Cisco Cisco FirePOWER Appliance 7115

Seite von 2442
Version 5.3
Sourcefire 3D System User Guide
722
Configuring Intrusion Policies
Managing Intrusion Policies
Chapter 19
The following table explains the most common actions taken when editing an 
intrusion policy:
Common Intrusion Policy Editing Actions 
T
O
...
Y
OU
 
CAN
...
specify a different drop 
behavior in an inline 
deployment
select or clear the Drop when Inline check box. 
See 
 on page 735 for more 
information.
select a different base policy
click Select Base Policy. See 
information.
view the advanced settings 
that are enabled by default in 
your base policy
click Manage Base Policy. Se
more information.
tailor variables and variable 
sets for your specific 
network environment
display or modify configured 
rule attributes for the rules in 
your intrusion policy
click Manage Rules. See 
 on page 744 for more 
information.
display a filtered view of the 
intrusion policy Rules page 
showing rules enabled in 
your policy by current rule 
state and, optionally, set rule 
attributes for specified rules
click View next to the number of rules under 
Manage Rules that are set to Generate Events 
or to Drop and Generate Events. See 
page 744 for more information.
display the FireSIGHT 
Recommended Rules 
configuration page
click FireSIGHT Recommendations in the 
navigation panel. Alternately, click Click here to 
set up FireSIGHT recommendations on the Policy 
Information page if you have not generated 
recommendations, or Click to change 
recommendations if you have generated 
recommendations. See 
for more information.