cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
865
Views
5
Helpful
3
Replies

Firepower Problem

John
Level 1
Level 1

Hi Cisco Community,

We would like to seek your help on my inquiries.

  1.  How can I see the signatures that the ASA with FirePOWER being used?
  2. How can I see how the firepower detecting?
  3. How can I do testing the dropping of connection using my desktop as an attacker/source of Intrusion?
3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

Do you have a working ASA with FirePOWER module?

What model ASA and version of FirePOWER software?

How are you managing it - FireSIGHT / FirePOWER Management Center or integrated into ASDM?

1. Generally FirePOWER doesn't use "rules". It uses a combination of settings from the Vulnerability database (VDB) and Snort Rules Update (SRU) that combine in your Intrusion and Access policies.

2. There are many many analysis tools in the manager. 

3. Look at connections and filter the display to show your desktop as source IP address.

 3. Look at the connections and filter the display to show your desktop as source IP address. - where I can find this one?

Hi,

On defense center. On top Click on Analysis >Connections . Then click on Edit Search , Networking and add the initiator IP as your desktop IP address.

Regards,

Aastha Bhardwaj

Rate if that helps!!!

Review Cisco Networking for a $25 gift card