09-23-2020 10:03 AM
Hi friends,
I have two FTD's in Failover with virtual FMC in version 6.4. I configured an Intrusion Policy, Balanced Security and Connectivity, and I applied the Intrusion feature in some of my access control policy rules.
What do you recommend me to prove that the IPS is working correctly? I need to see the intrusion events logs.
Regards,
JG
Solved! Go to Solution.
09-26-2020 10:04 PM - edited 09-26-2020 10:04 PM
To check if the intrusion policy is working as expected, enable ICMP signature (PROTOCOL-ICMP Echo Reply - SID 408) and test by sending ICMP pings through the firepower.
By default ICMP Echo Reply signature is Disabled. Change the rule state to 'Generate Events'.
Note: Make sure to 'Commit Changes' under Intrusion Policy > Policy Information.
09-26-2020 10:04 PM - edited 09-26-2020 10:04 PM
To check if the intrusion policy is working as expected, enable ICMP signature (PROTOCOL-ICMP Echo Reply - SID 408) and test by sending ICMP pings through the firepower.
By default ICMP Echo Reply signature is Disabled. Change the rule state to 'Generate Events'.
Note: Make sure to 'Commit Changes' under Intrusion Policy > Policy Information.
10-13-2020 03:09 PM
Thanks manabans.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide