FirePOWER Intrusion Policy Rules not generating events
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2018 09:05 AM - edited 02-21-2020 07:49 AM
So I am currently trying to get my IPS to generate events for when executables are downloaded. I have went in to my intrusion policy, enabled the rule for executable downloads to generate events and set the threshold for 1 count every 10 seconds. I also have my $EXTERNAL_NET and $HOME_NET variables configured properly. I set my intrusion policy inside of my ACP and set it to log at the beginning and end of connections as well, but when I try to generate events nothing shows up EVER. If anyone has any ideas as to why this is I would greatly appreciate as surfing the web turns up almost not similar topics.
- Labels:
-
IPS and IDS
