09-05-2017 07:20 PM - edited 02-21-2020 06:16 AM
Hi,
I have multiple specific SID's that I specifically want to disable across multiple intrusion policies on a Cisco Firepower device as part of a tuning process. Unfortunately when entering the SID's with a , deliminintaor into the filter from the rules page via the Intrusion policy window is not producing any results. I have also tried filtering GID:SID, SID;, [SID]. When searching for a single SID I can obtain a result.
Is anyone aware of a way I can achieve this, I do not want to filter based on categories but multiple specific SID's. Do I need to use regex to deliminate? Thanks in advance.
02-21-2018 07:50 AM - edited 02-21-2018 09:22 AM
Any updates on this????
It seems like any keywords entered are just stringed together with invisible 'and' statements. Basically can we use 'or' statements in the rule filter
02-21-2018 11:19 AM
Hi Austin, negative.
Search bar has an implicit AND to any/all keywords.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide