cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
224
Views
0
Helpful
1
Replies

CSA rule modules

ciscors
Level 1
Level 1

1) When I need to modify a rule, should I simply clone the rule or the entire rule module it belongs to. Cisco advises one of this to maintain the original rules for future use

2) Is there anything else I should be cloning?

Thank you

1 Reply 1

tsteger1
Level 8
Level 8

Hi Rajiv,

You can always create exceptions to rules instead of modifying the rule itself. If you know you want to change a rule rather than creating an exception, cloning rules inside a rule module and modifying the clone should be sufficient.

One of the downsides to cloning and/or modifying original rules is when you do upgrades to the MC. It will create new rules and append the old version number to your existing rules. This can be tedious to sort out so that you maintain all the modifications you have already accomplished.

This is where making exceptions to existing rules and keeping them in a separate policy can come in handy.

Hope this helps..

Tom S