10-29-2017 09:50 PM - edited 02-21-2020 06:35 AM
Hi guys,
I successfully deployed firepower IPS. I'm just wondering what is the use of the button "Associate" in the Dynamic Analysis section?
Thanks
11-21-2017 03:29 PM
thanks marvin,
By the way i was referring to AMP on the FTD firewalls and not AMP for endpoints.
Vaibhav
07-01-2018 02:47 PM
where does Cisco Mention the 100 Files, and is this per license, for eg if you have an Active pair of Firewalls runnings Firepower, do you 100 x 2 per 24 hours.
How does Firepower indicate when the 100 file limit is exceeded? Is it via the word of 'unknown' as a classification type?
11-20-2018 07:17 PM
Sorry the correct number is currently 200. See the link I posted on 11/152017. It is 200 for your organization. You need to purchase ThreatGrid Analysis packs to exceed that number.
When you exceed it you will get a warning message in your FMC. If you're not a current ThreatGrid customer, you can also request access to a mini-ThreatGrid portal if you want to see exactly how many files are being submitted.
11-20-2018 07:28 PM
11-20-2018 07:32 PM
Assuming you have your File policy in FMC set to submit unknown files to the cloud for analysis, Cisco will analyze them on the backend (up to 200 per day) using the ThreatGrid sandbox and other techniques.
You do not have access to the sandbox videos and detailed dynamic analysis data for files submitted thus - only the disposition that is reported back to your FMC.
If you submit manually using ThreatGrid then you have access to the full analysis details.
11-20-2018 07:39 PM
11-20-2018 04:31 PM
Is this information for FireAMP for Networks, file submission to the threatgrid? We already have a threatgrid. But we are not getting the expected results.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide