cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2216
Views
0
Helpful
3
Replies

IPS Enabling - Balance Security and Connectivity

Fantas
Level 1
Level 1

Hi,

 

I am enabling IPS poly with "Balance Security and Connectivity" in our production environment.

 

This IPS enabling is not going to break anything in production environment right and will only generate intrusion events.

 

Even it sees a malicious traffic but still will not block/drop it and will only generate intrusion event in logs.

 

we running FTS2100

3 Replies 3

If you want to create the intrusion policy in passive mode which will alert you but it will not drop the traffic in that case

create a policy"Drop when Inline" uncheck this and apply it to you FTD. by doing so it will only generate and log the event but this will not drop the packet. Its kind of a passive mode. it sees it but cant drop it.

 

TEST2.PNG

please do not forget to rate.

Hi,

 

I am not creating any IPS policy and using default one " Balance Security and Connectivity"

 

So wana make sure , This will not break anything in production If I enable it with ACP.

If you do only as you say - use the built-in Balanced Security and connectivity policy where no IPS policy is currently in use - you may start blocking some malicious traffic. That policy is set to drop certain events deemed as intrusions. It should not drop any legitimate traffic but not some organizations choose to allow traffic that even a moderately conservative default policy may block.

There are several ways to avoid this, the most common of which was already suggested by @Sheraz.Salim 

Review Cisco Networking for a $25 gift card