02-20-2018 12:29 PM - edited 02-21-2020 07:22 AM
Dears,
I have kept network analysis policies in a passive mode ( default mode) but the access control policies has default action of IPS that means if the traffic doesn't match it will pass by the IPS,
I have not enabled a network analysis policies that means a firepower is not configured properly or I can keep passive Network analysis policy and Inline IPS that makes more sense
OR
I shld keep both inline.
02-20-2018 01:08 PM
How is the sensor deployed? What is the policy map settings if its ASA+FP?
02-20-2018 07:18 PM
A network analysis policy governs how traffic is decoded and preprocessed so that it can be further evaluated, especially for anomalous traffic that might signal an intrusion attempt.
if you put NAP policy in passive, means traffic won't be dropped by any of the pre-processors if it matches with those GIDs. (preprocessors won't affect the traffic).
We should keep both in Inline mode.
Regards,
Dv
02-21-2018 12:47 AM
If I am keeping only one inline will it be a high security risk ??
02-21-2018 11:29 AM
anybody can justify the below, if I keep only one in inline does it will be considered as a high security risk.
02-21-2018 01:06 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide