cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3273
Views
0
Helpful
7
Replies

Firepower 2100 running Transparent Mode

latenaite2011
Level 4
Level 4

Just wondering if the 2100 Firepower appliance is running in transparent mode and we allow all traffic through, how does it protect the traffic from malicious activity?

2 Accepted Solutions

Accepted Solutions

You just select the Default Action as shown below when creating your Access Control Policy:

 

Sample ACP.PNG

View solution in original post

Since it is not terminating the VPN it can do very little other than confirm that the packets conform to the IPsec protocol specification.

View solution in original post

7 Replies 7

Marvin Rhoads
Hall of Fame
Hall of Fame

Even if you don't have any block rules in your access control policy you should at the very least have a default Intrusion policy and use the Security Intelligence feed.

 

Most customers use the "balanced security and connectivity" intrusion policy. That intrusion policy will block intrusions with CVSS score 9 or greater from the current and past 2 years.

 

Please refer to Cisco Live presentation BRKSEC-3300 for more details.

Thank you for respond to this.

How should the default intrusion policy look like?

I should allow all traffic through so that it will get inspected and the
intrusion policy will block intrusions with CVSS score 9 or greater?

You just select the Default Action as shown below when creating your Access Control Policy:

 

Sample ACP.PNG

Thank you Marvin.  It was helpful.

Just curious if the Firepower can inspect Site-to-Site VPN through the Firepower.  Is there anything special that needs to be for it?

Since it is not terminating the VPN it can do very little other than confirm that the packets conform to the IPsec protocol specification.

Ok, thank you Marvin.

 

 

Review Cisco Networking for a $25 gift card