Cisco Cisco Firepower Management Center 4000

Page of 1844
 
29-4
FireSIGHT System User Guide
 
Chapter 29      Using Adaptive Profiles 
  Configuring Adaptive Profiles
To configure adaptive profiles:
Access: 
Admin/Intrusion Admin
Step 1
Select 
Policies > Intrusion > Intrusion Policy
.
The Intrusion Policy page appears.
Step 2
Click the edit icon (
) next to the policy you want to edit.
If you have unsaved changes in another policy, click 
OK
 to discard those changes and continue. See 
 for information on saving unsaved changes in another 
policy.
The Policy Information page appears.
Step 3
Click 
Advanced Settings
 in the navigation panel on the left.
The Advanced Settings page appears.
Step 4
You have two choices, depending on whether 
Adaptive Profiles
 under Detection Enhancement is enabled:
  •
If the configuration is enabled, click 
Edit
.
  •
If the configuration is disabled, click 
Enabled
, then click 
Edit
.
The Adaptive Profiles page appears.
A message at the bottom of the page identifies the intrusion policy layer that contains the configuration. 
See 
 for more information.
Step 5
Optionally, in the 
Attribute Update Interval
 field, type the number of minutes that should elapse between 
synchronization of network map data from the Defense Center to the managed device. 
Note
Increasing the value for 
Attribute Update Interval
 could improve performance in a large network.
Step 6
In the 
Networks
 field, type the specific IP address, address block, or variable, or a list that includes any 
of these addressing methods separated by commas, to identify any host in the network map for which 
you want to use adaptive profiles.
See 
 for information on configuring variables. See 
 for information on configuring the network map.
Step 7
Save your policy, continue editing, discard your changes, or exit while leaving your changes in the 
system cache. See the 
 table for more information.