06-24-2025 12:15 PM
Hi all,
What's the general consensus about FMC's IPS recommendations? I currently run a base policy of "balanced security and connectivity".
Currently, my IPS is 477 alert rules, 9512 block rules. I ran the recommendations, and it went to 1 alert rule, 334 block rules.
Should I be running a the "recommendations" throughout the year? Or just leave it as the base?
06-24-2025 11:10 PM
Assuming the network discovery policy and variable set are properly defined, I recommend using the recommendations with a monthly (re)application.
06-25-2025 03:40 AM
Security level
1- level1 connectivity over secuirty
2- level2 balanced secuirty and connectivity
3- level3 secuirty over connectivity
4- level4 max detection
By defualt ftd run level2 and it OK' it balance between ftd throughput (which effect connectivity) and scan for traffic
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide