Tuesday, October 16, 2018

Firepower Health Policy Configuration

In this article I'm going to show you how to create Health Policy on Cisco Firepower, This is a very important feature that can help you monitor your devices for many things and you can send to SNMP manager or view locally, ok let's begin:

1. Go to System > Health > Policy

2. This page will require a policy Description > I'm going to use (FMC Initial Health Policy)

3. below the description you can see a list of many sensors that you can either enable or disable them

some of these items you may not need for a license reasons like in my case I dont have URL or VPN license so I don't need to enable these two.

other than that I'm going to enable the following:

1. Policy Run Time Interval (I'm going to use each 5 Minutes) :this will run health check every 5 minutes.

2. AMP status for the endpoints

3. AMP firepower status

4. Appliance Heartbeat > very important to check if devices are online

5. Automatic Application bypass monitoring

6.Backlog Status

7. CPU, Memory, Disk Status, Disk Usage, ....etc.

After Finishing your list, you can save and Apply it to your devices:

Go to Health > Policy > apply option :

this will lead you to the list of devices:










Press apply and Good Luck!










No comments:

Post a Comment

Python-Jinja template configuration generator for Cisco devices and printout configs to external text files

 In this post, I worked on collecting a code that works with Jinja template. the nice thing in working with Jinja is that you can have basel...