Create A Signature Override

You can only create signature overrides for IPS rules that are already triggered on an FDM-managed device. When you create a signature override in Security Cloud Control, the override is automatically applies the configured action (Drop, Alert, Disabled, Default) to all of the policy levels.

Procedure


Step 1

In the left pane, click Insights & Reports > Firewall Threat Defense > Threats Dashboard (FDM).

Step 2

Select a threat from the table and expand it. In the Tune Actions pane, click Tune.

Step 3

Tune the rules as described in step 4 in the Firepower Intrusion Policy Signature Overrides procedure.

Step 4

Review and deploy now the changes you made, or wait and deploy multiple changes at once.