Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Labels

Forum Posts

Hi,I have deployed Security Onion using snort2 system. I am getting alerts for some ET rules how to find the equivalent rule to block it on FMC/FTD.suppose I have below . how to find snort3 equivalant and block it as its passed by fmc/ftd and our ids...

Wonxie by Level 1
  • 330 Views
  • 2 replies
  • 1 Helpful votes

Assuming you're using FMC, how would you exclude a given IP address from a specific IPS alert?  For example, system traffic was blocked due to a specific malware definition but it was determined that the traffic was legitimate and you only want to ex...

david by Level 1
  • 7265 Views
  • 11 replies
  • 0 Helpful votes

Hello community, we are operating Cisco IPS sensors connected to FTD, however we noticed the category WEB-applications in the signature list it generates every month a lot of false positive alerts. I'm able to disable specific revision of signatures ...

rick11 by Level 1
  • 715 Views
  • 2 replies
  • 0 Helpful votes

Dear Cisco IDS/IPS Experts,I have two questions:1. Can the Firepower IDS/IPS detect Layer-2 attack based on EtherType and MAC address anomalies?2. Based on my experience 4-5 years ago, no IDS/IPS can detect Advanced Persistent Threat (APT). The anoma...

AudieO by Level 1
  • 1533 Views
  • 5 replies
  • 0 Helpful votes

Hi, looking for some help. i am working on a firewall with 750 rules. most of these rules are not set to log. is there any way to apply logging (at end) to a select bunch of rules in one hit. or am i looking at clicking 750 rules one at a time to swi...

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card