<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD - 7.6.2 - Snort Fail Open? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332816#M1122864</link>
    <description>&lt;P&gt;Yes very common. All major firewall vendors have "scheduled deploy" features for this exact reason (among others).&lt;/P&gt;</description>
    <pubDate>Tue, 23 Sep 2025 19:41:51 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2025-09-23T19:41:51Z</dc:date>
    <item>
      <title>FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332707#M1122855</link>
      <description>&lt;P&gt;The FTD's (managed by FMC) used to drop traffic all the time when doing policy deploys. But it seems to be better in 7.x.&lt;/P&gt;&lt;P&gt;We have some critical network traffic flowing through the firewall. At times we do see traffic disrupted during policy deploys. I believe this is due to the snort process restarting. Is there any way to make it so traffic is NEVER disrupted even when snort needs to restart? Like a fail open?&lt;/P&gt;&lt;P&gt;I'm looking for any tips or setting changes to ensure traffic stays up. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 13:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332707#M1122855</guid>
      <dc:creator>Ralphy006</dc:creator>
      <dc:date>2025-09-23T13:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332724#M1122856</link>
      <description>&lt;P&gt;I'm not aware of any. If the policy deploy requires a service restart, that's a fact of life.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 15:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332724#M1122856</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-09-23T15:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332731#M1122857</link>
      <description>&lt;P&gt;Looks same as i know refer below the when the snort restart take place :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.defenseorchestrator.com/cdfmc/c_snort_restart_scenarios.html#:~:text=When%20the%20traffic%20inspection%20engine,whether%20the%20Snort%20process%20restarts" target="_blank"&gt;https://docs.defenseorchestrator.com/cdfmc/c_snort_restart_scenarios.html#:~:text=When%20the%20traffic%20inspection%20engine,whether%20the%20Snort%20process%20restarts&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 15:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332731#M1122857</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-23T15:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332750#M1122858</link>
      <description>&lt;P&gt;Is this common among other firewall vendors too? Personally, I feel it's unacceptable to have no workaround&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 16:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332750#M1122858</guid>
      <dc:creator>Ralphy006</dc:creator>
      <dc:date>2025-09-23T16:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332752#M1122860</link>
      <description>&lt;P&gt;yeah that's what I was reading too. Looks line "inline" ports has a fail open option. I'm not sure how many FTD users use the "inline" feature. I'd think most used routed interfaces. In which there is no option but to drop traffic which is a shame. I was hoping there was some workaround&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 16:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332752#M1122860</guid>
      <dc:creator>Ralphy006</dc:creator>
      <dc:date>2025-09-23T16:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332754#M1122861</link>
      <description>&lt;P&gt;May cisco working on that i guess - but not that i am aware any version yet. even FMC you do not have multi user policy change (unlike other vendor - just to mentioned) - some limitation, But cisco BU look this and make use case to add features.&lt;/P&gt;
&lt;P&gt;so suggestion is do the changes in maintenance window, like off peak ours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 16:32:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332754#M1122861</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-23T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - 7.6.2 - Snort Fail Open?</title>
      <link>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332816#M1122864</link>
      <description>&lt;P&gt;Yes very common. All major firewall vendors have "scheduled deploy" features for this exact reason (among others).&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 19:41:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-7-6-2-snort-fail-open/m-p/5332816#M1122864</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-09-23T19:41:51Z</dc:date>
    </item>
  </channel>
</rss>

