09-21-2008 11:42 AM - edited 03-11-2019 06:47 AM
Hello All,
I was wondering if anyone has made practical uses of the ASA's Modular Framework Policy, especially in creating customized inspection engines via creating inspection-policy maps and matching regex expressions in the inspection-policy. How does a firewall administrator know what inspection-policy map to create and implement to keep up with the latest security threats? What resources or forums can a firewall administrator go to to find security threats that can be thwarted by creating inspection-policy maps? I see this as a very powerful tool, but where does one begin?
09-22-2008 12:07 AM
Hi,
The first step, as always, is to identify what threats you are trying to protect against. Once you know what to block, you should create a semi-formal policy definition and use the CCO documentation to tranfer this to the ASA.
In terms of forums, this one is pretty good for specific queries; CCO and Google are your friends.
HTH
09-22-2008 04:10 AM
I will probably dig through CCO. Thanks for the suggestion
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide