cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1329
Views
0
Helpful
3
Replies

FirePOWER not blocking while pruning?

Peter Koltl
Level 7
Level 7

I have found some events of type Would have dropped in ASA-Firepower FMC logs. The guide explains

The event type is always Would have dropped for packets seen while the system is pruning, regardless of deployment.

[...]

 the system sometimes prunes older event details to manage disk space usage.

The module is inline and IPS policy is set to Drop when Inline so I can think of no other explanation.

Would Firepower really pass traffic matching a threat pattern while it is busy pruning?? Were these packets really not dropped?

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

I would like to know the answer to that question as well. Peter, were you able to find anything about this?

Thanks!

Neno

Peter Koltl
Level 7
Level 7

No findings yet, Neno. Sorry.

Peter, 

Were you able to find any such information for your query?

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card