Cisco Cisco FirePOWER Appliance 7115
Version 5.3
Sourcefire 3D System User Guide
722
Configuring Intrusion Policies
Managing Intrusion Policies
Chapter 19
The following table explains the most common actions taken when editing an
intrusion policy:
Common Intrusion Policy Editing Actions
T
O
...
Y
OU
CAN
...
specify a different drop
behavior in an inline
deployment
select or clear the Drop when Inline check box.
See
on page 735 for more
information.
select a different base policy
click Select Base Policy. See
on page 737 for more
information.
view the advanced settings
that are enabled by default in
your base policy
click Manage Base Policy. See
more information.
tailor variables and variable
sets for your specific
network environment
display or modify configured
rule attributes for the rules in
your intrusion policy
click Manage Rules. See
on page 744 for more
information.
display a filtered view of the
intrusion policy Rules page
showing rules enabled in
your policy by current rule
state and, optionally, set rule
attributes for specified rules
click View next to the number of rules under
Manage Rules that are set to Generate Events
or to Drop and Generate Events. See
page 744 for more information.
display the FireSIGHT
Recommended Rules
configuration page
click FireSIGHT Recommendations in the
navigation panel. Alternately, click Click here to
set up FireSIGHT recommendations on the Policy
Information page if you have not generated
recommendations, or Click to change
recommendations if you have generated
recommendations. See
for more information.