<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does SNORT drop traffic, when its restarted with &amp;quot;Inspect Traffic During Policy Apply&amp;quot; is enabled in the Access Control Policy? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/does-snort-drop-traffic-when-its-restarted-with-quot-inspect/m-p/3071105#M925627</link>
    <description>&lt;P&gt;OK, So here is what I found on the subject. &amp;nbsp;The teacher in the instruction video states that SNORT drops traffic with this feature enabled AND SNORT restarts. &amp;nbsp;My question is, is traffic dropped? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's what I found&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Access Control Policy in question:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Inspect traffic during policy apply = Yes&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Resource: Configuration Guide for 6.0.1&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Snort® Restarts During Configuration Deployment:&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;The Inspect traffic during policy apply advanced access control policy general setting allows you to inspect&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;traffic while deploying configuration changes unless a configuration that you deploy requires the Snort process&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;to restart, as follows:&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;• Enabled — Certain configurations can require the Snort process to restart.&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;When the configurations you deploy do not require a Snort restart, the system initially uses the currently&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;deployed access control policy to inspect traffic, and switches during deployment to the access control&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;policy you are deploying.&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;• Disabled — The Snort process always restarts when you deploy. Traffic is not inspected during the&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;deployment.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Page: 271&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Resource: Youtube&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Video Title: Cisco FirePOWER Access Control Policies - Todd Lammle Training Series&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Time mentioned: 15:34&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Reference Link: &lt;A href="https://youtu.be/kCZQrAYdrFo" target="_blank"&gt;https://youtu.be/kCZQrAYdrFo&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Note: The Configuration Guide does not state that restarting SNORT will drop traffic, if "Inspect Traffic during policy&lt;/P&gt;
&lt;P&gt;apply" is set to enabled.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:04:46 GMT</pubDate>
    <dc:creator>Joshua.Dixon</dc:creator>
    <dc:date>2020-02-21T14:04:46Z</dc:date>
    <item>
      <title>Does SNORT drop traffic, when its restarted with "Inspect Traffic During Policy Apply" is enabled in the Access Control Policy?</title>
      <link>https://community.cisco.com/t5/network-security/does-snort-drop-traffic-when-its-restarted-with-quot-inspect/m-p/3071105#M925627</link>
      <description>&lt;P&gt;OK, So here is what I found on the subject. &amp;nbsp;The teacher in the instruction video states that SNORT drops traffic with this feature enabled AND SNORT restarts. &amp;nbsp;My question is, is traffic dropped? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's what I found&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Access Control Policy in question:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Inspect traffic during policy apply = Yes&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Resource: Configuration Guide for 6.0.1&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Snort® Restarts During Configuration Deployment:&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;The Inspect traffic during policy apply advanced access control policy general setting allows you to inspect&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;traffic while deploying configuration changes unless a configuration that you deploy requires the Snort process&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;to restart, as follows:&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;• Enabled — Certain configurations can require the Snort process to restart.&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;When the configurations you deploy do not require a Snort restart, the system initially uses the currently&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;deployed access control policy to inspect traffic, and switches during deployment to the access control&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;policy you are deploying.&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;• Disabled — The Snort process always restarts when you deploy. Traffic is not inspected during the&lt;/P&gt;
&lt;P style="padding-left: 60px;"&gt;deployment.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Page: 271&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Resource: Youtube&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Video Title: Cisco FirePOWER Access Control Policies - Todd Lammle Training Series&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Time mentioned: 15:34&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Reference Link: &lt;A href="https://youtu.be/kCZQrAYdrFo" target="_blank"&gt;https://youtu.be/kCZQrAYdrFo&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Note: The Configuration Guide does not state that restarting SNORT will drop traffic, if "Inspect Traffic during policy&lt;/P&gt;
&lt;P&gt;apply" is set to enabled.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:04:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-snort-drop-traffic-when-its-restarted-with-quot-inspect/m-p/3071105#M925627</guid>
      <dc:creator>Joshua.Dixon</dc:creator>
      <dc:date>2020-02-21T14:04:46Z</dc:date>
    </item>
    <item>
      <title>To inspect traffic when you</title>
      <link>https://community.cisco.com/t5/network-security/does-snort-drop-traffic-when-its-restarted-with-quot-inspect/m-p/3071106#M925628</link>
      <description>&lt;P&gt;To inspect traffic when you deploy configuration changes unless specific configurations require restarting the Snort process, ensure that &lt;SPAN class="uicontrol"&gt;Inspect traffic during policy apply&lt;/SPAN&gt; is set to its default value (enabled). When this option is enabled, resource demands could result in a &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;small number of packets dropping without inspection&lt;/STRONG&gt;&lt;/SPAN&gt;. See &lt;A href="https://10.7.75.150/help_files/c_Snort_Restarts_During_Configuration_Deployment.html#concept_33516C5D6B574B6888B1A05F956ABDF9"&gt;Snort® Restarts During Configuration Deployment&lt;/A&gt; for more information.&lt;/P&gt;
&lt;TABLE class="olh_note"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="olh_note"&gt;&lt;IMG src="https://10.7.75.150/help_files/template_images/caut.gif" /&gt;&lt;BR /&gt;&lt;B&gt;Caution&lt;/B&gt;&lt;/TD&gt;
&lt;TD class="olh_note"&gt;&lt;BR /&gt;&lt;HR /&gt;
&lt;P&gt;Disabling &lt;SPAN class="uicontrol"&gt;Inspect traffic during policy apply&lt;/SPAN&gt; restarts the Snort process when you deploy configuration changes.&lt;/P&gt;
&lt;HR /&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Answered my own question. &amp;nbsp;It does&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 17:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/does-snort-drop-traffic-when-its-restarted-with-quot-inspect/m-p/3071106#M925628</guid>
      <dc:creator>Joshua.Dixon</dc:creator>
      <dc:date>2017-05-11T17:11:03Z</dc:date>
    </item>
  </channel>
</rss>

