cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
656
Views
3
Helpful
8
Replies

Bypassing Security Intelligence for a specific ACP entry

Ditter
Level 4
Level 4

Hi,

is there a way to bypass SI for a specific ACP entry?

As i see it , security intelligence binds to the ACP as a whole. 

But is there any way that an ACP entry to bypass the check of the security intelligence?

Thanks,

Ditter

8 Replies 8

Add new entry in ACP and action is trust' this make specific traffic bypass all Snort include SI.

MHM

Thanks for the suggestion. I thought about this trust relationship, but what i want is a specific vlan to be checked against the ACP but now checked against SI.  If i have this vlan in trust relationship it will not be checked against the ACP policy rules. 

Can we check a vlan against SI but not bypass the ACP rules?

Ditter

images (2).jpeg

 this flow' there is no other than ACP trust can make specific vlan bypass SI and all snort.

Remember we talk about l3-l4 so only prefilter and acp can do that.

MHM

mitchelhorstone
Level 1
Level 1

Engaging in activities that circumvent security measures without authorization can have serious consequences and may violate ethical and legal standards.

Marvin Rhoads
Hall of Fame
Hall of Fame

You would have to allow the traffic via a prefilter rule (or set of rules).

What is the reason behind not wanting SI to apply?

Thanks for the answer.

I want to have a test vlan so that it can bypass the SI in order to check the results (or not) of the SI.

Ditter
Level 4
Level 4

I was thinking about nested ACPs.   As i see SI is an inherited feature so if i used inheritance could i do that?

Review Cisco Networking for a $25 gift card