cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1797
Views
0
Helpful
1
Replies

Do Firepower Recommendations "trickle down"?

jharding91
Level 1
Level 1

If I create a hierarchical IPS policy set, for instance:

 

IDS-ROOT w/ a base policy of Balanced Security and Connections

IPS-ROOT w/ a base policy of IDS-ROOT

 

and I run Firepower Recommendations on the IDS-ROOT policy, do they trickle down to the child policy?

 

I have used the rule comparison feature in FMC and it doesn't look like they do from that point of view so I wanted to verify that I should be running recommendations on all policies instead of just my root policy.

 

Thanks!

1 Reply 1

Greg Smalley
Level 1
Level 1

The cumulative effect of the all the layers trickle down to policies that inherit them.  An easy way to tell is to look at the number of rules set to drop and generate events on a child policy, run and use recommended rules on the master policy, and then look at how the number of rules set to drop and generate has changed on the child policy.  If there are no other enabled or disabled rules the amount of drop and generate rules should match in both policies.

 

Pre-Rules-Change.pngPost-2.png

 

Review Cisco Networking for a $25 gift card