cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2018
Views
15
Helpful
5
Replies

Firepower - anyone using security over connectivity or Maximum detection

evan.chadwick1
Level 1
Level 1

Thinking to select a group of important well defined hosts and apply a stricter IPS level. 
Anyone using the above policies? Moved from balanced security to a stricter policy?

5 Replies 5

Philip D'Ath
VIP Alumni
VIP Alumni

We have been trialling that mode for about 3 months.  We get maybe 1 false positive every month to two months.  Note that we are typically only using "business" web sites, with not that much variation.  If your users are accessing a wider variety of sites you may get different results.

Overall, we have decided to accept that odd false positive and leave it on preferring security.

Which mode? Max detection or security over connectivity?

Thanks, 

Evan

Security over Connectivity.

Rahul Govindan
VIP Alumni
VIP Alumni

I have used the security over connectivity policy once before. I have not seen a lot of differences compared to the balanced policy. I do see more low impact signatures (not suspicious) being hit with this policy.

Marvin Rhoads
Hall of Fame
Hall of Fame

FYI, please see below for a high-level comparison of the options.

Source: 

BRKSEC-3121 Firepower Threat Defence Advanced Capabilities Deployment and Troubleshooting Options (2017 Melbourne)

https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=94771

Connectivity over Security: ~ 500 Rules
• CVSS Score of 10
• Age of Vulnerability: 2 year and newer


Balanced : ~ 7200 Rules
• CVSS Score of 9 or greater
• Age of Vulnerability: 2 year and newer
• Rule category equals Malware-CnC, blacklist, SQL Injection, Exploit-kit


Security over Connectivity: ~ 10000 Rules
• CVSS Score of 8 or greater
• Age of Vulnerability: 3 years and newer
• Rule category equals Malware-CnC, blacklist, SQL Injection, Exploit-kit, App-detect

Review Cisco Networking for a $25 gift card