Hi friends,
I have two FTD's in Failover with virtual FMC in version 6.4. I configured an Intrusion Policy, Balanced Security and Connectivity, and I applied the Intrusion feature in some of my access control policy rules.
What do you recommend me to prove that the IPS is working correctly? I need to see the intrusion events logs.
Regards,
JG
Solved! Go to Solution.
To check if the intrusion policy is working as expected, enable ICMP signature (PROTOCOL-ICMP Echo Reply - SID 408) and test by sending ICMP pings through the firepower.
By default ICMP Echo Reply signature is Disabled. Change the rule state to 'Generate Events'.
Note: Make sure to 'Commit Changes' under Intrusion Policy > Policy Information.
To check if the intrusion policy is working as expected, enable ICMP signature (PROTOCOL-ICMP Echo Reply - SID 408) and test by sending ICMP pings through the firepower.
By default ICMP Echo Reply signature is Disabled. Change the rule state to 'Generate Events'.
Note: Make sure to 'Commit Changes' under Intrusion Policy > Policy Information.
Thanks manabans.