cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2560
Views
0
Helpful
2
Replies

Rule filtering on Specific SID's on Firepower device

Scott112
Level 1
Level 1

Hi,

 

I have multiple specific SID's that I specifically want to disable across multiple intrusion policies on a Cisco Firepower device as part of a tuning process. Unfortunately when entering the SID's with a , deliminintaor into the filter from the rules page via the Intrusion policy window is not producing any results. I have also tried filtering GID:SID, SID;, [SID]. When searching for a single SID I can obtain a result.

 

Is anyone aware of a way I can achieve this, I do not want to filter based on categories but multiple specific SID's. Do I need to use regex to deliminate? Thanks in advance. 

2 Replies 2

Austin Clark
Level 1
Level 1

Any updates on this????

 

It seems like any keywords entered are just stringed together with invisible 'and' statements. Basically can we use 'or' statements in the rule filter

Hi Austin, negative.

Search bar has an implicit AND to any/all keywords.

Review Cisco Networking for a $25 gift card