signature which blocks traffic between two hosts currently setted to disabled state. After that create the new access rule as in the first example but with action "Allow", and implement a new IPS policy with disabled signature.

Thanks, your first solution will work for me.

Br,

Thor-Egil

Thanks so much. This was the solution I needed for fix a Site-Site Hyper-V replication problem.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card