cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2588
Views
0
Helpful
1
Replies

Cisco FMC critical and major email alert

Adnan Khan
Level 4
Level 4

Hi,

 

I would like to configure Cisco FMC for email alerts notification for critical and major alerts. Any critical or major alerts triggered on FMC for FTD should receive an email notification. Can anyone share the procedure for that?

 

Thanks

1 Reply 1

Michael ONeil
Level 1
Level 1

When you ask for email alerts for Critical and Major events, I assume you mean for IPS events. These IPS events are catgorized by their Impact Flags. These events can be sent as an email alert.

Go to System Configuration and setup an email server and the from and to email addresses.

Then go to Policies, Alerts, Responses and create an email alert using the email server you setup in the System Configuration.

Then click the Impact Flags Events tab and select "email" and use the Email alert you created. Then at the bottom of that window select the Impact Flags you want to be alerted about. Note: I recommend only Impact Flags "1" as the rest of them will inundate and fill up your email inbox. Impact Flag 1 are those IPS events that are 99% true and not likely a false positive.

 

See this for reference:

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/fpmc-config-guide-v60_chapter_01110000.html

 

and 

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_for_intrusion_events.pdf

 

hope this helps

 

:)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card