12-25-2023 01:29 AM
Hi,
is there a way to bypass SI for a specific ACP entry?
As i see it , security intelligence binds to the ACP as a whole.
But is there any way that an ACP entry to bypass the check of the security intelligence?
Thanks,
Ditter
12-25-2023 01:51 AM - edited 12-25-2023 01:52 AM
check below guide :
12-25-2023 02:26 AM
Add new entry in ACP and action is trust' this make specific traffic bypass all Snort include SI.
MHM
12-25-2023 07:35 AM
Thanks for the suggestion. I thought about this trust relationship, but what i want is a specific vlan to be checked against the ACP but now checked against SI. If i have this vlan in trust relationship it will not be checked against the ACP policy rules.
Can we check a vlan against SI but not bypass the ACP rules?
Ditter
12-25-2023 10:27 PM
this flow' there is no other than ACP trust can make specific vlan bypass SI and all snort.
Remember we talk about l3-l4 so only prefilter and acp can do that.
MHM
12-25-2023 07:52 AM
Engaging in activities that circumvent security measures without authorization can have serious consequences and may violate ethical and legal standards.
12-26-2023 03:39 AM
You would have to allow the traffic via a prefilter rule (or set of rules).
What is the reason behind not wanting SI to apply?
12-26-2023 08:26 AM
Thanks for the answer.
I want to have a test vlan so that it can bypass the SI in order to check the results (or not) of the SI.
12-27-2023 06:39 AM
I was thinking about nested ACPs. As i see SI is an inherited feature so if i used inheritance could i do that?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide