cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
154
Views
1
Helpful
2
Replies

Firepower - Intrustion Policy - Recommendations

Ralphy006
Level 1
Level 1

Hi all,

What's the general consensus about FMC's IPS recommendations? I currently run a base policy of "balanced security and connectivity".

Currently, my IPS is 477 alert rules, 9512 block rules. I ran the recommendations, and it went to 1 alert rule, 334 block rules.

Should I be running a the "recommendations" throughout the year? Or just leave it as the base?

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Assuming the network discovery policy and variable set are properly defined, I recommend using the recommendations with a monthly (re)application.

Security level 

1- level1 connectivity over secuirty 

2- level2 balanced secuirty and connectivity 

3- level3 secuirty over connectivity 

4- level4 max detection 

By defualt ftd run level2 and it OK' it balance between ftd throughput (which effect connectivity) and scan for traffic 

MHM

Review Cisco Networking for a $25 gift card