<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 2110 Snort3 problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208994#M1116578</link>
    <description>&lt;P&gt;It certainly sounds like you have performed much more than the typical troubleshooting on your own. I would agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt; that getting support would be the best move at this point. It's odd that management insists on enabling more advanced features but won't pay for TAC support.&lt;/P&gt;
&lt;P&gt;It wouldn't hurt to upgrade to 7.4.2.1 to get the latest bug fixes.&lt;/P&gt;
&lt;P&gt;Have you tried disabling the file policy (AMP) in the rules that have it enabled? I find file policies of quite limited value since 90% or more of Internet edge traffic is encrypted and thus not inspectable for Malware payloads (unless you have SSL decryption which only a very small percentage of customers do).&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2024 12:08:55 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2024-10-15T12:08:55Z</dc:date>
    <item>
      <title>FTD 2110 Snort3 problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208878#M1116572</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello everyone!&lt;/SPAN&gt; &lt;SPAN class=""&gt;In&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;organization&lt;/SPAN&gt;&lt;SPAN&gt; we &lt;/SPAN&gt;&lt;SPAN class=""&gt;have&lt;/SPAN&gt; &lt;SPAN class=""&gt;two&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cisco&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;2110s&lt;/SPAN&gt;&lt;SPAN&gt; managed by &lt;/SPAN&gt;&lt;SPAN class=""&gt;FMC and &lt;/SPAN&gt;&lt;SPAN class=""&gt;configured&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;HA&lt;/SPAN&gt; &lt;SPAN class=""&gt;pair&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Until&lt;/SPAN&gt; &lt;SPAN class=""&gt;recently&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;they&lt;/SPAN&gt; &lt;SPAN class=""&gt;functioned&lt;/SPAN&gt; &lt;SPAN class=""&gt;as&lt;/SPAN&gt; &lt;SPAN class=""&gt;regular&lt;/SPAN&gt; &lt;SPAN class=""&gt;stateful L3-L4&lt;/SPAN&gt; &lt;SPAN class=""&gt;firewalls&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;However&lt;/SPAN&gt;&lt;SPAN&gt;, a &lt;/SPAN&gt;&lt;SPAN class=""&gt;couple&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;months&lt;/SPAN&gt; &lt;SPAN class=""&gt;ago&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;authorities&lt;/SPAN&gt; &lt;SPAN class=""&gt;demanded&lt;/SPAN&gt;&lt;SPAN&gt; that high-&lt;/SPAN&gt;&lt;SPAN class=""&gt;level&lt;/SPAN&gt; &lt;SPAN class=""&gt;filtering&lt;/SPAN&gt;&lt;SPAN&gt; be &lt;/SPAN&gt;&lt;SPAN class=""&gt;enabled&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; them&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;At&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;7.3.0&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;configuring&lt;/SPAN&gt; &lt;SPAN class=""&gt;IPS&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;took&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;Balanced&lt;/SPAN&gt; &lt;SPAN class=""&gt;Security&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;Connectivity&lt;/SPAN&gt; &lt;SPAN class=""&gt;policy&lt;/SPAN&gt;&lt;SPAN&gt; as &lt;/SPAN&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;basis&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;turned&lt;/SPAN&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco&lt;/SPAN&gt; &lt;SPAN class=""&gt;recommendations&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Everything&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;fine&lt;/SPAN&gt;&lt;SPAN&gt; for a &lt;/SPAN&gt;&lt;SPAN class=""&gt;month&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;FW&lt;/SPAN&gt; &lt;SPAN class=""&gt;worked&lt;/SPAN&gt; &lt;SPAN class=""&gt;stably&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;During&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt; &lt;SPAN class=""&gt;month&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;added&lt;/SPAN&gt; &lt;SPAN class=""&gt;several&lt;/SPAN&gt; &lt;SPAN class=""&gt;URL&lt;/SPAN&gt; &lt;SPAN class=""&gt;rules&lt;/SPAN&gt; &lt;SPAN class=""&gt;based&lt;/SPAN&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;organization&lt;/SPAN&gt;&lt;SPAN&gt;'s &lt;/SPAN&gt;&lt;SPAN class=""&gt;security&lt;/SPAN&gt; &lt;SPAN class=""&gt;policy&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Then&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;decided&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;turn&lt;/SPAN&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;SPAN class=""&gt;AMP&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Two&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt; &lt;SPAN class=""&gt;after&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;we&lt;/SPAN&gt; &lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;Snort3 &lt;/SPAN&gt;&lt;SPAN&gt;crash &lt;/SPAN&gt;&lt;SPAN class=""&gt;with&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;error&lt;/SPAN&gt; &lt;EM&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;Primary&lt;/SPAN&gt; &lt;SPAN class=""&gt;Detection&lt;/SPAN&gt; &lt;SPAN class=""&gt;Engine&lt;/SPAN&gt; &lt;SPAN class=""&gt;process&lt;/SPAN&gt; &lt;SPAN class=""&gt;terminated&lt;/SPAN&gt; &lt;SPAN class=""&gt;unexpectedly&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;s&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;decided&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;jump&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;conclusions&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;left&lt;/SPAN&gt; &lt;SPAN class=""&gt;everything&lt;/SPAN&gt; &lt;SPAN class=""&gt;as&lt;/SPAN&gt;&lt;SPAN&gt; it &lt;/SPAN&gt;&lt;SPAN class=""&gt;is&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;could&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;determine&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;cause&lt;/SPAN&gt;&lt;SPAN&gt; of the &lt;/SPAN&gt;&lt;SPAN class=""&gt;crash&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;A&lt;/SPAN&gt; &lt;SPAN class=""&gt;week&lt;/SPAN&gt;&lt;SPAN&gt; later, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;situation&lt;/SPAN&gt; &lt;SPAN class=""&gt;repeated&lt;/SPAN&gt;&lt;SPAN&gt; itself &lt;/SPAN&gt;&lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;continued&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;repeat&lt;/SPAN&gt;&lt;SPAN&gt; for &lt;/SPAN&gt;&lt;SPAN class=""&gt;another&lt;/SPAN&gt; &lt;SPAN class=""&gt;month&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;once&lt;/SPAN&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;SPAN class=""&gt;twice&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;week&lt;/SPAN&gt; &lt;SPAN class=""&gt;we&lt;/SPAN&gt; &lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; Snort3 &lt;/SPAN&gt;&lt;SPAN class=""&gt;crash&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I &lt;/SPAN&gt;&lt;SPAN class=""&gt;found&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;Snort3&lt;/SPAN&gt; &lt;SPAN class=""&gt;could&lt;/SPAN&gt; &lt;SPAN class=""&gt;crash&lt;/SPAN&gt; &lt;SPAN class=""&gt;due&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;SMB&lt;/SPAN&gt; &lt;SPAN class=""&gt;traffic&lt;/SPAN&gt; &lt;SPAN class=""&gt;generated&lt;/SPAN&gt;&lt;SPAN&gt; by the &lt;/SPAN&gt;&lt;SPAN class=""&gt;attacker&lt;/SPAN&gt; &lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-smbsnort3-dos-pfOjOYUV" target="_self"&gt;&lt;SPAN class=""&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-smbsnort3-dos-pfOjOYUV&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The &lt;/SPAN&gt;&lt;SPAN class=""&gt;security&lt;/SPAN&gt; &lt;SPAN class=""&gt;department&lt;/SPAN&gt;&lt;SPAN&gt; and I did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;signs&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;penetration&lt;/SPAN&gt; &lt;SPAN class=""&gt;into&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;however&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;decided&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;exclude&lt;/SPAN&gt; &lt;SPAN class=""&gt;SMB&lt;/SPAN&gt; &lt;SPAN class=""&gt;traffic&lt;/SPAN&gt;&lt;SPAN&gt; by &lt;/SPAN&gt;&lt;SPAN class=""&gt;placing&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;Prefilter&lt;/SPAN&gt; &lt;SPAN class=""&gt;Policy&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;However&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;this&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;as&lt;/SPAN&gt; &lt;SPAN class=""&gt;expected&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt;&lt;SPAN&gt; did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;help&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;After&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt;&lt;SPAN&gt;, I &lt;/SPAN&gt;&lt;SPAN class=""&gt;decided&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;update&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;latest&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;available&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;7.4.1&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;After&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;update&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt; &lt;SPAN class=""&gt;went&lt;/SPAN&gt;&lt;SPAN&gt; away &lt;/SPAN&gt;&lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;3&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;But&lt;/SPAN&gt; &lt;SPAN class=""&gt;then&lt;/SPAN&gt; &lt;SPAN class=""&gt;hell&lt;/SPAN&gt; &lt;SPAN class=""&gt;broke&lt;/SPAN&gt;&lt;SPAN&gt; loose&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exactly&lt;/SPAN&gt; &lt;SPAN class=""&gt;three&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt;&lt;SPAN&gt; later, &lt;/SPAN&gt;&lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;around&lt;/SPAN&gt; &lt;SPAN class=""&gt;10&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN class=""&gt;30&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;began&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;miss&lt;/SPAN&gt; &lt;SPAN class=""&gt;traffic&lt;/SPAN&gt; &lt;SPAN class=""&gt;badly&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;almost&lt;/SPAN&gt; &lt;SPAN class=""&gt;all&lt;/SPAN&gt; &lt;SPAN class=""&gt;packets&lt;/SPAN&gt;&lt;SPAN&gt; were &lt;/SPAN&gt;&lt;SPAN class=""&gt;lost&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;those&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;reached&lt;/SPAN&gt; &lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;delay&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;2-3&lt;/SPAN&gt; &lt;SPAN class=""&gt;seconds&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Snort&lt;/SPAN&gt;&lt;SPAN&gt; crash &lt;/SPAN&gt;&lt;SPAN class=""&gt;and &lt;/SPAN&gt;&lt;SPAN class=""&gt;Failover, as it was recently, &lt;/SPAN&gt;&lt;SPAN&gt;did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;occur&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;There&lt;/SPAN&gt; &lt;SPAN class=""&gt;were&lt;/SPAN&gt;&lt;SPAN&gt; no &lt;/SPAN&gt;&lt;SPAN class=""&gt;fresh&lt;/SPAN&gt; &lt;SPAN class=""&gt;core&lt;/SPAN&gt; &lt;SPAN class=""&gt;files&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;ngfw&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;var&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;common&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;analogically&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;dmp&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;ngfw&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;var&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;log&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;ngfw&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;var&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;log&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;crashinfo&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Logs&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;ngfw&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;var&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;log&lt;/SPAN&gt;&lt;SPAN class=""&gt;/&lt;/SPAN&gt;&lt;SPAN class=""&gt;messages&lt;/SPAN&gt;&lt;SPAN&gt; are &lt;/SPAN&gt;&lt;SPAN class=""&gt;attached&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Also&lt;/SPAN&gt; &lt;SPAN class=""&gt;of&lt;/SPAN&gt; &lt;SPAN class=""&gt;note&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;load&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;CPU&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt;&lt;SPAN&gt; more &lt;/SPAN&gt;&lt;SPAN class=""&gt;precisely&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;6th&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;10th&lt;/SPAN&gt; &lt;SPAN class=""&gt;cores&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;cpu_load image&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;Packet&lt;/SPAN&gt; &lt;SPAN class=""&gt;Queue&lt;/SPAN&gt; &lt;SPAN class=""&gt;Receive&lt;/SPAN&gt; &lt;SPAN class=""&gt;Utilizaton&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;snort_load &lt;/SPAN&gt;&lt;SPAN class=""&gt;image&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Through&lt;/SPAN&gt; &lt;SPAN class=""&gt;top&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;looked&lt;/SPAN&gt;&lt;SPAN&gt; at &lt;/SPAN&gt;&lt;SPAN class=""&gt;which&lt;/SPAN&gt; &lt;SPAN class=""&gt;processes&lt;/SPAN&gt; &lt;SPAN class=""&gt;load&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;6&lt;/SPAN&gt; &lt;SPAN class=""&gt;core&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;top&lt;/SPAN&gt; &lt;SPAN class=""&gt;image&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;syslog&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;ng&lt;/SPAN&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;SPAN class=""&gt;fail2ban&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;server&lt;/SPAN&gt; &lt;SPAN class=""&gt;were&lt;/SPAN&gt; &lt;SPAN class=""&gt;constantly&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;top&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;couldn&lt;/SPAN&gt;&lt;SPAN&gt;'t draw &lt;/SPAN&gt;&lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;useful&lt;/SPAN&gt; &lt;SPAN class=""&gt;conclusions&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;make&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;switch&lt;/SPAN&gt; &lt;SPAN class=""&gt;node&lt;/SPAN&gt; &lt;SPAN class=""&gt;manually&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Everything&lt;/SPAN&gt; &lt;SPAN class=""&gt;worked&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;next&lt;/SPAN&gt; &lt;SPAN class=""&gt;day&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;exactly&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;situation&lt;/SPAN&gt; &lt;SPAN class=""&gt;happened&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;log&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;load&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;CPU&lt;/SPAN&gt; &lt;SPAN class=""&gt;cores, &lt;/SPAN&gt;&lt;SPAN class=""&gt;snort&lt;/SPAN&gt; &lt;SPAN class=""&gt;queue utilization and &lt;/SPAN&gt;&lt;SPAN&gt;syslog-ng, fail2ban-server in top output&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN&gt; at &lt;/SPAN&gt;&lt;SPAN class=""&gt;about&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt; &lt;SPAN class=""&gt;+&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;5&lt;/SPAN&gt; &lt;SPAN class=""&gt;minutes&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;had&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;manually&lt;/SPAN&gt;&lt;SPAN&gt; switch off &lt;/SPAN&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;FW&lt;/SPAN&gt; &lt;SPAN class=""&gt;again&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;For&lt;/SPAN&gt; &lt;SPAN class=""&gt;3&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt;&lt;SPAN&gt; was &lt;/SPAN&gt;&lt;SPAN class=""&gt;repeated&lt;/SPAN&gt; &lt;SPAN class=""&gt;day&lt;/SPAN&gt;&lt;SPAN&gt; after &lt;/SPAN&gt;&lt;SPAN class=""&gt;day&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;approximately&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;except&lt;/SPAN&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;SPAN class=""&gt;weekends&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;when&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;load&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;2-3&lt;/SPAN&gt; &lt;SPAN class=""&gt;times&lt;/SPAN&gt; &lt;SPAN class=""&gt;less&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;weekdays&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Since&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt; &lt;SPAN class=""&gt;appeared&lt;/SPAN&gt; &lt;SPAN class=""&gt;only&lt;/SPAN&gt; &lt;SPAN class=""&gt;3&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt; &lt;SPAN class=""&gt;after&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;update&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;decided&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt;&lt;SPAN&gt; had &lt;/SPAN&gt;&lt;SPAN class=""&gt;nothing&lt;/SPAN&gt;&lt;SPAN&gt; to do &lt;/SPAN&gt;&lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;ran&lt;/SPAN&gt;&lt;SPAN&gt; into &lt;/SPAN&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;new&lt;/SPAN&gt; &lt;SPAN class=""&gt;problem&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Apparently&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;some&lt;/SPAN&gt; &lt;SPAN class=""&gt;specific&lt;/SPAN&gt; &lt;SPAN class=""&gt;traffic&lt;/SPAN&gt; &lt;SPAN class=""&gt;appeared&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;disabled&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;although&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;fact&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt; &lt;SPAN class=""&gt;sounds&lt;/SPAN&gt; &lt;SPAN class=""&gt;strange&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;because&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt; &lt;SPAN class=""&gt;we&lt;/SPAN&gt;&lt;SPAN&gt; did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;introduce&lt;/SPAN&gt; &lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;new&lt;/SPAN&gt; &lt;SPAN class=""&gt;products&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;traffic&lt;/SPAN&gt; &lt;SPAN class=""&gt;could&lt;/SPAN&gt; &lt;SPAN class=""&gt;hardly&lt;/SPAN&gt; &lt;SPAN class=""&gt;change&lt;/SPAN&gt; &lt;SPAN class=""&gt;significantly&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; An &lt;/SPAN&gt;&lt;SPAN class=""&gt;experienced&lt;/SPAN&gt; &lt;SPAN class=""&gt;colleague&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;another&lt;/SPAN&gt; &lt;SPAN class=""&gt;organization&lt;/SPAN&gt; &lt;SPAN class=""&gt;advised&lt;/SPAN&gt; &lt;SPAN class=""&gt;me&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;exclude&lt;/SPAN&gt; &lt;SPAN class=""&gt;elephant&lt;/SPAN&gt; &lt;SPAN class=""&gt;flows&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt; a high-&lt;/SPAN&gt;&lt;SPAN class=""&gt;level&lt;/SPAN&gt; &lt;SPAN class=""&gt;inspection&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;since&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;his&lt;/SPAN&gt; &lt;SPAN class=""&gt;opinion&lt;/SPAN&gt; &lt;SPAN class=""&gt;these&lt;/SPAN&gt; &lt;SPAN class=""&gt;flows&lt;/SPAN&gt; &lt;SPAN class=""&gt;may&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;cause&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;failures&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;caught&lt;/SPAN&gt; &lt;SPAN class=""&gt;all&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;elephant&lt;/SPAN&gt; &lt;SPAN class=""&gt;flows&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;put&lt;/SPAN&gt; &lt;SPAN class=""&gt;them&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;prefilter&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt;&lt;SPAN&gt; didn&lt;/SPAN&gt;&lt;SPAN class=""&gt;'t&lt;/SPAN&gt; &lt;SPAN class=""&gt;help&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;After&lt;/SPAN&gt;&lt;SPAN&gt; that, I &lt;/SPAN&gt;&lt;SPAN class=""&gt;decided&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;exclude&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt; the high-&lt;/SPAN&gt;&lt;SPAN class=""&gt;level&lt;/SPAN&gt; &lt;SPAN class=""&gt;inspection&lt;/SPAN&gt; &lt;SPAN class=""&gt;all&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;threads&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt;&lt;SPAN&gt; were &lt;/SPAN&gt;&lt;SPAN class=""&gt;passing&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt; of the &lt;/SPAN&gt;&lt;SPAN class=""&gt;failure&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;It&lt;/SPAN&gt; &lt;SPAN class=""&gt;only&lt;/SPAN&gt; &lt;SPAN class=""&gt;helped&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;moments&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;failure&lt;/SPAN&gt;&lt;SPAN&gt;, the &lt;/SPAN&gt;&lt;SPAN class=""&gt;traffic&lt;/SPAN&gt;&lt;SPAN&gt; did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;completely&lt;/SPAN&gt; &lt;SPAN class=""&gt;stop&lt;/SPAN&gt;&lt;SPAN&gt; being &lt;/SPAN&gt;&lt;SPAN class=""&gt;skipped&lt;/SPAN&gt;&lt;SPAN&gt; by &lt;/SPAN&gt;&lt;SPAN class=""&gt;FTD&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;only&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;delay&lt;/SPAN&gt; &lt;SPAN class=""&gt;increased&lt;/SPAN&gt; &lt;SPAN class=""&gt;slightly&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;CPU&lt;/SPAN&gt; &lt;SPAN class=""&gt;load&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;snort&lt;/SPAN&gt; &lt;SPAN class=""&gt;queue&lt;/SPAN&gt; &lt;SPAN class=""&gt;utilization&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;processes&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;top&lt;/SPAN&gt; &lt;SPAN class=""&gt;remained&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;After&lt;/SPAN&gt;&lt;SPAN&gt; that, I &lt;/SPAN&gt;&lt;SPAN class=""&gt;decided&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;maybe&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt;&lt;SPAN&gt; was &lt;/SPAN&gt;&lt;SPAN class=""&gt;specifically&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;my&lt;/SPAN&gt; &lt;SPAN class=""&gt;hardware&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;no&lt;/SPAN&gt;&lt;SPAN&gt;… The &lt;/SPAN&gt;&lt;SPAN class=""&gt;new&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;unambiguously&lt;/SPAN&gt; &lt;SPAN class=""&gt;serviceable&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;same&lt;/SPAN&gt; &lt;SPAN class=""&gt;version&lt;/SPAN&gt; &lt;SPAN class=""&gt;7.4.1&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;Snort3&lt;/SPAN&gt; &lt;SPAN class=""&gt;behaved&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;same&lt;/SPAN&gt;&lt;SPAN&gt; way &lt;/SPAN&gt;&lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt;&lt;SPAN&gt; did &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;make&lt;/SPAN&gt; &lt;SPAN class=""&gt;any&lt;/SPAN&gt; &lt;SPAN class=""&gt;significant&lt;/SPAN&gt; &lt;SPAN class=""&gt;changes&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;policies&lt;/SPAN&gt; &lt;SPAN class=""&gt;before&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;fateful&lt;/SPAN&gt; &lt;SPAN class=""&gt;day&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; The &lt;/SPAN&gt;&lt;SPAN class=""&gt;standard&lt;/SPAN&gt; &lt;SPAN class=""&gt;rules&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;which&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;canceled&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;few&lt;/SPAN&gt; &lt;SPAN class=""&gt;days&lt;/SPAN&gt; &lt;SPAN class=""&gt;before&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;crash&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;but&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt;&lt;SPAN&gt; did not have a &lt;/SPAN&gt;&lt;SPAN class=""&gt;positive&lt;/SPAN&gt; &lt;SPAN class=""&gt;effect&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;situation&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;remembered&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;relatively&lt;/SPAN&gt; &lt;SPAN class=""&gt;recently&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;when&lt;/SPAN&gt;&lt;SPAN&gt; I was &lt;/SPAN&gt;&lt;SPAN class=""&gt;still&lt;/SPAN&gt; &lt;SPAN class=""&gt;setting&lt;/SPAN&gt;&lt;SPAN&gt; up &lt;/SPAN&gt;&lt;SPAN class=""&gt;IPS&lt;/SPAN&gt;&lt;SPAN&gt;, I &lt;/SPAN&gt;&lt;SPAN class=""&gt;hung&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;large&lt;/SPAN&gt; &lt;SPAN class=""&gt;enough&lt;/SPAN&gt; &lt;SPAN class=""&gt;ACL&lt;/SPAN&gt; &lt;SPAN class=""&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;more&lt;/SPAN&gt;&lt;SPAN&gt; than &lt;/SPAN&gt;&lt;SPAN class=""&gt;1000&lt;/SPAN&gt; &lt;SPAN class=""&gt;records&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;Control&lt;/SPAN&gt; &lt;SPAN class=""&gt;Plane&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;block&lt;/SPAN&gt; &lt;SPAN class=""&gt;bruteforce&lt;/SPAN&gt; &lt;SPAN class=""&gt;attempts&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;RA&lt;/SPAN&gt; &lt;SPAN class=""&gt;VPN&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;canceled&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt;&lt;SPAN class=""&gt;...&lt;/SPAN&gt; &lt;SPAN class=""&gt;lo&lt;/SPAN&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;SPAN class=""&gt;behold&lt;/SPAN&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;SPAN&gt;!! &lt;/SPAN&gt;&lt;SPAN class=""&gt;4&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt;&lt;SPAN&gt; of &lt;/SPAN&gt;&lt;SPAN class=""&gt;silence&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;stable&lt;/SPAN&gt; &lt;SPAN class=""&gt;network&lt;/SPAN&gt; &lt;SPAN class=""&gt;operation&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;no&lt;/SPAN&gt; &lt;SPAN class=""&gt;failures&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;But&lt;/SPAN&gt;&lt;SPAN class=""&gt;...&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;wasn&lt;/SPAN&gt;&lt;SPAN class=""&gt;'t&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;end&lt;/SPAN&gt;&lt;SPAN&gt; of the &lt;/SPAN&gt;&lt;SPAN class=""&gt;story&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exactly&lt;/SPAN&gt; &lt;SPAN class=""&gt;4&lt;/SPAN&gt; &lt;SPAN class=""&gt;weeks&lt;/SPAN&gt;&lt;SPAN&gt; later, it &lt;/SPAN&gt;&lt;SPAN class=""&gt;all&lt;/SPAN&gt; &lt;SPAN class=""&gt;started&lt;/SPAN&gt; &lt;SPAN class=""&gt;again&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;And&lt;/SPAN&gt; &lt;SPAN class=""&gt;this&lt;/SPAN&gt;&lt;SPAN&gt; is &lt;/SPAN&gt;&lt;SPAN class=""&gt;terrible&lt;/SPAN&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt; &lt;SPAN class=""&gt;Of&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;latest&lt;/SPAN&gt; &lt;SPAN class=""&gt;changes&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;moved&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;RA&lt;/SPAN&gt; &lt;SPAN class=""&gt;VPN&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;another&lt;/SPAN&gt; &lt;SPAN class=""&gt;FTD&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;unload&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt;&lt;SPAN&gt; a &lt;/SPAN&gt;&lt;SPAN class=""&gt;bit&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;disabled&lt;/SPAN&gt; &lt;SPAN class=""&gt;AMP&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;policy&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;But&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;didn&lt;/SPAN&gt;&lt;SPAN class=""&gt;'t&lt;/SPAN&gt; &lt;SPAN class=""&gt;help&lt;/SPAN&gt;&lt;SPAN&gt; me either&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;don&lt;/SPAN&gt;&lt;SPAN class=""&gt;'t&lt;/SPAN&gt; &lt;SPAN class=""&gt;understand&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt;&lt;SPAN&gt; all &lt;/SPAN&gt;&lt;SPAN class=""&gt;what&lt;/SPAN&gt;&lt;SPAN&gt; the &lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&lt;/SPAN&gt; &lt;SPAN class=""&gt;might&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;SPAN&gt; I &lt;/SPAN&gt;&lt;SPAN class=""&gt;hope&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;your&lt;/SPAN&gt; &lt;SPAN class=""&gt;help&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Unfortunately&lt;/SPAN&gt;&lt;SPAN class=""&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;our&lt;/SPAN&gt; &lt;SPAN class=""&gt;organization&lt;/SPAN&gt;&lt;SPAN&gt; does &lt;/SPAN&gt;&lt;SPAN class=""&gt;not&lt;/SPAN&gt;&lt;SPAN&gt; have &lt;/SPAN&gt;&lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;service&lt;/SPAN&gt; &lt;SPAN class=""&gt;contract&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 08:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208878#M1116572</guid>
      <dc:creator>viktar23</dc:creator>
      <dc:date>2024-10-15T08:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 2110 Snort3 problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208895#M1116574</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1377042"&gt;@viktar23&lt;/a&gt;&amp;nbsp;hi, seems like you did many tries to solve the issue. next step should be the cisco TAC. as you mentioned that you dont have service contract for this devices, i highly recommend to purchase the contract to get support from TAC. because these find of internal issues can solved by the TAC team as you already did many tastings and corrections.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 09:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208895#M1116574</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2024-10-15T09:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 2110 Snort3 problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208994#M1116578</link>
      <description>&lt;P&gt;It certainly sounds like you have performed much more than the typical troubleshooting on your own. I would agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt; that getting support would be the best move at this point. It's odd that management insists on enabling more advanced features but won't pay for TAC support.&lt;/P&gt;
&lt;P&gt;It wouldn't hurt to upgrade to 7.4.2.1 to get the latest bug fixes.&lt;/P&gt;
&lt;P&gt;Have you tried disabling the file policy (AMP) in the rules that have it enabled? I find file policies of quite limited value since 90% or more of Internet edge traffic is encrypted and thus not inspectable for Malware payloads (unless you have SSL decryption which only a very small percentage of customers do).&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 12:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5208994#M1116578</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-10-15T12:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 2110 Snort3 problem</title>
      <link>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5209204#M1116597</link>
      <description>It also seemed to me that AMP has little effect on the Snort load due to the encrypted traffic. However, given the fact that problems with FTD began after enabling this policy, I decided to disable it anyway. Yes, I have disabled the file policy for all rules in the ACP used. I also disabled adaptive profiles just in case. We have traffic decryption enabled, but it is currently being used in test mode, literally for several traffic flows.</description>
      <pubDate>Tue, 15 Oct 2024 18:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-2110-snort3-problem/m-p/5209204#M1116597</guid>
      <dc:creator>viktar23</dc:creator>
      <dc:date>2024-10-15T18:29:15Z</dc:date>
    </item>
  </channel>
</rss>

