<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Excluding Specific Traffic from Firepower Inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/excluding-specific-traffic-from-firepower-inspection/m-p/5233647#M1118025</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Regarding the ASA5525 with the FirePower module I am using, the following configuration exists in the service policy rules:&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;class-map Internal-class&lt;BR /&gt;match any&lt;/P&gt;&lt;P&gt;policy-map Internal-policy&lt;BR /&gt;class Internal-class&lt;BR /&gt;sfr fail-open&lt;/P&gt;&lt;P&gt;service-policy Internal-policy interface Internal&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;I believe all traffic passing through the Internal interface is being inspected by Firepower. However, I would like to configure it so that specific traffic is excluded from Firepower inspection.&lt;/P&gt;&lt;P&gt;To achieve this, I attempted to add a rule to the Internal Policy in the ASDM's Service Policy Rules. I defined a class to specify the traffic but wasn’t sure what to configure under "Rule Actions."&lt;/P&gt;&lt;P&gt;I proceeded without setting any Rule Actions, but it didn’t work as expected.&lt;/P&gt;&lt;P&gt;Could you provide some advice?&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Dec 2024 01:33:49 GMT</pubDate>
    <dc:creator>Samechine</dc:creator>
    <dc:date>2024-12-07T01:33:49Z</dc:date>
    <item>
      <title>Excluding Specific Traffic from Firepower Inspection</title>
      <link>https://community.cisco.com/t5/network-security/excluding-specific-traffic-from-firepower-inspection/m-p/5233647#M1118025</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Regarding the ASA5525 with the FirePower module I am using, the following configuration exists in the service policy rules:&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;class-map Internal-class&lt;BR /&gt;match any&lt;/P&gt;&lt;P&gt;policy-map Internal-policy&lt;BR /&gt;class Internal-class&lt;BR /&gt;sfr fail-open&lt;/P&gt;&lt;P&gt;service-policy Internal-policy interface Internal&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;I believe all traffic passing through the Internal interface is being inspected by Firepower. However, I would like to configure it so that specific traffic is excluded from Firepower inspection.&lt;/P&gt;&lt;P&gt;To achieve this, I attempted to add a rule to the Internal Policy in the ASDM's Service Policy Rules. I defined a class to specify the traffic but wasn’t sure what to configure under "Rule Actions."&lt;/P&gt;&lt;P&gt;I proceeded without setting any Rule Actions, but it didn’t work as expected.&lt;/P&gt;&lt;P&gt;Could you provide some advice?&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2024 01:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/excluding-specific-traffic-from-firepower-inspection/m-p/5233647#M1118025</guid>
      <dc:creator>Samechine</dc:creator>
      <dc:date>2024-12-07T01:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding Specific Traffic from Firepower Inspection</title>
      <link>https://community.cisco.com/t5/network-security/excluding-specific-traffic-from-firepower-inspection/m-p/5233649#M1118027</link>
      <description>&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2022/06/11/asa-firepower-module/" target="_blank"&gt;https://integratingit.wordpress.com/2022/06/11/asa-firepower-module/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check this'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What you need is add line under class deny specific traffic from pass through sfr&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 07 Dec 2024 01:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/excluding-specific-traffic-from-firepower-inspection/m-p/5233649#M1118027</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-07T01:54:06Z</dc:date>
    </item>
  </channel>
</rss>

