05-18-2016 06:35 PM - edited 03-12-2019 06:01 AM
So as I read through the Sourcefire User Doc i am starting to get confused about the actual application of network analysis policies. So I know you can pick a default analysis policy via the Access control policy in the advanced section if none match. When reading the advanced documentation it appears that the packets will "pick" a network analysis policy based on the policies created? Can someone clarify this for me?
Solved! Go to Solution.
05-18-2016 10:44 PM
Hi
You can create a customer NAP (network analysis policy) but it needs to be selected in advance section of access control policy. If default policy is selected there, default policy will be applied.
There is an option where you can create custom rules for custom NAP. For example, you want to use the default 1 for all traffic and for specific network, need a custom NAP. You can do that in advance section of access control policy.
Rate if helps.
Yogesh
05-18-2016 10:44 PM
Hi
You can create a customer NAP (network analysis policy) but it needs to be selected in advance section of access control policy. If default policy is selected there, default policy will be applied.
There is an option where you can create custom rules for custom NAP. For example, you want to use the default 1 for all traffic and for specific network, need a custom NAP. You can do that in advance section of access control policy.
Rate if helps.
Yogesh
05-19-2016 05:16 AM
I forgot all about that section. :) I think it would make more sense to move that out of there due to the confusion of policy application.
11-17-2016 06:26 AM
What about Network Analysis Policy/ Rate-Based Attack Prevention/ Control Simultaneous Connections option, is there a more detailed explanation on how it really works?
The documentation describes: The rate-based action stops only after a sampling period completes where the sampled rate is below the threshold rate. Where does "sampling period" configuration take place?
Thanks in advance
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide