cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1331
Views
0
Helpful
3
Replies

FirePOWER not blocking while pruning?

Peter Koltl
Level 7
Level 7

I have found some events of type Would have dropped in ASA-Firepower FMC logs. The guide explains

The event type is always Would have dropped for packets seen while the system is pruning, regardless of deployment.

[...]

 the system sometimes prunes older event details to manage disk space usage.

The module is inline and IPS policy is set to Drop when Inline so I can think of no other explanation.

Would Firepower really pass traffic matching a threat pattern while it is busy pruning?? Were these packets really not dropped?

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

I would like to know the answer to that question as well. Peter, were you able to find anything about this?

Thanks!

Neno

Peter Koltl
Level 7
Level 7

No findings yet, Neno. Sorry.

Peter, 

Were you able to find any such information for your query?

 

Review Cisco Networking products for a $25 gift card