collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Author Topic: very few intrusion in firesight  (Read 5889 times)

Offline vivekkupekar

  • Cisco Newbie
  • *
  • Posts: 2
  • Reputation: 0
  • Certification: CCIE
very few intrusion in firesight
« on: August 19, 2015, 11:36:50 PM »
Hi All,

We have deployed ASA firepower with firesight. Right now we send a copy of all the ASA traffic to firepower module and using monitor only command. There are around 40 users at the site where firepower is deployed. We are using security over connectivity policy. Hence we are expecting that a large number of intrusion so that we can fine tune them.

However we see only 1 or 2 alerts in a week. In a similar type of deployment for IPS (2 years bacj) we had a lot of false positives which we tuned later.

Is is true that firepower generate very few alerts as it is more intelligent than IPS? or Do we have a mis configuration?

Thanks,
Vivek

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 398
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: very few intrusion in firesight
« Reply #1 on: August 20, 2015, 11:17:32 PM »
This is an interesting question. I don't think we can compare the amount of IPS event on FirePower to Cisco traditional IPS as they are two very different products and sets of signature. It is also possible that signatures that are relevant to your environment may be disabled by default in the base template and that's why it is usually recommended to run FireSight recommendation. If you are curious, since you are still in monitor-only, you can create a user layer and enable all signatures and see if you get more events and tune them down like you said.

Offline vivekkupekar

  • Cisco Newbie
  • *
  • Posts: 2
  • Reputation: 0
  • Certification: CCIE
Re: very few intrusion in firesight
« Reply #2 on: August 21, 2015, 12:12:13 PM »
Thanks for the reply, MC!

Let me check if creating a new policy with all signature enabled helps... I will keep you posted

 

Related Topics

  Subject / Started by Replies Last post
1 Replies
6149 Views
Last post March 01, 2016, 11:45:35 PM
by MC
9 Replies
12059 Views
Last post April 14, 2016, 06:33:26 PM
by Pacerfan9
1 Replies
7057 Views
Last post September 18, 2017, 08:42:49 PM
by Administrator

SimplePortal 2.3.7 © 2008-2024, SimplePortal